Portable Storage Device Remote Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Institutions face challenges in restricting access to proprietary data stored on portable storage devices, particularly when employees' status changes from authorized to unauthorized, such as during termination or suspension, as existing solutions do not effectively manage access rights remotely.
Innovation Solution
A portable storage device with a non-volatile user memory and a register for permission indicia, controlled by a remote service center, which regulates access by consuming or replenishing permission indicia based on user status, allowing or limiting access, usage quotas, and directory services, ensuring secure access management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If password or biometric protection is used for portable storage devices, then access security is improved, but the ability to remotely manage access rights when employee status changes is worsened
Solution Approach 1:
The patent implements dynamic access control by introducing a permission register that can be remotely updated. The access control mechanism transitions from static password/biometric protection to a dynamic system where permission bits can be modified remotely based on employee status changes, allowing the system to adapt to changing security requirements
Solution Approach 2:
The system establishes a feedback loop between the portable storage device and the remote institution computer through the host computer. The institution can monitor and update permission registers based on employee status, creating a closed-loop control system that responds to changing access requirements
2Reliability
If technical and administrative measures are implemented for restricting data copying, then data theft prevention is improved, but the complexity of access management system is worsened
Solution Approach 1:
The patent extracts the complex access management logic from the portable storage device and relocates it to the institution's remote computer system. The portable device only needs to implement simple permission checking based on bits in a register, while the complex policy enforcement and update mechanisms reside remotely, reducing device complexity
Solution Approach 2:
The host computer acts as an intermediary between the portable storage device and the institution's remote system. It facilitates communication and permission updates without requiring the portable device to have complex built-in management capabilities, simplifying the device architecture
3Ease of operation
If full access is provided to employees carrying portable storage devices, then ease of operation is improved, but the risk of unauthorized access by former employees is worsened
Solution Approach 1:
The system performs preliminary actions by establishing remote permission control mechanisms before unauthorized access can occur. When an employee's status changes, the institution can proactively update the permission register remotely to revoke or limit access rights, preventing potential data theft before it happens
Solution Approach 2:
The patent changes the access control parameter from static permission settings to dynamic permission bits that can be remotely modified. This allows the system to transition from providing full access to implementing restricted access by simply changing the permission register contents, balancing convenience with security
Data Source
AI summary
A portable storage device controllable by a remote service center is disclosed herein. In some embodiments, the portable storage device includes a register for storing permission indicia and a non-volatile user memory for storing user data. Upon receiving a permission directive from a remote service center (e.g. via the host device), the permission indicia may be replenished (i.e. if it is desired to extend additional device-use privileges) or depleted (i.e. if is desired to deny or reduce device-use privileges). When providing host access to the onboard non-volatile user memory of the portable storage device, the permission indicia are consumed, thereby limiting the extent of host-user memory access allowable without a refresh of the permission indicia. Exemplary permission indicia include but are not limited to distinct host-device couplings, inter-device transfer quota, and usage time quote. Methods, systems including the aforementioned portable storage device, and computer code are also described.


