Group Policy Control for Unique Class Identifier Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems lack the ability to control access rights to unique class identifier devices and removable storage devices network-wide using the group policy framework, posing security risks as these devices can be used to smuggle confidential data and introduce malicious software.
Innovation Solution
A system that allows IT administrators to set access rights for unique class identifier devices and removable storage devices through a user interface on a control server, using group policy objects defined via administrative templates, which are implemented on client terminals during device installation or upon changes in group policy settings.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If removable storage devices are completely forbidden or ports are disabled, then security risks are reduced, but usability and data transfer capability are lost
Solution Approach 1:
The patent applies different access rights to different device classes (removable storage devices vs. fixed storage devices) rather than applying a uniform restriction. This allows selective control where removable storage devices can be restricted while fixed storage devices remain accessible, resolving the contradiction between security and usability.
Solution Approach 2:
The patent implements dynamic access control through group policy objects that can be configured and updated. Access rights to removable storage devices can be dynamically adjusted based on user groups, device types, and security policies, allowing the system to adapt between secure and usable states as needed.
2Extent of automation
If group policy is used to control software features, then centralized management is achieved, but control over removable storage devices and unique class identifier devices is not available
Solution Approach 1:
The patent extends the group policy framework to universally control not only software features but also hardware device access. By making the group policy system multi-functional, it can now manage both software configurations and hardware access rights through the same centralized infrastructure, thereby achieving both centralized management and expanded device control capability.
Solution Approach 2:
The patent segments device control into separate policy categories within the group policy framework. Different device classes (removable storage, unique class identifier devices, fixed storage) can have distinct access policies applied, allowing fine-grained control while maintaining centralized management through the unified group policy system.
3Adaptability or versatility
If access rights are not controlled for unique class identifier devices, then device flexibility is maintained, but security vulnerabilities increase
Solution Approach 1:
The patent applies preliminary action by establishing access control policies before devices are used. Group policy objects are configured in advance to define which users can access which device classes, and these policies are applied automatically when devices are connected or when users attempt to access them, preventing security vulnerabilities before they can manifest.
Data Source
AI summary
A system is disclosed for centralized management of access permissions to unique class identifier devices on client terminals using a group policy framework. The system includes a first aspect whereby administrative templates related to the unique class identifier devices are used to configure a user interface allowing an IT administrator or other to set access permissions for the unique class identifier devices. The system further includes a second aspect for implementing the access permissions to the unique class identifier devices on the client terminals.


