Storage Device Network Identifier Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is no automated solution for managing access to portable storage devices when they are shared across different networks, requiring users to manually check and remove sensitive data before connecting them to a new network.

Innovation Solution

A method and device that retrieve and use network identifiers to differentiate between 'friendly' and 'foreign' networks, allowing access to private data only on recognized networks, while restricting access to private data on unfamiliar networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the storage device allows access to all data on any network, then ease of sharing is improved, but security of private data deteriorates

Engineering Contradiction:
Improveease of sharingVSAvoidsecurity of private data
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments data into public and private categories, and further segments access rights based on network identification. The storage device automatically identifies the network type (home/office vs. public) and applies different access policies accordingly, allowing full access on trusted networks while restricting access to only public data on untrusted networks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The storage device performs preliminary network identification and classification before any data access occurs. By detecting network identifiers (SSID, MAC addresses, router IP) and comparing them against stored lists of trusted networks, the system pre-establishes appropriate access permissions, eliminating the need for manual user intervention before sharing.

Inventive Principle:
Principle #10Preliminary action

2Object-affected harmful factors

If the user manually checks and removes sensitive data before connecting to a new network, then security of private data is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvesecurity of private dataVSAvoidease of operation
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The storage device autonomously performs network identification, classification, and access control enforcement without requiring user action. The system automatically detects network characteristics, compares them against stored profiles, and adjusts data accessibility accordingly, freeing users from manual security management tasks.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously monitors network identification information and dynamically adjusts access permissions based on the detected network type. This closed-loop approach ensures that access control policies are automatically updated in response to changes in the network environment, maintaining security while enabling seamless connectivity.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If the storage device implements automated network identification and access control, then ease of operation is improved, but device complexity increases

Engineering Contradiction:
Improveease of operationVSAvoiddevice complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The storage device leverages existing multi-functional components already present in modern portable storage devices: network interface cards capable of detecting various network identifiers (SSID, MAC addresses, router IP addresses), microprocessors for comparing data against stored lists, and memory for storing network profiles and access control policies. This approach enables sophisticated access control without adding dedicated hardware complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10891388B2Personalized access to storage device through a network
Publication Date: 2021.01.12 DEVERHOOD HT CO LTD
  • US10891388B2 patent drawing

AI summary

A technique is provided for a personalized access to a storage device from a communication device through a local network, with public data and private data being stored in the storage device. The storage device is configured to retrieve an identifier of the local network, allow access to the public data and a set of private data if the retrieved identifier is included in a first list of local networks, and deny access to the set of private data if the retrieved identifier is not included in the first list of the local networks.