Firewall Protection for Mass-Storage Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security measures for host systems against mass-storage devices, such as USB flash drives, are limited in addressing a broad array of information-security risks and typically focus on specific threats like viruses or access control, failing to comply with comprehensive information-security policies.

Innovation Solution

Implementing a method that routes communication between a host system and mass-storage devices through a network protocol, using a firewall to emulate a network drive and apply security measures, thereby protecting the host system from various risks by configuring the firewall to restrict access and apply security rules.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If mass-storage devices are directly connected to host systems for easy data access, then ease of operation is improved, but information-security risks increase

Engineering Contradiction:
Improvedata access convenienceVSAvoidinformation-security risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a firewall as an intermediary component between the host system and mass-storage devices. The firewall intercepts and filters communication traffic, allowing legitimate data access while blocking malicious operations. This mediator approach maintains user convenience while providing security enforcement without requiring direct connection changes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the communication path by creating separate layers: the host system layer, the firewall layer, and the mass-storage device layer. By segmenting the direct connection into controlled communication channels through the firewall, the system maintains operational ease while introducing security checkpoints that prevent harmful factors.

Inventive Principle:
Principle #1Segmentation

2Reliability

If existing security measures like anti-virus programs are used, then specific virus protection is improved, but comprehensive security coverage deteriorates

Engineering Contradiction:
Improvevirus protection effectivenessVSAvoidcomprehensive security coverage
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent makes the firewall universal by configuring it to handle multiple security functions simultaneously: virus protection, unauthorized access prevention, data leakage blocking, and other information-security threats. This single multi-functional firewall replaces multiple specialized tools, providing comprehensive coverage while maintaining effective protection across all threat types.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If mass-storage devices are recognized as network devices, then firewall protection capability is improved, but device complexity increases

Engineering Contradiction:
Improvefirewall protection capabilityVSAvoidsystem configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent inverts the traditional approach by not modifying the mass-storage device itself, but rather by changing how the host system perceives and communicates with the device. By recognizing the mass-storage device as a network device and applying firewall rules to network traffic, the system gains comprehensive protection without adding complexity to the storage device hardware or firmware.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS8806604B2Methods for firewall protection of mass-storage devices
Publication Date: 2014.08.12 SANDISK ISRAEL LTD
  • US8806604B2 patent drawing
  • US8806604B2 patent drawing
  • US8806604B2 patent drawing

AI summary

The present invention discloses methods for protecting a host system from information-security risks posed by a URD, the method including the steps of: operationally connecting the URD to the host system; communicating, between the URD and the host system, via a network protocol, through a firewall residing in the host system; and configuring said firewall to provide security measures related to the URD. Preferably, the firewall is a software firewall or a hardware firewall. A method for protecting a host system from information-security risks posed by a URD, the method including the steps of: operationally connecting the URD to the host system; communicating, between the URD and the host system, via a network protocol, through a firewall residing in the host system; and configuring said firewall to restrict access of at least one application to the URD. Preferably, the firewall is a software firewall or a hardware firewall.