Invention Grant
- Patent Title: Filesystem view separation for data confidentiality and integrity using lattice-based security domains
-
Application No.: US16019793Application Date: 2018-06-27
-
Publication No.: US11562086B2Publication Date: 2023-01-24
- Inventor: Frederico Araujo , Marc Phillipe Stoecklin , Teryl Paul Taylor
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agent Jeffrey S. LaBaw; David H. Judson
- Main IPC: G06F21/62
- IPC: G06F21/62 ; G06F21/57 ; H04L67/30 ; G06F21/53 ; G06F16/185 ; G06F16/17

Abstract:
A stackable filesystem architecture that curtails data theft and ensures file integrity protection. In this architecture, processes are grouped into ranked filesystem views, or “security domains.” Preferably, an order theory algorithm is utilized to determine a proper domain in which an application is run. In particular, a root domain provides a single view of the filesystem enabling transparent filesystem operations. Each security domain transparently creates multiple levels of stacking to protect the base filesystem, and to monitor file accesses without incurring significant performance overhead. By combining its layered architecture with view separation via security domains, the filesystem maintains data integrity and confidentiality.
Public/Granted literature
- US20200004977A1 Filesystem view separation for data confidentiality and integrity using lattice-based security domains Public/Granted day:2020-01-02
Information query