Removable Media Security via Redirection Code Interception

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices and host devices connected to external media, such as USB flash drives, are vulnerable to malicious code and data transfer risks when outside the enterprise network, lacking the second line of defense provided by network security systems.

Innovation Solution

A method and system that detect removable media devices, authenticate access, inject redirection code, intercept data requests, and apply security policies to filter out malware and ensure secure data transfer, using a mobile security system that acts as a miniature gateway, providing two lines of defense even when outside the enterprise network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If mobile devices connect to external media outside enterprise network, then device portability and access flexibility are improved, but security protection deteriorates due to loss of network security system defense

Engineering Contradiction:
Improvedevice portabilityVSAvoidsecurity protection
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an intermediary security system that acts as a mediator between the mobile device and external media. This security system includes a security module that intercepts data requests, scans for malicious code, and filters content before allowing access, thereby providing security protection without restricting device portability or external media access

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If network security system is used within enterprise network, then security protection is improved, but device accessibility outside network deteriorates

Engineering Contradiction:
Improvesecurity protectionVSAvoiddevice accessibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a self-service security system where the mobile device itself performs security functions through an installed security module. This module provides local scanning, filtering, and protection capabilities, enabling the device to maintain security protection independently when outside the enterprise network, thus not limiting device accessibility

Inventive Principle:
Principle #25Self-service

3Reliability

If security scanning and filtering is performed on all data requests, then malicious code detection is improved, but data transfer speed deteriorates

Engineering Contradiction:
Improvemalicious code detectionVSAvoiddata transfer speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies partial scanning and filtering actions based on risk assessment. The security module prioritizes scanning for high-risk file types and contexts while using less intensive scanning for low-risk data, thereby maintaining malicious code detection capability while minimizing impact on data transfer speed

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11604861B2Systems and methods for providing real time security and access monitoring of a removable media device
Publication Date: 2023.03.14 CUPP COMPUTING
  • US11604861B2 patent drawing
  • US11604861B2 patent drawing
  • US11604861B2 patent drawing

AI summary

A method comprises detecting a removable media device being coupled to an external device port of a digital device having an operating system and a file system, authenticating a password to access the removable media device, causing redirection code to be temporarily generated on the digital device, intercepting with the redirection code a data request, determining to allow the data request based on a security policy, allowing the operating system or file system to provide the data based on the determination, detecting the removable media device being removed from the digital device; and terminating the at least a portion of the redirection code.