Virtual File System for Secure Mobile Enterprise Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices in enterprise environments face limitations in accessing enterprise content due to security concerns and system compatibility issues, leading to a degraded user experience and increased governance and compliance challenges for IT departments.

Innovation Solution

The Averail Cloud Content Exchange (ACXS) service provides a secure virtual file management system that enables secure access to on-premise and cloud-based storage services from mobile devices, implementing a federated identity model, policy management, and encryption to ensure compliance with enterprise policies while allowing seamless access and collaboration across multiple storage domains.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If mobile devices are granted access to enterprise content, then user experience and accessibility are improved, but security risks and compliance challenges increase

Engineering Contradiction:
Improveaccessibility to enterprise contentVSAvoidsecurity and compliance
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a virtual file system and policy enforcement point as an intermediary layer between mobile devices and enterprise content management systems. This mediator enables secure access by filtering and controlling file operations according to enterprise policies, thus resolving the contradiction between accessibility and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the file access control into multiple layers: device-level policies, virtual file system policies, and content management system policies. This segmentation allows granular control over mobile device access while maintaining overall security, addressing both accessibility and compliance requirements.

Inventive Principle:
Principle #1Segmentation

2Reliability

If mobile devices are IT-managed with MDM solutions, then security control is improved, but device complexity and user autonomy worsen

Engineering Contradiction:
Improvesecurity controlVSAvoidmanagement overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service mechanisms where mobile devices automatically enroll in MDM management, self-provision virtual file system policies, and autonomously enforce security rules. This reduces manual IT intervention and management complexity while maintaining strong security control.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The virtual file system serves multiple functions simultaneously: it acts as a security enforcement point, a synchronization mechanism, a policy management interface, and a user access portal. This multi-functionality consolidates various management tasks into a single system, reducing overall device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If multiple storage domains are integrated, then content accessibility and collaboration are improved, but system complexity increases

Engineering Contradiction:
Improvecross-domain accessVSAvoidsystem integration
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The virtual file system is designed as a universal access layer that can connect to multiple different storage domains (enterprise file systems, cloud storage, personal storage) through standardized interfaces. This allows seamless cross-domain access without requiring separate integration logic for each storage system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The virtual file system acts as an intermediary that abstracts the complexity of multiple storage domains behind a unified interface. It handles domain-specific protocols, authentication, and data formats transparently, allowing users to access content across domains without dealing with underlying system complexities.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If policy enforcement is implemented on mobile devices, then compliance is improved, but device performance and user experience worsen

Engineering Contradiction:
ImprovecomplianceVSAvoiddevice performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary policy evaluation and file filtering at the virtual file system layer before actual file operations occur. By pre-establishing policy rules and caching access decisions, the system ensures compliance without adding significant overhead during actual file access operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces traditional mechanical file access control (which would require constant system checks and validations) with a virtual file system that uses software-based policy enforcement. This substitution allows compliance checking to occur transparently in the virtual layer without impacting the performance of actual file operations on the device.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS9465953B2Secure virtual file management system
Publication Date: 2016.10.11 IVANTI INC
  • US9465953B2 patent drawing
  • US9465953B2 patent drawing
  • US9465953B2 patent drawing

AI summary

Virtual file management is disclosed. Managed content from multiple separate storage domains is organized into a virtual file system that maintains with respect to each of at least a subset of said separate storage domains information of storage domain specific file system primitives to perform primitive operations with respect to content stored in that storage domain. Policies are determined that apply to the managed content. Each policy indicates primitive operations permitted to be performed with respect to the managed content. Information comprising the virtual file system and the policies is provided to a client application on a mobile device. The client application is configured to provide access to the managed content in the virtual file system in a manner at least in part indicated in the policies, including by allowing the permitted primitive operations to be performed using said storage domain specific file system primitives.