Secure Device File Access Control via Server Permissions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for secure file management are inadequate in preventing data exposure and unauthorized access, particularly when sensitive documents are decrypted outside of a secure environment or on compromised systems, and there is a need for improved secure distribution and management of files.
Innovation Solution
A secure device protected against malicious software, capable of establishing a secure connection to a server, processes file access requests based on updated use permissions obtained from the server, encrypts files with internal or smart card-stored keys, and restricts access rights, allowing secure file storage, transmission, and usage according to company policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If documents are decrypted for viewing or processing, then usability and accessibility are improved, but security is worsened as documents become exposed to malware and unauthorized access
Solution Approach 1:
The system segments the document lifecycle into secure storage, secure transmission, and controlled access phases. Documents remain encrypted at rest and are only decrypted within the secure device's protected environment, separating the storage function from the processing function to maintain security while enabling usability.
Solution Approach 2:
The secure device acts as an intermediary between the encrypted document storage and the user's PC. It mediates the decryption and viewing process by providing a protected environment where documents can be accessed without exposing them to the untrusted PC environment, thus maintaining security while enabling document usability.
2Reliability
If USB ports are blocked to prevent data theft, then security is improved, but legitimate storage applications are worsened
Solution Approach 1:
The system extracts the storage function from the PC's USB ports and relocates it to a dedicated secure device. This separates the storage capability from the untrusted PC environment, allowing data protection without blocking legitimate storage needs, as users can still access storage functionality through the secure device's protected interface.
Solution Approach 2:
The secure device serves as an intermediary storage solution between the PC and external storage needs. It provides legitimate storage functionality while maintaining security by operating in a protected environment, thus resolving the contradiction between data protection and storage versatility.
3Reliability
If monitoring software is installed to detect data copying, then security monitoring is improved, but system vulnerability is worsened as the PC becomes more exposed to attacks
Solution Approach 1:
The system extracts the security monitoring function from the PC environment and relocates it to the secure device. This removes the vulnerability of installing monitoring software on the PC while maintaining security monitoring capabilities within the protected secure device environment, thus improving security without increasing system exposure.
Solution Approach 2:
The secure device acts as an intermediary monitoring point that tracks and controls document access without requiring software installation on the PC. It provides security monitoring functionality while isolating the monitoring process from the untrusted PC environment, thereby improving security monitoring without increasing system vulnerability.
4Productivity
If external devices are used for data transfer, then productivity is improved, but data loss risk is worsened
Solution Approach 1:
The secure device serves as a secure intermediary for data transfer operations. It enables productive data transfer between the PC and external devices while maintaining security by keeping documents encrypted and controlled within the protected environment, thus improving productivity without increasing data loss risk.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention is notably directed to a method, a secure device and a computer program product for securely managing files. The method may comprise the steps of: - providing (S100) a secure device (10), wherein the secure device is protected by design against malicious software or malware and adapted to establish a connection 10 to a server (40) via a host, the host connected to the server through a telecommunication network; - upon receiving (S700 S800) a request for using a file stored on the secure device, processing the request at the secure device according to an updated use permission associated to the file, 15 wherein the updated use permission is obtained by: - instructing (S300) at the secure device to establish a connection (91) between the secure device and the server (40) via the host; and - updating (S400) at the device the use permission associated to the file, according to permission data sent from the server through the established connection (91).