Kernel Mode Data Management Program for External Storage Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data management systems fail to effectively prevent unauthorized access, copying, and misuse of user data provided to clients, particularly in scenarios where confidentiality and intended usage are critical.

Innovation Solution

An electronic computer data management method and program that controls I/O devices to restrict access to external storage devices, prohibits unauthorized reading and writing, and limits network usage, using a driverware system that operates in kernel mode to enforce permissions based on a process control list.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If user data is provided to clients on portable storage devices, then clients can freely access and utilize the data, but unauthorized copying and misuse cannot be prevented

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a data management system as an intermediary layer between the client and the portable storage device. This system includes a control unit that mediates all data access operations, allowing legitimate client access while preventing unauthorized copying. The intermediary monitors and controls data read operations, enabling ease of operation for authorized users while ensuring data security through centralized control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements a feedback mechanism where the control unit continuously monitors data access operations and provides real-time control decisions. The system receives feedback about access requests, evaluates them against security rules, and responds by permitting or blocking operations. This feedback loop ensures that data accessibility is maintained for authorized operations while automatically preventing unauthorized copying and misuse.

Inventive Principle:
Principle #23Feedback

2Reliability

If access control is implemented to prevent unauthorized copying, then data security is improved, but data accessibility and usability are reduced

Engineering Contradiction:
Improvedata securityVSAvoiddata utilization efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by implementing differentiated access control for different data operations and different clients. The control unit allows read operations for authorized clients while blocking copy operations to unauthorized destinations. This selective control ensures data security for critical operations while maintaining productivity for legitimate data access and utilization, avoiding blanket restrictions that would reduce overall efficiency.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements dynamic access control where permissions are adjusted based on the specific operation, client credentials, and data sensitivity. The control unit dynamically evaluates each access request and adjusts permissions in real-time, allowing productive operations while blocking security risks. This dynamic approach maintains high data utilization efficiency for authorized operations while ensuring continuous data security protection.

Inventive Principle:
Principle #15Dynamics

3Loss of information

If comprehensive access monitoring is implemented, then data traceability is improved, but system complexity and processing overhead increase

Engineering Contradiction:
Improveaccess history trackingVSAvoidsystem structure
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent merges the access monitoring function with the existing data access control operations. The control unit combines traceability logging with permission evaluation in a single integrated process, so that every access decision automatically generates a traceable record. This merging approach improves access history tracking without adding separate monitoring infrastructure, thereby reducing system complexity while maintaining comprehensive traceability.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP1950682B1Computer data management method, program, and recording medium
Publication Date: 2018.04.18 SCI PARK CORP
  • EP1950682B1 patent drawingFigure 1
  • EP1950682B1 patent drawingFigure 2
  • EP1950682B1 patent drawingFigure 3

AI summary

The present invention provides a data management program for performing monitoring so that user data provided to the client cannot be copied and utilized for a purpose other than the intended purpose. When a storage device (8) storing user data (3) is connected to a client computer (12), a management program (4) prohibits writing to all of the external storage devices. The management program (8) makes settings prohibiting usage of a network (7). The management program (4) performs control by acquiring the file name, folder name, and attribute data of the execution file as well as the process name and process ID of the process being executed. The management program (4) has built-in driverware (50) which runs in the kernel mode (15) of an operating system (21) and serves to provide a common interface for the communication of device drivers (35, 36, 42 to 44) and an application program (20).