Group Policy Control for Unique Class Identifier Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack the ability to control access rights to unique class identifier devices and removable storage devices network-wide using the group policy framework, posing security risks as these devices can be used to smuggle confidential data and introduce malicious software.

Innovation Solution

A system that allows IT administrators to set access rights for unique class identifier devices and removable storage devices through a user interface on a control server, using group policy objects defined via administrative templates, which are implemented on client terminals during device installation or upon changes in group policy settings.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If removable storage devices are completely forbidden or ports are disabled, then security risks are reduced, but usability and data transfer capability are lost

Engineering Contradiction:
ImprovesecurityVSAvoidusability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies different access rights to different device classes (removable storage devices vs. fixed storage devices) rather than applying a uniform restriction. This allows selective control where removable storage devices can be restricted while fixed storage devices remain accessible, resolving the contradiction between security and usability.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements dynamic access control through group policy objects that can be configured and updated. Access rights to removable storage devices can be dynamically adjusted based on user groups, device types, and security policies, allowing the system to adapt between secure and usable states as needed.

Inventive Principle:
Principle #15Dynamics

2Extent of automation

If group policy is used to control software features, then centralized management is achieved, but control over removable storage devices and unique class identifier devices is not available

Engineering Contradiction:
Improvecentralized managementVSAvoiddevice control capability
Core Design Contradiction:
Extent of automationVSAdaptability or versatility

Solution Approach 1:

The patent extends the group policy framework to universally control not only software features but also hardware device access. By making the group policy system multi-functional, it can now manage both software configurations and hardware access rights through the same centralized infrastructure, thereby achieving both centralized management and expanded device control capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments device control into separate policy categories within the group policy framework. Different device classes (removable storage, unique class identifier devices, fixed storage) can have distinct access policies applied, allowing fine-grained control while maintaining centralized management through the unified group policy system.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If access rights are not controlled for unique class identifier devices, then device flexibility is maintained, but security vulnerabilities increase

Engineering Contradiction:
Improvedevice flexibilityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by establishing access control policies before devices are used. Group policy objects are configured in advance to define which users can access which device classes, and these policies are applied automatically when devices are connected or when users attempt to access them, preventing security vulnerabilities before they can manifest.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8166515B2Group policy for unique class identifier devices
Publication Date: 2012.04.24 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8166515B2 patent drawing
  • US8166515B2 patent drawing
  • US8166515B2 patent drawing

AI summary

A system is disclosed for centralized management of access permissions to unique class identifier devices on client terminals using a group policy framework. The system includes a first aspect whereby administrative templates related to the unique class identifier devices are used to configure a user interface allowing an IT administrator or other to set access permissions for the unique class identifier devices. The system further includes a second aspect for implementing the access permissions to the unique class identifier devices on the client terminals.