Portable Security Appliance for Mobile Device Data Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices and host devices are vulnerable to malicious code and data transfer risks when connected to external networks or devices without adequate security measures, particularly lacking the second line of defense provided by network security systems.

Innovation Solution

A security device with a processor, memory, and a security engine that enforces a security policy on data transfer requests between a host and an external device, acting as a mobile security system or personal security appliance to provide two lines of defense, even when outside the enterprise network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If mobile devices connect to external networks or devices directly, then ease of operation and accessibility are improved, but security protection deteriorates due to loss of network security system defense

Engineering Contradiction:
Improvedevice connectivityVSAvoidsecurity protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a security appliance as an intermediary device between mobile devices and external networks or devices. This appliance provides security filtering and monitoring capabilities, acting as a portable network security system that travels with mobile devices. The security appliance intercepts and analyzes data traffic, blocking malicious content while allowing legitimate communication, thus resolving the contradiction between easy connectivity and security protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If network security systems are deployed at enterprise gateways, then security protection is improved, but device versatility and mobile access deteriorate

Engineering Contradiction:
Improvesecurity protectionVSAvoidmobile device access
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the network security function from the fixed enterprise gateway and distributes it to portable security appliances that can accompany mobile devices anywhere. Instead of having security only at the enterprise network boundary, the security capability is divided into standalone units that can be attached to individual mobile devices, enabling security protection to follow the device wherever it connects to networks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security appliance is designed as a universal device that can protect multiple types of mobile devices (laptops, smartphones, PDAs) across various networks (enterprise, public, wireless). It provides multiple security functions including firewall, virus scanning, and content filtering in a single portable unit, making security protection adaptable to diverse mobile computing scenarios.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If security scanning is performed on all data transfers, then security protection is improved, but processing speed and productivity deteriorate

Engineering Contradiction:
Improvesecurity protectionVSAvoiddata transfer speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The security appliance implements selective scanning rather than scanning all data transfers uniformly. It uses heuristics and context-aware filtering to identify and scan only potentially malicious content, allowing legitimate data transfers to pass through with minimal or no scanning. This partial action approach maintains security protection while reducing the overall processing burden and preserving data transfer speeds for non-suspicious content.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP2132643B1System and method for providing data and device security between external and host devices
Publication Date: 2017.10.25 CUPP COMPUTING
  • EP2132643B1 patent drawing
  • EP2132643B1 patent drawing
  • EP2132643B1 patent drawing

AI summary

A secure data exchange system comprising a security device including a first external, device plug, and a security engine operative to enforce a security policy on data transfer requests received from the host; an external device including a second external device plug; and a host including a first external device port operative to communicatively couple with the first external device plug, a second external device port operative to communicatively couple with the second external device plug, and a driver, e.g., a redirect driver, operative to transfer a data transfer request to the security device before executing the data transfer request.