| CPC G06F 21/62 (2013.01) [G06F 16/164 (2019.01); H04L 63/10 (2013.01)] | 20 Claims |

|
1. A method, comprising:
receiving a request from a user to access data stored in a filesystem;
generating access request metadata based on the request from the user;
in response to the request, retrieving metadata of the data and metadata of the user;
validating the metadata of the data, the metadata of the user, and the access request metadata against a data access rule which is an element of a context-based hierarchical policy, and the data access rule follows the data and is enforced by an entity external to the data, wherever the data is located, and the data access rule is enforced regardless of how the data is requested to be accessed;
granting the user access to the data upon successful validation of the metadata of the data and the metadata of the user; and
when a kernel underlying the filesystem, and operable to perform data access checks in conjunction with a security provider and communicate data access decisions, erroneously generates an indication to the filesystem that access to the data should be granted to the user, overriding the indication and denying access to the data by the user.
|