Removable Media Security via Dummy Data Interception

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for securing data on removable media devices are inadequate as they rely on user compliance with encryption policies, which can be time-consuming and difficult to enforce, leading to risks of data loss and unauthorized access.

Innovation Solution

A system and method that automatically enforce a security policy by writing data to a removable media device with dummy data while the actual data is written to a corresponding file on a fixed media device, with compliance checked against a security policy, ensuring transparent and enforced security measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption is used to secure data on removable media, then data security is improved, but user compliance becomes difficult to enforce and the process becomes time-consuming

Engineering Contradiction:
Improvedata securityVSAvoiduser compliance
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically enforces security policies by monitoring and controlling data operations on removable media without requiring user action. The security mechanism serves itself by automatically detecting policy violations and preventing unauthorized operations, eliminating the need for users to manually encrypt data or comply with security procedures.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system introduces an intermediary security layer between the user and the removable media device. This intermediary automatically intercepts and monitors file operations, applying security policies transparently without requiring user awareness or action. The intermediary handles encryption and policy enforcement automatically, resolving the contradiction between security and ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If removable media devices are banned or rendered inoperable, then data security is improved, but legitimate business applications are lost

Engineering Contradiction:
Improvedata securityVSAvoidbusiness application capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system applies different security controls to different operations on removable media rather than banning all operations. Legitimate business applications are allowed to function with appropriate security policies applied locally to each operation, while unauthorized operations are blocked. This enables both security and business functionality to coexist.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts security enforcement based on the specific operation and context rather than applying a static ban. The security mechanism adapts to allow legitimate business applications while preventing unauthorized data transfers, providing both security and adaptability simultaneously.

Inventive Principle:
Principle #15Dynamics

3Reliability

If encryption policies are enforced manually by users, then data security may be improved, but the system becomes time-consuming and difficult to maintain

Engineering Contradiction:
Improvedata securityVSAvoidtime for compliance
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The security system performs self-service by automatically monitoring, detecting, and enforcing encryption policies without requiring user time or effort. The system continuously monitors file operations and automatically applies security measures, eliminating the time loss associated with manual compliance while maintaining strong security enforcement.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9135448B2System and method for writing to removable media
Publication Date: 2015.09.15 ZECURION
  • US9135448B2 patent drawing
  • US9135448B2 patent drawing
  • US9135448B2 patent drawing

AI summary

The invention provides a system and method for writing data to a removable media device in accordance with a security policy. According to a method of the invention a request to write data to a first file on the removable media device is detected. Dummy data is written to the first file instead of writing the requested data. The requested data is written instead to a corresponding second file on a fixed media device. The corresponding second file is compared to a security policy. Response to the write request is based on the results of the comparison.