Secure External Memory Device Application Control via Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Smart external memory devices (SEMDs) pose security concerns for enterprises and users, including unsecured storage, data leakage, introduction of unfiltered applications, and lack of control over authorized applications, as well as the inability to restrict usage to company-issued devices.

Innovation Solution

Implementing a security system with a File System Filter Driver, Policy Driver Component, Network Configuration Manager, U3 Package Parser, Application Database, and encryption module to control and authorize U3 applications, encrypt data, and restrict access to only approved devices within a company's private network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If SEMDs are used to store data and applications, then application mobility and data accessibility are improved, but security risks and data leakage concerns increase

Engineering Contradiction:
Improveapplication mobilityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the SEMD into distinct functional components: an encrypted data storage area, an unencrypted applications area, and a separate encryption key storage mechanism. This segmentation allows applications to operate without encryption overhead while data remains protected, resolving the contradiction between mobility and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the encryption state parameter dynamically - data is encrypted at rest with configurable encryption algorithms (AES, RSA, etc.), but decrypted only when authorized applications access it through the security manager. This parameter change enables both secure storage and convenient access.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If all applications are allowed to access SEMD data, then ease of operation is improved, but unauthorized access and data leakage increase

Engineering Contradiction:
Improvedata accessibilityVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-generated harmful factors

Solution Approach 1:

The patent introduces a security manager as an intermediary layer between applications and SEMD data. This security manager verifies application credentials, manages encryption keys, and controls access permissions. Applications interact with the security manager rather than directly accessing data, enabling easy operation for authorized apps while blocking unauthorized access.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If encryption is applied to all data on SEMD, then data security is improved, but system complexity and access overhead increase

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by encrypting only the data portion of the SEMD while keeping the applications portion unencrypted. This selective encryption reduces system complexity and access overhead for applications while maintaining strong security for data. Different regions of the storage device have different encryption properties based on their functional requirements.

Inventive Principle:
Principle #3Local quality

4Reliability

If company-issued devices are restricted for SEMD usage, then security control is improved, but device versatility and user flexibility decrease

Engineering Contradiction:
Improvesecurity controlVSAvoiddevice flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements feedback mechanisms where the security manager continuously monitors application behavior, access patterns, and system state. Based on this feedback, the system dynamically adjusts access permissions and can revoke credentials for suspicious activities. This feedback loop maintains security control while allowing flexible device usage within established policies.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8887295B2Method and system for enabling enterprises to use detachable memory devices that contain data and executable files in controlled and secure way
Publication Date: 2014.11.11 SUPERCOM IP LLC
  • US8887295B2 patent drawing
  • US8887295B2 patent drawing
  • US8887295B2 patent drawing

AI summary

Secure operation of SEMDs on a client computer in a host system is obtained by controlling what applications (i.e., U3 applications) that can run on the host system and access data on the SEMD. Applications allowed to run on each host machine are identified and any access to the SEMD by an allowed application is permitted and other access are prohibited. Security and/or privacy for data that is stored on a SEMD is provided by only allowing approved USB memory card based applications to access the data stored on the SEMD. All other applications, either unapproved USB memory card based applications or non-SEMD resident cannot access the data on the SEMD. Other security is provided by preventing access to the SEMD except for computers or systems that are a part of a company's private network and maintaining the data on the SEMD in an encrypted state.