Gate Device Security Tagging for Network File Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing access control methods for protecting files in computer networks are either file system-dependent, require user categorization, or necessitate encryption, which are not effective in selectively limiting access or protecting files from unauthorized copying and transmission.
Innovation Solution
A gate device is employed in communication channels to check for a security tag on files being sent to external connections, limiting access based on the presence or absence of this tag, and optionally encrypting files or using anti-tamper codes to ensure protection, thereby providing domain-specific security without additional measures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If access control codes are stored in the file system to guarantee confidentiality, then access control is provided, but the system becomes bound to the file system and requires user categorization
Solution Approach 1:
The patent extracts the security control mechanism from the file system and places it in the communication channel via a gate device. The gate device checks for security tags on files during transmission, separating the access control function from file system dependencies and user categorization requirements.
Solution Approach 2:
The patent introduces a gate device as an intermediary in the communication channel that mediates file transmission by checking for security tags. This intermediary provides access control without requiring file system integration or user categorization, as it operates independently on the communication level.
2Reliability
If encryption is used to protect confidential files, then content-containing copies are protected wherever they are, but a key and decryption are required before access is possible
Solution Approach 1:
The patent applies security tags selectively to specific files that require protection, rather than encrypting all files. Files with security tags receive enhanced protection during transmission, while files without tags remain freely accessible, providing localized security where needed without universal encryption overhead.
Solution Approach 2:
The patent applies security tags to files in advance before transmission. The gate device then automatically recognizes and blocks these tagged files during communication, eliminating the need for real-time decryption keys while maintaining protection. The security measure is prepared beforehand and enforced automatically.
3Object-affected harmful factors
If a firewall is used to block file reception, then protection against computer viruses is provided, but confidential files among files sent by the computer system are not protected
Solution Approach 1:
The patent inverts the traditional firewall approach by instead of blocking unwanted files, it selectively allows only files with security tags to pass through the gate device. This inverted selection process protects confidential files during outbound transmission while still providing virus protection for inbound files, addressing both limitations of conventional firewalls.
Data Source
AI summary
The computer system comprises a local network domain of communicating computers and a connection for communication with an external network. A gate device coupled between the local network and the connection is arranged to check files sent from the local network to the connection for the presence of a security tag in the file, and to send or not send on each file to the connection depending on detection of the presence or absence of the security tag in the file.

