Intermediary Security Device for Mobile Data Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices and host devices are vulnerable to malicious code and data transfer risks when connected to external devices or the internet without a network security system, lacking the first line of defense and potentially spreading threats back to secure networks.

Innovation Solution

A security device with a processor, memory, and a security engine that enforces security policies on data transfer requests between host and external devices, using a USB standard or wireless connections to protect against viruses, spyware, and unauthorized data transfer, and a mobile security system acting as a gateway to provide two lines of defense for mobile devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If mobile devices connect to the internet outside the enterprise network, then device mobility and access to information are improved, but vulnerability to malicious code and attacks increases

Engineering Contradiction:
Improvedevice mobilityVSAvoidsecurity protection
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a mobile security system that acts as an intermediary device between the mobile device and the internet. This security system provides firewall, antivirus, and content filtering capabilities, serving as a mediator that allows internet access while protecting against threats. The security system can be physically connected to the mobile device or integrated into it, creating a buffer zone that maintains security policies even when outside the enterprise network.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the security functionality by separating it from the main mobile device into a dedicated mobile security system. This segmentation allows the security functions (firewall, antivirus, content filtering) to operate independently and enforce enterprise security policies without interfering with the mobile device's primary functions. The segmented architecture enables the mobile device to maintain mobility while the security system provides specialized protection.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If mobile devices connect directly to the internet without a network security system, then device simplicity and ease of operation are improved, but the first line of defense is lost increasing vulnerability to attacks

Engineering Contradiction:
Improvedevice simplicityVSAvoidmalicious code vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The mobile security system serves as an intermediary that transparently handles security functions. Users connect their mobile devices to the security system, and all internet traffic automatically passes through the security filters without requiring user awareness or intervention. This intermediary approach maintains ease of operation while providing comprehensive security protection against malicious code, spyware, and content filtering.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If devices transfer data between external devices and host systems, then data exchange functionality is improved, but risk of data breaches and malicious code transfer increases

Engineering Contradiction:
Improvedata exchange functionalityVSAvoiddata breach risk
Core Design Contradiction:
ProductivityVSObject-generated harmful factors

Solution Approach 1:

The patent implements preliminary security actions by scanning and filtering data before it is transferred between external devices and host systems. The security system performs antivirus scanning, content filtering, and policy enforcement on incoming and outgoing data transfers. This preliminary action ensures that malicious code is detected and blocked before it can compromise the host system or data breaches occur before sensitive information is exposed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security system provides continuous feedback monitoring of data transfer activities. It tracks data flow between external devices and host systems, enforcing security policies in real-time. When potential threats or policy violations are detected during data transfer, the system provides feedback by blocking the transfer and alerting users or administrators, thereby preventing data breaches while maintaining legitimate data exchange functionality.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11652829B2System and method for providing data and device security between external and host devices
Publication Date: 2023.05.16 CUPP COMPUTING
  • US11652829B2 patent drawing
  • US11652829B2 patent drawing
  • US11652829B2 patent drawing

AI summary

A secure data exchange system comprising a security device including a first external device plug, and a security engine operative to enforce a security policy on data transfer requests received from the host; an external device including a second external device plug; and a host including a first external device port operative to communicatively couple with the first external device plug, a second external device port operative to communicatively couple with the second external device plug, and a driver, e.g., a redirect driver, operative to transfer a data transfer request to the security device before executing the data transfer request.