CA2525249C

Distributed filesystem network security extension

Abstract

A security protocol that dynamically implements enhanced mount security of a filesystem when access to sensitive files on a networked filesystem is requested. When the user of a client system attempts to access a specially-tagged sensitive file, the server hosting the filesystem executes a software code that terminates the current mount and reconfigures the server ports to accept a re-mount from the client via a more secure port. The server reconfigured server port is provided the IP address of the client and matches the IP address during the re-mount operation. The switch to a secure mount is completed in a seamless manner so that authorized users are allowed to access sensitive files without bogging down the server with costly encryption and other resource-intensive security features. No significant delay is experienced by the user, while the sensitive file is shielded from unauthorized capture during transmission to the client system.

CA2525249C, drawing sheet 1
Sheet 1 of 11

Term

Term ended

Expired 15 April 2024, 2.4 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

17 claims: 2 independent, 15 dependent

  1. 1
    CA 02525249 2010-11-05 AUS920030048CA1 13 CLAIMS 1. A method for providing security for transmission of at least a first file, the method being for use in a data processing system comprising (1) a storage medium on which is stored said at least a first file having a preset access permission, (2) at least a first standard port and second secure port for connecting said data processing system to external client systems, (3) a logic component for selectively routing transmission of said at least one file via said first port and said second port, and (4) a reconfiguration logic component for configuring said first standard port and said second secured port for supporting a mount by said client system, said method comprising:responsive to a request for access to said first file by said external client system, checking said preset access permission of said first file;and when said preset access permission of said first file indicates secured access is required for said first file, dynamically routing a transmission of said first file to external client system via said second port, said dynamic routing step comprising: first configuring said second secure port to support a remount operation received from said client system;terminating a current mount on said first standard port with said client system;and storing session parameters of said current mount to enable seamless continuation of said session on said second secure port.
  2. 2
    The method of Claim 1, further comprising:routing said transmission of said first file via said first standard port when said preset access permission indicates a regular access is sufficient. The method of Claim 1, further comprising: CA 02525249 2010-11-05 AUS920030048CA1 14 enabling a first mount of said data processing system via said first standard port;and enabling a second mount of said data processing system via said second secure port only when said first file requires secured access.
  3. 3
    4. The method of Claim 1, wherein said data processing system further comprises an encryption module associated with said second secured port, said dynamic routing step comprising:first encrypting said first file utilizing said encryption module.
  4. 4
    5. The method of Claim 4, wherein said configuring and storing step includes:retrieving an IP address of said client system;placing said IP address in a configuration of said second secure port, wherein said second secure port automatically recognizes a remount operation from said client system and re-establishes the session with said client system.
  5. 5
    6. The method of Claim 1, wherein said preset access permission is a bit within metadata linked to said first file and said method further comprises reading a value of said bit to evaluate whether said first file requires secure access.
  6. 6
    7. The method of Claim 1, wherein said preset access permission includes an identification of which specific users are permitted to access said first file via a secured access, said method further comprising;comparing a user of said client system with said specific users with permission to access said file;and when said user is one of said specific users, automatically initiating a rerouting of a transmission of said first file via said second secure port.
  7. 7
    8. The method of Claim 1, wherein said first standard port connects to said client system via a first unsecured network and said second secure port connects to said client system via a second secured network. CA 02525249 2010-11-05 AUS920030048CA1
  8. 8
    9. The method of Claim 1, wherein:said data processing system is a server within a network having a first subnet connecting said first standard port to said client system and a second subnet connecting said second secure port to said client system;said first file is stored within a filesystem;said checking step includes accessing said filesystem and locating said first file;and said routing step includes transmitting said file via said second subnet when said file requires secure access and transmitting said first file via said first subnet when said first file does not require secure access.
  9. 9
    10. A system for providing security for transmission of at least a first file, for use in a data processing system comprising (1) a storage medium on which is stored said at least a first file having a preset access permission, (2) at least a first standard port and a second secure port for connecting said data processing system to external client systems, and (3) means for selectively routing transmission of said at least one file via said first port and said second port, said system comprising:means, responsive to a request for access to said first file by said external client system, for checking said preset access permission of said first file;reconfiguration means for configuring said first standard port and said second secured port for supporting a mount by said client system;and when said preset access permission of said first file indicates secured access is required for said first file, means for dynamically routing a transmission of said first file to external client system via said second port, said means for dynamically routing comprising: means for first configuring said second secure port to support a remount operation received from said client system;means for terminating a current mount on said first standard port with said client system;and CA 02525249 2010-11-05 AUS920030048CA1 16 means for storing session parameters of said current mount to enable seamless continuation of said session on said second secure port.
  10. 10
    11. The system of Claim 10, further comprising:means for routing said transmission of said first file via said first standard port when said preset access permission indicates a regular access is sufficient.
  11. 11
    12. The system of Claim 10, further comprising:means for enabling a first mount of said data processing system via said first standard port;and means for enabling a second mount of said data processing system via said second secure port only when said first file requires secured access.
  12. 12
    13. The system of Claim 10, wherein said data processing system further comprises an encryption module associated with said second secured port, said logic for dynamically routing comprising:means for first encrypting said first file utilizing said encryption module.
  13. 13
    14. The system of Claim 10, wherein said configuring and storing step includes:means for retrieving an IP address of said client system;means for placing said IP address in a configuration of said second secure port, wherein said second port automatically recognizes a remount operation from said client system and re-establishes the session with said client system.
  14. 14
    15. The system of Claim 10, wherein said preset access permission is a bit within metadata linked to said first file and said system further comprises reading a value of said bit to evaluate whether said first file requires secure access.
  15. 15
    16. The system of Claim 10, wherein said preset access permission includes an identification of which specific users are permitted to access said first file via a secured access, said system further comprising:CA 02525249 2010-11-05 AUS920030048CA1 17 means for comparing a user of said client system with said specific users with permission to access said file;and when said user is one of said specific users, means for automatically initiating a re-routing of a transmission of said first 5 file via said second secure port.
  16. 16
    17. The system of Claim 10, wherein said first standard port connects to said client system via a first unsecured network and said second secure port connects to said client system via a second secured network.
  17. 17
    18. The system of Claim 10, wherein:said data processing system is a server within a network having a first subnet connecting said first standard port to said client system and a second subnet 15 connecting said second secure port to said client system;said first file is stored within a filesystem;said means for checking includes means for accessing said filesystem and locating said first file;and said means for routing includes means for transmitting said file via said second subnet when said file requires secure access and transmitting said first file via said first subnet when said first file does not require secure access.