Removable Memory Storage Device Dual Authentication Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing USB flash drives lack a mechanism to control and differentiate between read-only and write access, allowing unauthorized modifications when shared among users, as the primary user cannot prevent accidental or malicious changes to the stored data once authentication is provided.

Innovation Solution

A system and method that require dual authentication processes for a user, where the first authentication allows read access only and the second authentication enables read-and-write access, ensuring that data integrity is maintained by limiting modifications to authorized sessions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a single authentication process is used to allow user access to USB flash drive data, then ease of operation is improved, but data security deteriorates because the user cannot prevent unauthorized modifications

Engineering Contradiction:
Improveease of operationVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication process is segmented into two distinct types: read authentication and write authentication. Read authentication allows users to access and view data without modification capabilities, while write authentication provides full read-write access. This segmentation enables differentiated access control where the primary user can grant read-only access to others while retaining write permissions, thus improving both ease of operation and data security

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If authentication data is provided to allow another user access to USB flash drive data, then ease of operation is improved, but data security deteriorates because the primary user loses control over data modifications

Engineering Contradiction:
Improveease of operationVSAvoidunauthorized modifications
Core Design Contradiction:
Ease of operationVSObject-generated harmful factors

Solution Approach 1:

Access rights are segmented into read-only permissions and read-write permissions. When the primary user authenticates, they can choose to grant only read access to other users, preventing them from making modifications. The primary user retains write authentication capabilities, allowing them to control and prevent unauthorized modifications while still enabling convenient read access for collaborators

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different authentication credentials are assigned different local qualities or permissions. The read authentication credential provides limited access suitable for viewing data, while the write authentication credential provides full access. This allows the primary user to distribute read credentials freely for collaboration while maintaining write credentials for themselves, enabling ease of operation for others without compromising data security

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9009816B2Removable memory storage device with multiple authentication processes
Publication Date: 2015.04.14 KINGSTON DIGITAL INC
  • US9009816B2 patent drawing
  • US9009816B2 patent drawing
  • US9009816B2 patent drawing

AI summary

A method comprises providing first user authentication data of a user and comparing the first user authentication data to first stored template data. When the comparison is indicative of a match, a first session is provided, which supports one of user access for retrieving first data that are stored within a peripheral memory storage device and user access for modifying a data content of the peripheral memory storage device. The first session does not support the other one of user access for retrieving first data that are stored within the peripheral memory storage device and user access for modifying a data content of the peripheral memory storage device. During the first session, second user authentication data of the same user is provided and compared to second stored template data. When the comparison is indicative of a match, a second session is provided, which does support the other one of user access for retrieving first data that are stored within the peripheral memory storage device and user access for modifying the data content of the peripheral memory storage device.