Portable Drive Security Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current solutions fail to comprehensively secure portable drives used across various devices within and outside a computer network, as they lack effective mechanisms to manage access and encryption policies dynamically based on drive mobility and content sensitivity.

Innovation Solution

A system comprising engines for drive registration, monitoring, and security policy determination, which assesses drive mobility and content sensitivity to enforce customized security policies, including encryption and access controls, to ensure secure usage within a computer network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If comprehensive security policies are enforced on portable drives, then data protection is improved, but user convenience and drive usability deteriorate

Engineering Contradiction:
Improvedata protectionVSAvoiddrive usability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system dynamically adjusts security policies based on real-time drive mobility status and content sensitivity assessments. When a drive is detected as mobile (moved between devices or locations), security policies are automatically enhanced. When the drive is stationary and trusted, policies are relaxed to improve usability. This dynamic adaptation resolves the contradiction by making security measures context-dependent rather than static.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes security parameters (encryption levels, access restrictions, monitoring intensity) based on assessed drive mobility and content sensitivity. High-mobility drives with sensitive content receive stricter parameters, while low-mobility drives with non-sensitive content receive relaxed parameters. This parameter adjustment resolves the contradiction by tailoring security intensity to actual risk levels.

Inventive Principle:
Principle #35Parameter changes

2Object-affected harmful factors

If strict access control policies are applied to portable drives, then unauthorized access is prevented, but legitimate user access is restricted

Engineering Contradiction:
Improveunauthorized accessVSAvoiduser access
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system applies different access control policies to different drives based on their individual mobility history and content sensitivity. Each drive receives customized security treatment rather than uniform restrictions. This local differentiation resolves the contradiction by ensuring strict controls are applied only where necessary while maintaining ease of access for trusted drives.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system continuously monitors drive usage patterns, mobility events, and access attempts, using this feedback to adjust access control policies in real-time. Legitimate user behavior patterns are learned and recognized, allowing automatic differentiation between authorized and unauthorized access attempts. This feedback mechanism resolves the contradiction by making access controls adaptive to actual user needs and threat levels.

Inventive Principle:
Principle #23Feedback

3Reliability

If encryption policies are enforced on all portable drives, then data confidentiality is improved, but system complexity and processing overhead increase

Engineering Contradiction:
Improvedata confidentialityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system adjusts encryption parameters (whether to encrypt, encryption strength, scope of encryption) based on assessed drive mobility and content sensitivity. Not all drives receive full encryption by default; instead, encryption is applied selectively based on risk assessment. This parameter differentiation resolves the contradiction by reducing unnecessary encryption overhead for low-risk drives while maintaining strong confidentiality for high-risk drives.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP2980722B1System and method for securing use of a portable drive with a computer network
Publication Date: 2020.08.12 AO KASPERSKY LAB
  • EP2980722B1 patent drawingFigure 1A
  • EP2980722B1 patent drawingFigure 1B
  • EP2980722B1 patent drawingFigure 2

AI summary

Solution for autonomously securing the use of a portable drive with a computer network. A data store is written and maintained that contains entries corresponding to a plurality of portable drives initialized for use with the computer network, each entry corresponding to at least one identifiable drive. Events (121) are monitored as they occur on the computer network involving use of each of the plurality of portable drives. Predefined security policy determination criteria (132) are applied, which can include drive mobility assessment criteria (133) and drive content sensitivity criteria (134), to determine a drive-specific security policy for each one of the plurality of portable drives. A set of at least one policy enforcement action is executed that corresponds to a determined drive-specific security policy in response to detected usage activity for each one of the plurality of portable drives.