Group Policy Device Access Control via Class Identifier

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack the ability to control access rights to unique class identifier devices and removable storage devices network-wide using the group policy framework, posing security risks as these devices are not recognized by the operating system until their class identifier is known, at which point access restrictions can be applied.

Innovation Solution

A system that allows IT administrators to set access rights for unique class identifier and removable storage devices through a user interface on a control server, using group policy objects defined in administrative templates, which are then implemented on client terminals during device installation or upon changes in group policy settings, ensuring centralized management and enforcement of access permissions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If removable storage devices are completely forbidden or ports are disabled, then security risks are reduced, but usability and data transfer capabilities are lost

Engineering Contradiction:
ImprovesecurityVSAvoidusability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies different access control policies to different removable storage devices based on their device class identifiers. Instead of a blanket ban or enablement, the system selectively controls access rights for specific device classes (e.g., USB flash drives vs. optical drives), allowing targeted security measures that preserve usability for trusted devices while blocking access to potentially malicious ones.

Inventive Principle:
Principle #3Local quality

2Extent of automation

If group policy is used to control device access, then centralized management is improved, but the ability to control unique class identifier devices is currently unavailable

Engineering Contradiction:
Improvecentralized managementVSAvoiddevice control capability
Core Design Contradiction:
Extent of automationVSAdaptability or versatility

Solution Approach 1:

The patent enables administrators to define group policy objects and access control templates in advance before devices are connected. When a removable storage device is inserted, the system automatically identifies its device class identifier and applies the pre-defined group policy, eliminating the need for real-time manual configuration and enabling centralized automated management of previously uncontrollable device types.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If access control is applied to each device individually, then security precision is improved, but system complexity increases

Engineering Contradiction:
Improveaccess control precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent creates a universal group policy framework that can be applied across multiple device types and scenarios through a single administrative interface. Administrators define once and the policy applies to all devices matching the specified criteria (device class, user group, computer group), eliminating the need for separate access control configurations for each device while maintaining precise control over access rights.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7971232B2Setting group policy by device ownership
Publication Date: 2011.06.28 MICROSOFT TECHNOLOGY LICENSING LLC
  • US7971232B2 patent drawing
  • US7971232B2 patent drawing
  • US7971232B2 patent drawing

AI summary

A system is disclosed for centralized management of access permissions to specific devices on client terminals using a group policy framework. The system identifies a unique device identifier for a specific device, and allows policy to be set for the specific device based on identifying the specific device by its unique device identifier.