IP Library Granted Patent US 9,483,491
Granted Patent B2
US 9,483,491 · App. 13/689,648 · Granted Nov 1, 2016

Flexible permission management framework for cloud attached file systems

Inventors: Ravi Wijayaratne (San Jose, CA); Ray White (San Jose, CA); Manish Marathe (San Jose, CA); Aahz (San Carlos, CA); Rajesh Ram (Union City, CA); Amrit Jassal (Morgan Hill, CA)
Assignee: EGNYTE, INC.
G06F17/30194G06F21/6236
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,483,491
App. No.
13/689,648
Granted
Nov 1, 2016
Kind
B2
Abstract

A method of managing file permissions in a remote file storage system includes defining permissions for the remote file storage system and controlling access to objects on the remote file storage system according to the permissions of the remote file storage system. The permissions are transferred to a client file storage system remote from the remote file storage system, and access to objects on the client file storage system is controlled according to the permissions of the remote file storage system. A remote file storage system includes a permissions file generator operative to generate a permissions file, which is transmitted to a client file storage system for enforcement at the client file storage system.

Claims (79)

1. A method of managing file permissions in a remote file storage system, said method comprising:

defining permissions for said remote file storage system;

controlling access to objects on said remote file storage system according to said permissions of said remote file storage system;

transferring said permissions to a client file storage system remote from said remote file storage system;

controlling access to objects on said client file storage system according to said permissions of said remote file storage system;

altering said permissions of said remote file storage system at said remote file storage system;

controlling access to objects on said remote file storage system according to said altered permissions of said remote file storage system;

transferring said altered permissions to said client file storage system; and

controlling access to objects on said client file storage system according to said altered permissions of said remote file storage system; and wherein

said step of controlling access to objects on said client file storage system according to said permissions of said remote file storage system includes overriding permissions of said client file storage system.

2. The method of claim 1 , additionally comprising:

defining a virtual file system structure for said objects on said remote file storage system; and

defining said permissions based at least in part on said virtual file system structure.

3. The method of claim 1 , wherein said step of transferring said altered permissions to said client file storage system occurs in conjunction with a data synchronization process between said remote file storage system and said client file storage system.

4. The method of claim 1 , wherein said step of transferring said altered permissions to said client file storage system occurs in response to a command from a user.

5. The method of claim 1 , wherein said step of transferring said altered permissions to said client file storage system occurs in response to said step of altering said permissions.

6. The method of claim 1 , additionally comprising:

locally altering said permissions of said remote file storage system at said client file storage system;

controlling access to objects on said client file storage system according to said locally-altered permissions of said remote file storage system;

transferring said locally-altered permissions to said remote file storage system; and

controlling access to objects on said remote file storage system according to said locally-altered permissions of said remote file storage system.

7. The method of claim 6 , wherein said step of transferring said locally-altered permissions to said remote file storage system occurs in conjunction with a data synchronization process between said remote file storage system and said client file storage system.

8. The method of claim 6 , wherein said step of transferring said locally-altered permissions to said remote file storage system occurs in response to a command from a user.

9. The method of claim 6 , wherein said step of transferring said locally-altered permissions to said remote file storage system occurs in response to said step of locally altering said permissions of said remote file storage system at said client file storage system.

10. The method of claim 1 , wherein said step of defining permissions for said remote file storage system includes associating access control lists with said objects on said remote file storage system.

11. The method of claim 1 , additionally comprising:

defining a plurality of permissions sets for said remote file storage system;

associating each of said permissions sets with a respective one of a plurality of clients;

controlling access to objects on said remote file storage system by said clients according to said permissions sets of said remote file storage system;

transferring each of said permissions sets to a respective one of a plurality of client file storage systems each associated with one of said plurality of clients, said client file storage systems being remote from said remote file storage system; and

controlling access to objects on said client file storage systems according to said permission sets of said remote file storage system associated with said clients.

12. A remote file storage system comprising:

memory for storing file objects received from a client;

a client interface operative to receive said file objects from said client, to provide said file objects to said client, to receive data indicative of permissions associated with said file objects, and to provide a permissions file to said client;

a permissions file generator operative to generate said permissions file based on said data indicative of said permissions associated with said file objects, said permissions file defining different permissions for a plurality of said file objects; and

a permissions enforcer operative to control access to said file objects according to said permissions file; and wherein

said client interface is operative to receive additional data indicative of permissions associated with said file objects;

said permissions file generator is operative to generate an updated permissions file based at least in part on said additional data indicative of permissions associated with said file objects; and

said client interface is operative to provide said updated permissions file to said client.

13. The system of claim 12 , additionally comprising:

a processing unit; and wherein

said permissions file generator and said permissions enforcer are code modules executed by said processing unit.

14. The system of claim 12 , additionally comprising:

a virtual file system module operative to define a virtual file system structure for said file objects; and wherein

said permissions file generator is operative to generate said permissions file based at least in part on said virtual file system structure.

15. The system of claim 12 , additionally comprising a synchronizer operative to:

synchronize said file objects stored on said remote file storage system with file objects stored on a file storage system of said client; and

synchronize said permissions file with a permissions file on said file storage system of said client.

16. The system of claim 12 , wherein said permissions file associates access control lists with said file objects.

17. A local file storage system for use with a remote file storage system, said local file storage system including:

memory for storing local file objects from local clients;

a client interface operative to receive said local file objects from said local clients and to provide said local file objects to said local clients;

a remote file server interface operative to receive a permissions file from a remote file server, said permissions file being indicative of permissions associated with remote file objects stored on said remote file server, said remote file objects being copies of said local file objects; and

a permissions enforcer operative to control access to said local file objects by said local clients according to said permissions defined by said permissions file for said remote file objects; and wherein

said remote file server interface is further operative to receive an updated permissions file from said remote file server, said updated permissions file being indicative of updated permissions associated with at least some of said remote file objects stored on said remote file server; and

said permissions enforcer is further operative to control access to said local file objects by said local clients according to said updated permissions defined by said updated permissions file for said remote file objects.

18. The system of claim 17 , additionally comprising:

a virtual file system module operative to present a virtual file system structure associated with said local file objects to said local clients; and wherein

said permissions file is based at least in part on said virtual file system structure.

19. The system of claim 18 , wherein said permissions file associates access control lists with elements of said virtual file system structure.

20. A file storage system comprising:

a local file storage system including memory, said local file storage system being operative to store file objects from local clients in said memory and to provide said file objects to said local clients from said memory;

a remote file storage system including memory, said remote file storage system being operative to store copies of said file objects in said memory of said remote file storage system and to provide said copies of said file objects from said memory of said remote file storage system;

a permissions file generator on at least one of said local file storage system and said remote file storage system and operative to generate a permissions file and to provide said permissions file to said local file storage system and said remote file storage system;

a first permissions enforcer on said local file storage system, said first permissions enforcer operative to control access to said file objects on said local file storage system according to said permissions file; and

a second permissions enforcer on said remote file storage system, said second permissions enforcer operative to control access to said file objects on said remote file storage system according to said permissions file; and wherein

responsive to receiving additional data indicative of permissions associated with said file objects stored on said remote file storage system, said permissions file generator is further operative to

generate an updated permissions file based at least in part on said additional data and

provide said updated permissions file to said local file storage system and said remote file storage system;

responsive to receiving said updated permissions file, said first permissions enforcer is operative to control access to said file objects on said local file storage system according to said updated permissions file; and

responsive to receiving said updated permissions file, said second permissions enforcer is operative to control access to said file objects on said remote file storage system according to said updated permissions file.

21. The system of claim 20 , additionally comprising:

a file object synchronizer operative to synchronize said file objects stored on said remote server and said file objects stored on said local server; and

a permissions file synchronizer operative to synchronize said permissions file on said remote server and said permissions file on said local server.

22. The system of claim 20 , wherein said permissions file defines different permissions for a plurality of said file objects.

23. The method of claim 1 , wherein said step of transferring said permissions to a client file storage system remote from said remote file storage system includes transferring permissions information defining different permissions for a plurality of said objects.

24. The system of claim 17 , wherein said permissions file defines different permissions for a plurality of said remote file objects.

25. The system of claim 17 , wherein said permissions enforcer is operative to control access to said local file objects by analyzing said permissions file and overriding local permissions to grant or deny access to said local file objects.

26. The method of claim 1 , wherein said step of transferring said permissions to a client file storage system remote from said remote file storage system occurs over a wide area network.

Assignments (8)
SECURITY INTEREST Recorded Mar 25, 2025
From: EGNYTE, INC.
To: TCG SENIOR FUNDING, L.L.C., AS COLLATERAL AGENT
Reel/Frame 070614/0319 →
RELEASE OF SECURITY INTEREST Recorded Mar 14, 2025
From: JPMORGAN CHASE BANK, N.A.
To: EGNYTE, INC.
Reel/Frame 070518/0898 →
RELEASE OF SECURITY INTEREST Recorded Mar 14, 2025
From: JPMORGAN CHASE BANK, N.A.
To: EGNYTE, INC.
Reel/Frame 070519/0129 →
SECURITY INTEREST Recorded Apr 1, 2022
From: EGNYTE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 059568/0653 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY ADDRESS PREVIOUSLY RECORDED AT REEL: 55441 FRAME: 199. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 13, 2021
From: EGNYTE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 057210/0629 →
SECURITY INTEREST Recorded Mar 1, 2021
From: EGNYTE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055441/0199 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNOR LAST NAME FROM WIJAYARATNE TO KARIYAWASAM BODHITANTRI WIJAYARATNE, WHICH WAS PREVIOUSLY LISTED AS THE MIDDLE NAME PREVIOUSLY RECORDED ON REEL 039762 FRAME 0124. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 20, 2016
From: WHITE, RAY; MARATHE, MANISH; AAHZ (FULL LEGAL NAME), AAHZ (FULL LEGAL NAME); RAM, RAJESH; JASSAL, AMRIT; KARIYAWASAM BODHITANTRI WIJAYARATNE, RAVI
To: EGNYTE, INC.
Reel/Frame 040085/0047 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 16, 2016
From: WIJAYARATNE, RAVI KARIYAWASAM BODHITANTRI; WHITE, RAY; MARATHE, MANISH; AAHZ (FULL LEGAL NAME), AAHZ (FULL LEGAL NAME); RAM, RAJESH; JASSAL, AMRIT
To: EGNYTE, INC.
Reel/Frame 039762/0124 →
Continuity (2)
Provisional Application 61564628 · Nov 29, 2011
Related Publication 20140149461A1 · May 29, 2014