Zero-Trust File Views With Entity-Based Access Capabilities
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems fail to facilitate the presentation of a variety of potential structures or organizations for data that reflect different points of view, and simulation systems do not readily enable handling alternative perspectives.
Innovation Solution
A system for securing resources in a computing system through entity aggregation, involving user-type, data-type, and process-type entities, with each entity associated with access and privilege information, and an aggregation covenant that defines capabilities, allowing for the configuration of rules to aggregate entities and define instances with unique capabilities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional data structures and access control systems are used, then system simplicity is maintained, but the ability to present multiple potential structures reflecting different points of view is lost
Solution Approach 1:
The patent segments the data structure into multiple independent views, where each view represents a different organizational perspective. Each view can be independently configured and managed, allowing the system to present multiple potential structures simultaneously without creating a monolithic complex structure.
Solution Approach 2:
The patent implements nested data structures where views are contained within the overall data structure hierarchy. Each view can contain its own nested elements, allowing multiple levels of organization to coexist. This nesting approach enables the system to maintain simplicity at each level while achieving versatility through the combination of multiple nested views.
2Reliability
If simulation systems are used to model alternative perspectives, then analytical capability is improved, but ease of handling alternative points of view deteriorates
Solution Approach 1:
The patent creates a universal data structure framework that can serve multiple analytical functions simultaneously. The same structured approach used for presenting alternative views can be directly applied to simulation and analysis operations, eliminating the need for separate specialized systems and making alternative perspective handling more accessible.
Solution Approach 2:
The patent introduces an intermediary layer between the raw data and the analysis operations. This intermediary structured framework acts as a mediator that translates alternative perspectives into a standardized format suitable for simulation and analysis, while maintaining the ease of working with structured data throughout the process.
3Adaptability or versatility
If entities are aggregated with different capabilities, then security flexibility is improved, but access control complexity increases
Solution Approach 1:
The patent applies local quality by assigning specific capabilities to individual entities within the aggregation based on their local requirements. Each entity can have its own access control attributes and permissions defined at the local level, allowing security flexibility without requiring a complex centralized access control system. The aggregation structure automatically manages the coordination of these local capabilities.
Data Source
AI summary
Securing a file in a computer network includes processing a file system request that identifies a user entity, a file entity, and a file-directed action. Responding to the request with an indication of permission to reveal a portion of the file system, an indication of permission to reveal at least a portion of the file, and an indication of permission to perform the file-directed action. The response being based on access and use constraints of the file entity, as well as a portion of user entity-context and action code entity-context.


