BRIEF DESCRIPTION OF THE SEVERAL VIEWS OF THE DRAWINGS
FIG. 1 illustrates different components of the storage system on a computer.
FIG. 2 illustrates an example for states of an ADUPHardware that accepts DUPManualActions and authenticates the users.
FIG. 3 illustrates an example for states of a device driver that control the ADUPHardware and a file system module which flushes dirty buffers of a user in the file system buffer cache to mass memory and removes association between the user and the buffers in the buffer cache, before sending a message containing the identifier of the user to the ADUPHardware device driver.
FIG. 4 illustrates an example for states of a module in the storage component that implements access restrictions for each user.
FIG. 5 illustrates an example of how different components interact when used with an ADUPHardware that accepts DUPManualActions and authenticates users.
DETAILED DESCRIPTION OF THE INVENTION
FIG. 2 illustrates an example for different states of an ADUPHardware that is attached to a computer and accepts DUPManualActions. The ADUPHardware awaits 201 either a DUPManualAction from a user or a computer command. The ADUPHardware checks 202 the type of input, DUPManualAction or a command from computer. When a DUPManualAction is received, the ADUPHardware checks 204 whether the user and the state requested by the DUPManualAction are valid. If the user or the state is invalid, the DUPManualAction is ignored (discarded). If the user and state are valid, the user is prompted 205 for a password. If the password entered by the user is invalid 206, the ADUPHardware ignores (discards) the DUPManualAction. If the password entered by the user is valid 207, the ADUPHardware updates 207 a register readable by the computer, with the identifier of the user and interrupts 205 the computer using a hardware interrupt, such as PCI interrupt. The computer cannot write into the ADUPHardware register containing the identifier of the user. The ADUPHardware then returns to the state where it waits for a DUPManualAction or a computer command. When ADUPHardware receives a computer command 203 to change the state of the ADUPHardware corresponding to a user, the ADUPHardware changes the state of the user to the state selected through DUPManualAction by the user. Since the state requested by the user is not communicated to the computer, no malicious software can control the state of the ADUPHardware corresponding to a user. The ADUPHardware updates a register readable by the computer 203, with the state corresponding to the user. The computer cannot write into the register containing the state of ADUPHardware corresponding to a user.
Preferably, if more than one DUPManualAction is received for the same user before the state corresponding to the user is changed, the ADUPHardware will change state corresponding to the user to the state corresponding to the last authenticated DUPManualAction made by the user. Optionally, if more than one DUPManualAction is received for the same user before the state corresponding to the user is changed, the ADUPHardware will change the state corresponding to the user to the state corresponding to the first authenticated DUPManualAction made by the user after the last state change for the user. Some implementations may even change the state to one of the states corresponding to an authenticated DUPManualAction between the first manual action after the last state change and the last manual action depending on some other criteria.
The DUPManualAction on an ADUPHardware may be pressing one or more buttons and/or toggling the position of one or more switches and/or turning a wheel and/or changing one or more jumper positions and/or any other DUPManualAction supported by the ADUPHardware.
The ADUPHardware may use registers or memory locations readable by the computer to communicate the identifier of the user who initiated DUPManualAction and the current state of ADUPHardware corresponding to a user. A computer should not be allowed to write into these registers or memory locations. This improves security as a malicious software will not be able to manipulate the state of the hardware corresponding to each user.
An ADUPHardware may control one or more mass memories. There could be one or more ADUPHardwares on a computer, each controlling states corresponding to a mutually exclusive set of users. Some implementations may use more than one ADUPHardware on the same computer, each controlling states corresponding to sets of users which are not mutually exclusive, but we do not recommend such implementations.
There could be different behaviors for the ADUPHardware while accepting passwords. If password entered by a user is invalid, the ADUPHardware could again prompt the user for password and accept a new password from the user until a valid password is received or until the maximum number of password retries is reached or if the user cancels the request to reenter the password. The ADUPHardware that supports retries, will ignore (discard) DUPManualAction only if a valid password is not received even after maximum number of password retries or if the user cancels the password retry. The ADUPHardware may also prompt for a user name in addition to the password. The ADUPHardware may also prompt for a password before the state entered by the user is validated. The method used by an ADUPHardware for authenticating a user using a password is implementation specific.
The ADUPHardware may use other options for validating a user such as finger print validation, retina validation, other current and future technologies for user authentication. The ADUPHardware may also use a combination of two or more of password validation, finger print validation, retina validation, etc., for validating the user. The method used by a ADUPHardware for authenticating a user is implementation specific.
FIG. 3 illustrates an example for states of a device driver which runs on a computer and controls the ADUPHardware which accepts DUPManualActions. The ADUPHardware device driver runs 301 either when an interrupt from the ADUPHardware or a message from the file system arrives. The ADUPHardware device driver checks 302 the type of input, an interrupt or a file system message. When an interrupt is received 303, the driver sends a request to the file system to flush dirty buffers belonging to the user/s who identifier/s are present in the computer readable user registers. Only the identifiers of users who performed DUPManualActions will be present in the computer readable user registers of ADUPHardware. A buffer in the file system buffer cache is considered dirty if the user has written into the buffer. The file system flushes (writes to mass memories) 305 the dirty buffers in the file system buffer cache belonging to the user, resets the user identifier in all the buffers that were assigned to the user and then, sends a message 306 containing the user identifier, to the ADUPHardware device driver. The ADUPHardware device driver sends 304 a command to the ADUPHardware to change the state corresponding to the user.
If there are more than one file systems on a computer, the ADUPHardware device driver must send messages containing the identifier of the user to all the file systems on the computer. The ADUPHardware device driver will command ADUPHardware to change the state corresponding to a user only after all the file systems flush dirty buffers assigned to the user and resets the user identifier in all the buffers that were assigned to the user.
The ADUPHardware device driver may use one message for each user to request a file system to flush buffers corresponding to the user.
An ADUPHardware device driver may control one or more ADUPHardware. There could be one or more ADUPHardware device drivers running on a computer each controlling a mutually exclusive set of ADUPHardware.
There could be one or more storage components or new modules that implement access control according to the invention on a computer. We refer to the modules that implement access control according to the invention as DUPImplementers. When an upper layer module sends a new read or write request to the a DUPImplementer, the DUPImplementer will get the current ADUPHardware state corresponding to the user on whose behalf the read or write request was created. The DUPImplementer is configured with information on portions of mass memories and type of access (read or write) allowed or denied for each portion of mass memory, for each combination of user and state. The DUPImplementer checks the portions of mass memory or mass memories accessed by the read or write request against the configuration. If a read or write requests violates the access restrictions, the read or write request is not allowed to proceed and is returned with error. If no configuration is present for a portion of mass memory, DUPImplementers are configured either to allow or to block the read or write request that access such a portion.
FIG. 4 illustrates an example for a storage component that is a DUPImplementer. The storage component processes read or write requests 401. When a new read or write request arrives, the storage component will read or get the ADUPHardware state 402 corresponding to the user on whose behalf the read or write request was created. The storage component checks 403 whether the read or write request violates access restrictions configured corresponding to the current state of the user. If access is not allowed 404, the read or write request is returned to the upper layer with error. If the access is allowed 405 the read or write request is allowed to proceed.
A user is allowed access to portions of a mass memory or memories by privileged users. The portions of mass memories to which each user has access is not mutually exclusive. The portions of mass memories to which a user has access and the type of access is written to a portion of the mass memory to which only privileged users has access. The area of the mass memory where this configuration is stored is protected by the ADUPHardware.
A configuration software allows each user to further divide these portions of mass memory or mass memories to which the user has access. The configuration software further allows a user to enable or disable read or write access to each of these divided portions and associate the access restrictions to a state of the ADUPHardware corresponding to the user. Preferably, the access restrictions associated with each state is independent of access restrictions associated with other states of the ADUPHardware corresponding to the same user. Optionally, access restrictions are such that there are dependencies between access restrictions corresponding to some or all of the states corresponding to a user.
Preferably, the configuration corresponding to a user is written to a predefined area of the mass memory or mass memories, selected on the basis of the user identifier and write to this area is enabled for the user only on one or more states of ADUPHardware corresponding to the user. Preferably, no other user, including privileged users has write or read access to this area of the mass memory or mass memories.
FIG. 5 illustrates an example of interaction between different components in a computer 501 that implement read and write protection for each user to parts of a mass memory, using an ADUPHardware 506508 that accepts DUPManualActions. Only components that are changed or affected by the invention are shown. The ADUPHardware 506 writes the identifier of the user in a memory location readable by the computer and interrupts the computer after a user performs DUPManualAction to change the state corresponding to the user and the user is authenticated. The ADUPHardware device driver 507 processes the interrupt and reads the identifier of the user from the ADUPHardware. The ADUPHardware device driver will send a request to the file system 504 to flush dirty buffers assigned to the user. The file system 504 goes through the list of buffers assigned to the user, writes (flushes) dirty buffers that were assigned to the user to the mass memory and removes the association between the user and the buffer. After removing the association between the user and all the buffers that were assigned to the user, the file system 504 sends a message to the ADUPHardware device driver 507. The ADUPHardware device driver sends a command to the ADUPHardware to change it's state corresponding to the user. Part of the ADUPHardware 508 is enclosed in the disk enclosure 510. In this example, the configuration software 502 configures the file system 504, the storage stack 503 and disk controller firmware 509 to implement access restrictions for users. The storage stack gets the state of the ADUPHardware corresponding to a user by reading the computer readable memory in the ADUPHardware containing states. The file system gets the state of ADUPHardware corresponding to a user through the ADUPHardware device driver, which reads the computer readable memory in the ADUPHardware containing states. The disk controller firmware 509 gets the state of the ADUPHardware by reading a memory in the ADUPHardware 506508 containing the current state for each user using an interface within the disk enclosure. The state of the ADUPHardware corresponding to a user is used by the storage stack, the disk controller firmware and the file system to implement access restrictions for the user configured using the configuration software. The configuration software interacts with the storage stack to write the configuration to the disk 505. The configuration is read by the storage stack, the disk controller firmware, the file system and the configuration software. The file system and the configuration software interact with the storage stack to read the configuration from the disk 505. The components which are not affected by the invention such as Interface Driver, HBA, Disk Controller, etc., are not shown.
The protection provided by ADUPHardware need not be limited to mass memories alone. Other modules that implement access protections could check the current state of the ADUPardware corresponding to a user and implement access restrictions based on the current state and configuration associated with that state for the modules.
Since ADUPHardware or part of ADUPHardware can be enclosed in the same mass memory that is being protected, there is less risk to data even if the laptop of a user is stolen.
The authentication is done by ADUPHardware and a malicious software will not be able to manipulate the authentication process.