Portable Drive Security via Dynamic Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current solutions fail to comprehensively secure portable drives used across various devices within and outside a computer network, as they lack effective mechanisms to manage and enforce security policies based on drive mobility and content sensitivity.

Innovation Solution

A system comprising a computing platform with a drive registration engine, a monitoring engine, and a security policy determination and enforcement engine that autonomously registers, monitors, and enforces drive-specific security policies based on predefined criteria, including mobility and content sensitivity, to ensure secure usage of portable drives within a computer network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If portable drives are allowed to move freely within and outside the network for user convenience, then ease of operation is improved, but security risk increases due to unauthorized access and data breaches

Engineering Contradiction:
Improveportable drive mobilityVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The security policy is made dynamic by continuously monitoring drive location and automatically adjusting security levels based on geographic context. The drive transitions between different security states (permissive when on-network, restrictive when off-network) based on real-time location assessment, resolving the contradiction between mobility convenience and security risk.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

A security policy enforcement module acts as an intermediary between the portable drive and the network/resources. This intermediary assesses drive location, determines appropriate security policies, and enforces them by controlling access to network resources, thereby managing the security risk while allowing operational flexibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive security policies are enforced on all portable drives, then data protection is improved, but device complexity increases due to multiple monitoring and enforcement mechanisms

Engineering Contradiction:
Improvedata protectionVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security policy enforcement module performs multiple functions: monitoring drive location, assessing security risk, determining appropriate policies, and enforcing those policies. By consolidating these functions into a single multi-functional module, the system achieves comprehensive data protection without proportionally increasing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system autonomously monitors drive location, automatically determines security policies based on pre-defined criteria, and self-enforces those policies without requiring constant administrator intervention. This self-service capability reduces operational complexity while maintaining reliable data protection.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9537895B2System and method for securing use of a portable drive with a computer network
Publication Date: 2017.01.03 AO KASPERSKY LAB
  • US9537895B2 patent drawing
  • US9537895B2 patent drawing
  • US9537895B2 patent drawing

AI summary

Solution for autonomously securing the use of a portable drive with a computer network. A data store is written and maintained that contains entries corresponding to a plurality of portable drives initialized for use with the computer network, each entry corresponding to at least one identifiable drive. Events are monitored as they occur on the computer network involving use of each of the plurality of portable drives. Predefined security policy determination criteria is applied, which can include drive mobility assessment criteria and drive content sensitivity criteria, to determine a drive-specific security policy for each one of the plurality of portable drives. A set of at least one policy enforcement action is executed that corresponds to a determined drive-specific security policy in response to detected usage activity for each one of the plurality of portable drives.