Virtual File System Access Manager for Cross-Device Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing enterprise management software is limited in controlling access to files across devices both within and external to the enterprise's network, leading to potential unauthorized access and data security risks when files are copied or transferred to other devices or locations.

Innovation Solution

A virtual local file system managed by an access manager that interacts with the host operating system to control file access permissions, using a file attributes repository to dynamically manage access rights based on user permissions, time, location, and device attributes, ensuring secure access to files across all connected devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If enterprise management software is used to control access to files on network drives, then access control within the enterprise network is improved, but the system cannot manage access to files when they are copied to other devices or locations outside the network

Engineering Contradiction:
Improveaccess control reliabilityVSAvoidfile access management scope
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a file container as an intermediary that wraps the original file and carries embedded access control rules. This container travels with the file wherever it is copied or transferred, enabling the access control system to maintain authority over the file even when it moves outside the enterprise network to personal devices, cloud storage, or other locations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies access control rules and embeds them within the file container before the file is copied or transferred. By pre-configuring the access control metadata and rules in advance, the system ensures that authorization checks are already in place and can be enforced immediately when the file is accessed on any device, without requiring real-time network connection or additional setup.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If files are copied to removable storage or external devices for business purposes, then file accessibility and mobility are improved, but the risk of unauthorized access increases when devices are lost or stolen

Engineering Contradiction:
Improvefile mobilityVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies different access control rules to different portions or aspects of the file based on location and context. The access control metadata within the file container can specify different authorization levels for different devices, locations, or users, allowing the system to maintain high mobility while enforcing appropriate security restrictions at each access point.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent pre-empts potential unauthorized access by embedding access control rules that automatically enforce authorization checks before any file access occurs. The system proactively prevents unauthorized access by verifying credentials and applying rules before the file can be opened or viewed, rather than reacting after a security breach occurs.

Inventive Principle:
Principle #9Preliminary anti-action

3Reliability

If traditional enterprise management software is used, then access control on managed devices is maintained, but access control is lost when files are transferred to unmanaged devices outside the network

Engineering Contradiction:
Improveaccess control enforcementVSAvoidcross-device compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal file container format that can carry access control rules across different operating systems, devices, and network environments. The file container structure and embedded metadata are designed to be platform-independent, allowing the same access control mechanism to function whether the file is accessed on Windows, macOS, Linux, mobile devices, or cloud storage services.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10404708B2System for secure file access
Publication Date: 2019.09.03 CROWDSTRIKE
  • US10404708B2 patent drawing
  • US10404708B2 patent drawing
  • US10404708B2 patent drawing

AI summary

A virtual local file system for managing file access, such as read, write and execute, of files on local media is disclosed. An access manager, executable by the host operating system, is stored on each host device. The access manager interacts with the local file system to control file access permissions and how processes of the host operating system execute, view or modify files accessible to the local file system. The access manager may also dynamically control file access to files on the host operating system using a file attributes repository, which may be stored locally or remotely from the host device. Exemplary attributes for defining permission to access a file include but not are limited to, specific users, a time of day, a number of copies of a file, an allowed process, an IP address range, and a MAC address.