×

System and method for file system mandatory access control

  • US 7,962,950 B2
  • Filed: 06/29/2001
  • Issued: 06/14/2011
  • Est. Priority Date: 06/29/2001
  • Status: Expired due to Fees
First Claim
Patent Images

1. A method for controlling access to a file by a process, said method comprising:

  • receiving a request from said process to access said file, said process being associated with a compartment implemented on an operating system;

    determining an identifier of said compartment; and

    searching for access rules defining whether processes associated with particular compartments are permitted to access certain file resources, said rules retained in a database in a hierarchical manner that parallels a subdirectory structure of a file system containing said file;

    wherein said request includes a filename containing a path identifier, said path identifier specifying a plurality of subdirectories, and wherein said step of searching includes the sub-steps of;

    (a) searching said database according to a lowest subdirectory of said plurality of subdirectories for an access rule applicable to said compartment;

    (b) when an access rule is found in step (a), proceeding to step (e);

    (c) searching said database according a next higher subdirectory of said plurality of subdirectories for an access rule applicable to said compartment; and

    (d) repeating step (c) until the first event of the following events occurs;

    (i) an access rule applicable to said compartment is located;

    (ii) said database is searched according to a root directory;

    (e) when an access rule applicable to said compartment is located, providing access to said file when said access rule applicable to said compartment allows access.

View all claims
  • 9 Assignments
Timeline View
Assignment View
    ×
    ×