Secure Media Exchange Kiosk for Malware-Free File Transfer

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Removable media, such as USB drives, pose a significant threat to secure networks as they can introduce viruses and malware, serving as a primary vector for cyber-attacks, and existing solutions do not effectively manage the secure exchange of files between protected and unprotected systems.

Innovation Solution

Implementing a Secure Media Exchange (SMX) system on a single board computer, like the RASPBERRY PI, which includes a processing device, touch screen display, and interface for storage devices, to perform check-in and check-out processes. This involves scanning for malware, digitally signing clean files, modifying the file system, and generating results for display, ensuring only trusted devices can access protected systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If removable media are used to transfer information into and out of secure networks, then information exchange capability is improved, but network security deteriorates due to malware introduction risks

Engineering Contradiction:
Improveinformation exchange capabilityVSAvoidmalware introduction risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary system (SMX kiosk with processing device) that mediates between removable media and secure networks. The kiosk performs check-in/check-out processes, scanning for malware and digitally signing files, thereby enabling information exchange while filtering out harmful factors before they can reach the secure network.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary actions by scanning removable media for malware and digitally signing clean files before they are allowed to access the secure network. This advance verification prevents malware introduction while maintaining information exchange capability.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If strict security controls are implemented to prevent malware introduction, then network security is improved, but ease of operation deteriorates due to restricted media access

Engineering Contradiction:
Improvenetwork securityVSAvoidmedia access convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements self-service through automated check-in and check-out processes. The processing device automatically scans media, identifies malware, digitally signs clean files, and modifies file systems without requiring manual security verification, thereby maintaining strict security controls while improving operational ease.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Security verification is performed in advance through automated scanning and digital signing processes. This preliminary action establishes trust before media access is granted, allowing strict security controls to be implemented without significantly impacting ease of operation during actual use.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If malware scanning and digital signing processes are implemented, then security reliability is improved, but processing time deteriorates

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidcheck-in processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent replaces manual security verification processes with automated digital signing and scanning mechanisms. The processing device uses cryptographic algorithms for digital signing and automated scanning techniques, substituting time-consuming manual procedures with efficient computational processes that maintain security reliability while reducing processing time.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentEP3738064B1System and method for implementing secure media exchange on a single board computer
Publication Date: 2023.08.09 HONEYWELL INTERNATIONAL INC
  • EP3738064B1 patent drawingFigure 1
  • EP3738064B1 patent drawingFigure 2
  • EP3738064B1 patent drawingFigure 3~4

AI summary

An apparatus includes a single board computer (402) comprising a processing device (302). The apparatus also includes a touch screen display (404) coupled to the single board computer. The apparatus further includes at least one interface (310, 408) configured to be coupled to a storage device (304, 502). The processing device is configured to detect the storage device, perform a check-in process for the storage device, and generate a result of the check-in process for display on the touch screen display. To perform the check-in process, the processing device is configured to scan the storage device to identify any malware contained on the storage device, digitally sign one or more clean files on the storage device, and modify a file system of the storage device.