Virtual File System for Secure Mobile Enterprise Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile devices in enterprise environments face limitations in accessing enterprise content due to security concerns and system compatibility issues, leading to a degraded user experience and increased governance and compliance challenges for IT departments.
Innovation Solution
The Averail Cloud Content Exchange (ACXS) service provides a secure virtual file management system that enables secure access to on-premise and cloud-based storage services from mobile devices, implementing a federated identity model, policy management, and encryption to ensure compliance with enterprise policies while allowing seamless access and collaboration across multiple storage domains.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If mobile devices are granted access to enterprise content, then user experience and accessibility are improved, but security risks and compliance challenges increase
Solution Approach 1:
The patent introduces a virtual file system and policy enforcement point as an intermediary layer between mobile devices and enterprise content management systems. This mediator enables secure access by filtering and controlling file operations according to enterprise policies, thus resolving the contradiction between accessibility and security.
Solution Approach 2:
The patent segments the file access control into multiple layers: device-level policies, virtual file system policies, and content management system policies. This segmentation allows granular control over mobile device access while maintaining overall security, addressing both accessibility and compliance requirements.
2Reliability
If mobile devices are IT-managed with MDM solutions, then security control is improved, but device complexity and user autonomy worsen
Solution Approach 1:
The patent implements self-service mechanisms where mobile devices automatically enroll in MDM management, self-provision virtual file system policies, and autonomously enforce security rules. This reduces manual IT intervention and management complexity while maintaining strong security control.
Solution Approach 2:
The virtual file system serves multiple functions simultaneously: it acts as a security enforcement point, a synchronization mechanism, a policy management interface, and a user access portal. This multi-functionality consolidates various management tasks into a single system, reducing overall device complexity.
3Adaptability or versatility
If multiple storage domains are integrated, then content accessibility and collaboration are improved, but system complexity increases
Solution Approach 1:
The virtual file system is designed as a universal access layer that can connect to multiple different storage domains (enterprise file systems, cloud storage, personal storage) through standardized interfaces. This allows seamless cross-domain access without requiring separate integration logic for each storage system.
Solution Approach 2:
The virtual file system acts as an intermediary that abstracts the complexity of multiple storage domains behind a unified interface. It handles domain-specific protocols, authentication, and data formats transparently, allowing users to access content across domains without dealing with underlying system complexities.
4Reliability
If policy enforcement is implemented on mobile devices, then compliance is improved, but device performance and user experience worsen
Solution Approach 1:
The system performs preliminary policy evaluation and file filtering at the virtual file system layer before actual file operations occur. By pre-establishing policy rules and caching access decisions, the system ensures compliance without adding significant overhead during actual file access operations.
Solution Approach 2:
The patent replaces traditional mechanical file access control (which would require constant system checks and validations) with a virtual file system that uses software-based policy enforcement. This substitution allows compliance checking to occur transparently in the virtual layer without impacting the performance of actual file operations on the device.
Data Source
AI summary
Virtual file management is disclosed. Managed content from multiple separate storage domains is organized into a virtual file system that maintains with respect to each of at least a subset of said separate storage domains information of storage domain specific file system primitives to perform primitive operations with respect to content stored in that storage domain. Policies are determined that apply to the managed content. Each policy indicates primitive operations permitted to be performed with respect to the managed content. Information comprising the virtual file system and the policies is provided to a client application on a mobile device. The client application is configured to provide access to the managed content in the virtual file system in a manner at least in part indicated in the policies, including by allowing the permitted primitive operations to be performed using said storage domain specific file system primitives.


