Mobile Device USB Data Security via Preliminary Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile devices lack effective data security when connected to other devices via USB, as data can be easily accessed or copied if the device is lost or stolen, even with screen locking passwords.

Innovation Solution

Implementing an authentication method that generates a request for authentication when a predetermined condition is met, such as connection to another device, and allows or denies data read/write operations based on successful authentication, ensuring the device remains secure by limiting access when in a locking state.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the mobile device is connected to other devices via USB for data synchronization or storage, then data synchronization and transfer functionality is improved, but data security deteriorates because data can be easily accessed or copied if the device is lost or stolen

Engineering Contradiction:
Improvedata synchronization functionalityVSAvoiddata security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary authentication before allowing any data access or synchronization operations. The authentication request is generated in advance when connection conditions are met, and authentication information must be provided before data transfer can occur, preventing unauthorized access proactively

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Authentication information acts as an intermediary between the mobile device and external devices. This intermediary mechanism verifies user identity and authorization before allowing data access, serving as a mediator that protects data while enabling legitimate synchronization operations

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication protocols are implemented to protect data security, then data security is improved, but device complexity increases due to complex synchronization authentication protocols

Engineering Contradiction:
Improvedata securityVSAvoidauthentication protocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication function is extracted from the complex synchronization protocol and implemented as a separate, independent module. This allows authentication to be handled independently using existing screen locking mechanisms, simplifying the overall system while maintaining security

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system uses existing screen locking authentication mechanisms (password, fingerprint, etc.) to handle data access authentication automatically. The authentication system serves itself by leveraging already-implemented security features rather than requiring separate complex authentication infrastructure

Inventive Principle:
Principle #25Self-service

3Reliability

If authentication is required for data access, then data security is improved, but ease of operation deteriorates because users must provide authentication information for each data operation

Engineering Contradiction:
Improvedata securityVSAvoiddata access convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

Authentication is performed preliminarily before data access is needed. Once authenticated, the system maintains authentication state and allows data operations without requiring repeated authentication inputs, improving ease of operation while maintaining security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system provides feedback by maintaining authentication state and memory of authenticated devices. This feedback mechanism allows the system to remember authorized devices and users, enabling seamless data access without repeated authentication requirements

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9323908B2Authentication method and electronic device
Publication Date: 2016.04.26 LENOVO (BEIJING) LTD
  • US9323908B2 patent drawing
  • US9323908B2 patent drawing
  • US9323908B2 patent drawing

AI summary

Embodiments of the present disclosure provide an authentication method and an electronic device. The method includes: generating by a first device an authentication request if a predetermined condition exists between the first device and a second device, when the first device is in a locking state, wherein the first device has the locking state and a non-locking state; receiving by the first device authentication information, the authentication information being input in response to the authentication request; and authenticating the second device using the authentication information. Through the present disclosure, others cannot directly damage or copy data in the first device in a connection manner such as using a data line even if they get hold of the device, as long as the first device is in the locking state. Thus, the security of the data in the first device is ensured. Since a complex synchronization authentication protocol does not need to be developed by synchronization software and the first device, and the present disclosure is compatible with various commercially available synchronization software, the implementation method is simple and efficient, and the compatibility is good.