首页> 外国专利> FILE ACCESS CONTROL SYSTEM BASED ON VOLUME GLOBALLY UNIQUE IDENTIFIERS AND METHOD THEREFOR

FILE ACCESS CONTROL SYSTEM BASED ON VOLUME GLOBALLY UNIQUE IDENTIFIERS AND METHOD THEREFOR

机译:基于体积全局唯一标识符的文件访问控制系统及其方法

摘要

The present invention relates to a file access control system based on volume globally unique identifiers (GUIDs). The file access control system comprises: a policy setting unit which operates in a user mode, changes process execution paths and file paths based on volume GUIDs for performance of access control, and stores the changed execution paths and file paths in a policy DB; a process volume management unit which operates in a kernel mode, when execution of a process, performed by an application in the user mode, is detected, changes a process execution path of the process based on a volume GUID, and stores the changed volume GUID-based process execution path and a process ID (PID) in a process volume DB; and an access control unit which, when an access control command for a file is generated, acquires a volume GUID-based file path included in the corresponding command and a PID of a process having attempted to access the file, acquires a volume GUID-based process execution path stored in the process volume DB based on the corresponding PID, and then determines whether the access to the corresponding file is permitted by comparing the volume GUID-based file path and the volume GUID-based process execution path with policies of the policy DB. According to the present invention, when access is attempted via a drive path other than a designated drive letter, when the drive letter is changed, or when the drive letter is removed, the drive letter and the drive path are represented and controlled by using a volume GUID, which is a unique value indicative of a specific volume, thereby accurately identifying the same target during policy setting and controlling.;COPYRIGHT KIPO 2016
机译:本发明涉及基于卷全局唯一标识符(GUID)的文件访问控制系统。该文件访问控制系统包括:策略设置单元,其以用户模式操作,基于卷GUID改变处理执行路径和文件路径以执行访问控制,并将改变后的执行路径和文件路径存储在策略DB中;在内核模式下操作的进程卷管理单元,当检测到由用户模式下的应用执行的进程执行时,基于卷GUID更改进程的进程执行路径,并存储更改后的卷GUID流程卷DB中的基于流程的执行路径和流程ID(PID);以及访问控制单元,其在生成用于文件的访问控制命令时,获取包括在相应命令中的基于卷GUID的文件路径以及试图访问该文件的进程的PID,以获取基于卷GUID的基于相应的PID,将处理执行路径存储在进程卷DB中,然后通过将基于卷GUID的文件路径和基于卷GUID的进程执行路径与策略的策略进行比较,确定是否允许访问相应文件D B。根据本发明,当试图通过除指定的驱动器号以外的驱动器路径进行访问时,当改变驱动器号或移除驱动器号时,通过使用表示和控制驱动器号和驱动器路径来进行控制。音量GUID,它是表示特定音量的唯一值,从而在策略设置和控制过程中准确识别相同的目标。; COPYRIGHT KIPO 2016

著录项

  • 公开/公告号KR101650287B1

    专利类型

  • 公开/公告日2016-08-23

    原文格式PDF

  • 申请/专利权人 SECUVE;

    申请/专利号KR20160027480

  • 申请日2016-03-08

  • 分类号G06F21/62;G06F21/52;

  • 国家 KR

  • 入库时间 2022-08-21 14:12:05

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号