Security Control Management for Data Storage Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network devices face challenges in controlling data leakage and unauthorized access, as they are vulnerable to online and physical attacks, which compromises their security and allows malicious activities.

Innovation Solution

A system that monitors and adjusts security controls for data storage devices by determining their current security level and applying appropriate security measures, such as software and hardware configurations, to mitigate vulnerabilities and enhance security before data storage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security controls are applied to data storage devices to improve security level, then information security is improved, but device complexity increases

Engineering Contradiction:
Improveinformation securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary assessment of the data storage device's security level and pre-identifies appropriate security controls before data storage operations begin. This allows security configurations to be established in advance, ensuring security requirements are met without adding complexity to ongoing operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors and assesses the security level of data storage devices, using this feedback information to dynamically adjust and apply appropriate security controls. This closed-loop approach ensures security is maintained while avoiding unnecessary controls that would increase complexity.

Inventive Principle:
Principle #23Feedback

2Reliability

If security controls are applied to mitigate vulnerabilities, then security against attacks is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvesecurity against attacksVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically performs security assessments, identifies vulnerabilities, selects appropriate security controls, and applies them without requiring manual intervention. This self-service approach maintains high security while preserving ease of operation by eliminating the need for users to manually configure security settings.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Security controls are pre-configured and applied automatically based on the device's security level assessment, so users do not need to manually configure security settings. This preliminary automation of security setup maintains security effectiveness while preserving operational simplicity.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If security level of data storage device is increased, then data protection is improved, but device complexity increases

Engineering Contradiction:
Improvedata protectionVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system applies security controls selectively based on the specific vulnerabilities and security level of each data storage device rather than uniformly across all devices. This localized approach ensures data protection is improved for each device's specific needs without unnecessarily increasing complexity.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts security parameters and control applications based on the assessed security level of each device. By changing security parameters adaptively rather than using fixed high-security configurations, the system improves data protection while minimizing unnecessary complexity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11308231B2Security control management for information security
Publication Date: 2022.04.19 BANK OF AMERICA CORP
  • US11308231B2 patent drawing
  • US11308231B2 patent drawing
  • US11308231B2 patent drawing

AI summary

A device configured to receive a data storage request that identifies a data content type for a data element and a target data storage device. The device is further configured to determine the target data storage device does not match an approved data storage device. The device is further configured to determine a security level associated with the target data storage device and to determine vulnerability types associated with the determined security level of the target data storage device. The device is further configured to identify security controls based on the determined vulnerability types and to output the identified security controls. Each security control comprises a hardware configuration for data storage devices that are associated with mitigating one or more vulnerability types.