Secure Media Exchange Kiosk for Cyber-Protected Data Transfer

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Removable media devices, such as USB drives, pose a significant cyber-attack vector into cyber-secure facilities like industrial control systems, as they can introduce viruses and malware, despite physical security measures, due to uncontrolled network access.

Innovation Solution

Implementing a Secure Media Exchange (SMX) kiosk that runs a cyber-checking algorithm to encrypt removable media devices only if they are deemed safe, using a driver and agent installed on network nodes, ensuring that files can only be read on protected machines with the encryption key, and providing physical protection to the kiosk to prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If removable media devices are used to transfer data into cyber-secure facilities, then data transfer capability is improved, but cyber-security risk increases due to potential introduction of viruses and malware

Engineering Contradiction:
Improvedata transfer capabilityVSAvoidcyber-security risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

A secure media exchange (SMX) kiosk is introduced as an intermediary system between the external environment and the cyber-secure facility. The kiosk runs a cyber-checking algorithm that scans removable media devices for malware before allowing them to access the protected network. This mediator enables data transfer while filtering out harmful factors, thus resolving the contradiction between transfer capability and security risk.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary cyber-checking of removable media devices at the SMX kiosk before they are allowed to transfer data into the secure facility. By conducting security verification in advance, the system prevents malware from entering the network, thus enabling data transfer capability while eliminating security risks beforehand.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If physical security measures are implemented to limit physical access to facilities, then cyber-security is improved, but ease of operation deteriorates due to restricted access

Engineering Contradiction:
Improvecyber-securityVSAvoidaccess control
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The SMX kiosk serves as an intermediary access point that mediates between physical security restrictions and data transfer needs. Users can transfer data through the kiosk without requiring physical access to the secure facility, thus maintaining security while improving operational ease for authorized data transfer tasks.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If encryption is applied to removable media devices to protect data, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidencryption implementation
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The encryption system operates autonomously through the SMX kiosk, which automatically applies encryption to removable media devices that pass the cyber-checking algorithm. The system self-manages key distribution and encryption/decryption operations without requiring user intervention, thus improving security while minimizing the perceived complexity for end users.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10642988B2Removable media protected data transfer in a cyber-protected system
Publication Date: 2020.05.05 HONEYWELL INTERNATIONAL INC
  • US10642988B2 patent drawing
  • US10642988B2 patent drawing
  • US10642988B2 patent drawing

AI summary

A method of data transfer in a cyber-protected system includes inserting a removable media device into a removable media interface of a Secure Media Exchange (SMX) kiosk running a cyber-checking algorithm. The SMX kiosk includes a user interface, physical controls, input and output ports. An enclosure for physical protection prevents access to the physical controls, input and output ports configured with openings revealing the removable media interface and user interface. The cyber-checking algorithm inspects the removable media device for threats and adds encryption to the removable media device only if passing inspecting. The cyber-protected system includes networked devices coupled to communicate over a communications network including at least one SMX protected machine at a protected system node having a SMX algorithm and an encryption key. The SMX algorithm allows reading information from the removable media device on the SMX protected machine only if the encryption is confirmed.