Intermediary Security Device for Mobile Data Exchange
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile devices and host devices are vulnerable to malicious code and data transfer risks when connected to external devices or the internet without a network security system, lacking the first line of defense and potentially spreading threats back to secure networks.
Innovation Solution
A security device with a processor, memory, and a security engine that enforces security policies on data transfer requests between host and external devices, using a USB standard or wireless connections to protect against viruses, spyware, and unauthorized data transfer, and a mobile security system acting as a gateway to provide two lines of defense for mobile devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If mobile devices connect to the internet outside the enterprise network, then device mobility and access to information are improved, but vulnerability to malicious code and attacks increases
Solution Approach 1:
The patent introduces a mobile security system that acts as an intermediary device between the mobile device and the internet. This security system provides firewall, antivirus, and content filtering capabilities, serving as a mediator that allows internet access while protecting against threats. The security system can be physically connected to the mobile device or integrated into it, creating a buffer zone that maintains security policies even when outside the enterprise network.
Solution Approach 2:
The patent segments the security functionality by separating it from the main mobile device into a dedicated mobile security system. This segmentation allows the security functions (firewall, antivirus, content filtering) to operate independently and enforce enterprise security policies without interfering with the mobile device's primary functions. The segmented architecture enables the mobile device to maintain mobility while the security system provides specialized protection.
2Ease of operation
If mobile devices connect directly to the internet without a network security system, then device simplicity and ease of operation are improved, but the first line of defense is lost increasing vulnerability to attacks
Solution Approach 1:
The mobile security system serves as an intermediary that transparently handles security functions. Users connect their mobile devices to the security system, and all internet traffic automatically passes through the security filters without requiring user awareness or intervention. This intermediary approach maintains ease of operation while providing comprehensive security protection against malicious code, spyware, and content filtering.
3Productivity
If devices transfer data between external devices and host systems, then data exchange functionality is improved, but risk of data breaches and malicious code transfer increases
Solution Approach 1:
The patent implements preliminary security actions by scanning and filtering data before it is transferred between external devices and host systems. The security system performs antivirus scanning, content filtering, and policy enforcement on incoming and outgoing data transfers. This preliminary action ensures that malicious code is detected and blocked before it can compromise the host system or data breaches occur before sensitive information is exposed.
Solution Approach 2:
The security system provides continuous feedback monitoring of data transfer activities. It tracks data flow between external devices and host systems, enforcing security policies in real-time. When potential threats or policy violations are detected during data transfer, the system provides feedback by blocking the transfer and alerting users or administrators, thereby preventing data breaches while maintaining legitimate data exchange functionality.
Data Source
AI summary
A secure data exchange system comprising a security device including a first external device plug, and a security engine operative to enforce a security policy on data transfer requests received from the host; an external device including a second external device plug; and a host including a first external device port operative to communicatively couple with the first external device plug, a second external device port operative to communicatively couple with the second external device plug, and a driver, e.g., a redirect driver, operative to transfer a data transfer request to the security device before executing the data transfer request.


