External File Sequestration for Risky Download Data Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Home users lack the technological knowledge to implement complex security measures for protecting data files, and existing data backup methods are inadequate against data theft and corruption from potentially risky downloads.

Innovation Solution

A computer system configured to temporarily store important files to an external data storage device upon detecting a potentially risky download, using a file protection manager to identify and transfer these files, and optionally deleting them from the host system to prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data backup methods are used, then data availability is improved, but protection against data theft and corruption from risky downloads is insufficient

Engineering Contradiction:
Improvedata protectionVSAvoiddata theft and corruption
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts critical data files from the host system's internal storage and moves them to an external data storage device. This extraction isolates the data from potential malware infections and unauthorized access attempts on the host system, while maintaining backup availability. The external storage device acts as a secure repository that is not compromised by risky downloads on the host.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The external data storage device serves as an intermediary between the host system and the data. Instead of data being directly accessible from the host system where it could be stolen or corrupted, the external device mediates data access. The system can retrieve data from this intermediary when needed, providing both protection and availability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If complex security measures are implemented, then data security is improved, but ease of operation deteriorates for home users

Engineering Contradiction:
Improvedata securityVSAvoiduser friendliness
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements self-service security by automatically detecting when data files need protection and autonomously transferring them to the external storage device. The file protection manager monitors downloads, identifies critical files, and executes transfers without requiring user intervention or technical knowledge. Users simply need to connect the external device and have it automatically protected.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary protective actions by proactively transferring data files to external storage before malicious software can compromise them. The file protection manager anticipates potential threats and pre-empts data theft by isolating critical files in advance, rather than requiring users to manually secure their data when problems arise.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12475223B2File protection using an external data storage device
Publication Date: 2025.11.18 SANDISK TECHNOLOGIES LLC
  • US12475223B2 patent drawing
  • US12475223B2 patent drawing
  • US12475223B2 patent drawing

AI summary

A host system is configured to sequester protected data files to a separate data storage device. The host system includes an input device for receiving commands from a user, storage media for storing data files including the protected data files, a communication interface configured to communicate with the separate data storage device, and a network interface configured to communicate with a network server. The host system includes one or more processors configured, individually or in combination, to receive from the user, via the input device, a request to download a file from the network server. In response to determining that the file is a potential risk to the host system, the one or more processors are further configured, individually or in combination, to transfer the first subset of files to the separate data storage device and subsequent to transferring the first subset of files, complete downloading the file.