IP Library Patent Application 11839287
Patent Application
App. No. 11/839,287

STORING CUSTOM METADATA USING CUSTOM ACCESS CONTROL ENTRIES

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
11/839,287
Abstract

A computer-implemented system and method for storing custom metadata in a custom access control entry of a securable object. An exemplary method includes determining the custom metadata to be stored (e.g., information relating to the securable object that is inexpressible using a native file system application programming interface, information relating to remote domain permission data, information to support a custom feature of an application, etc.). The system may identify a custom access control entry (ACE) type corresponding to the custom metadata. In one embodiment, the custom ACE type is not a member of a set of ACE types directly interpretable by a native security subsystem to manage permissions for the securable object. The system may additionally store the custom ACE type and the custom metadata in a custom ACE, which may be added to the access control list of the securable object. The securable object may then be saved to the file system (e.g., to an NTFS file system).

Claims (50)

1 . A computer-implemented method for storing custom metadata in an access control list of a securable object having permissions managed by a native security subsystem, the method comprising:

determining the custom metadata to be stored;

identifying a custom access control entry (ACE) type corresponding to the custom metadata, wherein the custom ACE type is not a member of a set of ACE types directly interpretable by the native security subsystem to manage permissions for the securable object;

storing the custom ACE type and the custom metadata in a custom ACE;

adding the custom ACE to the access control list of the securable object; and

saving the securable object with the custom ACE having the custom metadata to a file system.

2 . The method of claim 1 , wherein the custom ACE includes no information relating to a set of native security information directly interpretable by the native security subsystem, the set comprising:

a security identifier;

an access mask; and

a set of inheritance information.

3 . The method of claim 1 , wherein the set of ACE types directly interpretable by the native security subsystem by the native security subsystem relate to access denied, access allowed, and system audit.

4 . The method of claim 1 , wherein the set of ACE types used by the native security subsystem is a non-extensible set for a native operating system.

5 . The method of claim 4 , wherein the custom ACE type is determined by an application developer and the set of ACE types directly interpretable by the native security subsystem is determined by the native operating system developer.

6 . The method of claim 1 , wherein the custom metadata comprises access control information relating to the securable object that is usable by a remote operating system that is different than a native operating system.

7 . The method of claim 1 , wherein the custom metadata comprises information about the securable object that is not expressible using an application programming interface of the file system.

8 . The method of claim 7 , wherein the file system comprises a new technology file system (NTFS).

9 . The method of claim 7 , wherein the custom metadata comprises at least one of a set of remote permission metadata, the set comprising a sticky bit indicator, a user identifier, a group identifier, a set user identifier, and a set group identifier.

10 . The method of claim 1 , wherein the custom ACE is a member a discretionary access control list.

11 . The method of claim 10 , wherein the custom ACE does not include data corresponding to a native trustee account that is directly interpretable by the native security subsystem.

12 . The method of claim 10 , wherein the custom ACE does not include data corresponding to an access mask that is directly interpretable by the native security subsystem.

13 . The method of claim 1 , wherein the native security subsystem manages permissions for the securable object by:

enforcing access rules defined by a set of standard access control entries within a discretionary access control list; and

auditing attempts to access the securable object based on standard access control entries within the system access control list.

14 . The method of claim 13 , wherein adding custom access control entries does not affect permissions to or auditing of the securable object within the native security subsystem.

15 . A computer-readable medium having stored thereon an access control list data structure for a securable object managed by a file system within a domain, the data structure comprising:

a first data field containing data representing an ACE type, wherein the data structure includes:

at least one conventional ACE having a conventional ACE type; and

at least one custom ACE having a custom ACE type;

for the conventional ACE:

a second data field configured to store a security identifier that corresponds to a trustee account within the domain;

a third data field containing data representing an access mask that, in combination with the first data field and the second data field, determines a permission for a trustee for the securable object; and

for the custom ACE, a fourth data field containing custom metadata.

16 . The computer-readable medium of claim 15 , wherein the fourth data field is different than each of:

the second data field;

the third data field; and

a combination of the second and third data field.

17 . The computer-readable medium of claim 15 , wherein the access control list comprises a discretionary access control list.

18 . A computer-implemented method for managing permissions by a native domain on behalf of a remote domain using a custom ACE, the method comprising:

receiving a document from the remote domain, the document including a set of permission data that is presented in a remote domain permission schema different than a native domain permission scheme;

reading the remote domain permission data;

storing the remote domain permission data in a custom ACE; and

saving the document with custom ACE.

19 . The computer-implemented method of claim 18 , further comprising:

receiving a request to export the document;

granting permission to access the document;

converting the custom ACE to the remote domain permission data;

validating the received request using remote domain permission data;

when the received request is permitted, exporting the document to the remote domain; and

when the received request is not permitted, denying the request to export the document to the remote domain.

20 . The computer-implemented method of claim 18 , wherein the custom ACE is added to a discretionary access control list.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 15, 2015
From: MICROSOFT CORPORATION
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 034766/0509 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 18, 2007
From: BATTEPATI, ROOPESH C.; JOHNSON, MICHAEL C.
To: MICROSOFT CORPORATION
Reel/Frame 020129/0288 →