Storage Interface Protection Module for Secure Split-Disk Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Removable storage devices pose significant data security risks as they can be threats to both computer and storage device security, with existing solutions being costly, resource-intensive, and prone to vulnerabilities.

Innovation Solution

A protection module is integrated into a target device to control read/write permissions between a computer and a storage device, ensuring data interaction adheres to predefined protection modes, isolating devices and preventing unauthorized access or data leakage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing security software is used to protect data interaction between computer and storage device, then data security is improved, but system resources are consumed and vulnerabilities exist

Engineering Contradiction:
Improvedata securityVSAvoidsystem resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

A protection module is introduced as an intermediary component between the computer device and storage device. This module intercepts and controls data interaction instructions, performing permission verification and control operations. By positioning the protection module at the interface layer, the system achieves security protection without requiring extensive software installations on either endpoint, thereby reducing system resource consumption while maintaining data security

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces software-based security mechanisms with a hardware-integrated protection module. The protection module is embedded in the storage device or at the connection interface, providing security control through hardware-level permission management rather than relying on software applications. This substitution eliminates the need for installing and running security software, significantly reducing system resource usage while providing continuous protection

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If permission control is implemented at the interface level, then data security is improved, but device complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidinterface complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The protection module merges multiple security functions into a single integrated component. It combines permission control, instruction interception, and data interaction management in one module, rather than requiring separate security software and control mechanisms. This merging approach provides comprehensive security protection while maintaining a simple, unified interface that does not significantly increase device complexity

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The protection module is designed with multi-functionality to handle various data interaction scenarios through a single component. It can control different types of instructions (read, write, delete), support multiple permission levels, and work with different storage devices. This universal design provides robust security protection without requiring device-specific security implementations, thereby avoiding increased complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12566556B2Data security protection method, device, system, server-side, and storage medium
Publication Date: 2026.03.03 HUANG JIANBANG
  • US12566556B2 patent drawing
  • US12566556B2 patent drawing
  • US12566556B2 patent drawing

AI summary

The application relates to the technical field of information security, and provides a data security protection method, device, system, security control framework and medium, wherein by sending split disk capacity parameters of a target split disk to a computer device, or by obtaining a mapping relationship between a sector address range and a target address range of a target file, when data interaction is performed with the computer device, an operation address corresponding to the data interaction instruction is modified into a target sector address in the split disk capacity parameters of the target split disk; and data read/write is performed according to the target sector address. By modifying the operation address of the instruction into the target sector address, the direct mapping read/write of the data address is realized, so that the computer device only identifies the target split disk.