Removable Media Security via Dummy Data Interception
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for securing data on removable media devices are inadequate as they rely on user compliance with encryption policies, which can be time-consuming and difficult to enforce, leading to risks of data loss and unauthorized access.
Innovation Solution
A system and method that automatically enforce a security policy by writing data to a removable media device with dummy data while the actual data is written to a corresponding file on a fixed media device, with compliance checked against a security policy, ensuring transparent and enforced security measures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encryption is used to secure data on removable media, then data security is improved, but user compliance becomes difficult to enforce and the process becomes time-consuming
Solution Approach 1:
The system automatically enforces security policies by monitoring and controlling data operations on removable media without requiring user action. The security mechanism serves itself by automatically detecting policy violations and preventing unauthorized operations, eliminating the need for users to manually encrypt data or comply with security procedures.
Solution Approach 2:
The system introduces an intermediary security layer between the user and the removable media device. This intermediary automatically intercepts and monitors file operations, applying security policies transparently without requiring user awareness or action. The intermediary handles encryption and policy enforcement automatically, resolving the contradiction between security and ease of operation.
2Reliability
If removable media devices are banned or rendered inoperable, then data security is improved, but legitimate business applications are lost
Solution Approach 1:
The system applies different security controls to different operations on removable media rather than banning all operations. Legitimate business applications are allowed to function with appropriate security policies applied locally to each operation, while unauthorized operations are blocked. This enables both security and business functionality to coexist.
Solution Approach 2:
The system dynamically adjusts security enforcement based on the specific operation and context rather than applying a static ban. The security mechanism adapts to allow legitimate business applications while preventing unauthorized data transfers, providing both security and adaptability simultaneously.
3Reliability
If encryption policies are enforced manually by users, then data security may be improved, but the system becomes time-consuming and difficult to maintain
Solution Approach 1:
The security system performs self-service by automatically monitoring, detecting, and enforcing encryption policies without requiring user time or effort. The system continuously monitors file operations and automatically applies security measures, eliminating the time loss associated with manual compliance while maintaining strong security enforcement.
Data Source
AI summary
The invention provides a system and method for writing data to a removable media device in accordance with a security policy. According to a method of the invention a request to write data to a first file on the removable media device is detected. Dummy data is written to the first file instead of writing the requested data. The requested data is written instead to a corresponding second file on a fixed media device. The corresponding second file is compared to a security policy. Response to the write request is based on the results of the comparison.


