Removable Storage Permission Control for Secure Data Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Removable storage devices pose significant data security risks when connected to computers, as they can transmit malicious programs or data leakage, and existing security software is costly, resource-intensive, and vulnerable to attacks.

Innovation Solution

A protection module is integrated into the target device to control read/write permissions, ensuring data interaction instructions meet specified protection modes, isolating devices and preventing unauthorized access or data transfer.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing security software is used to protect data interaction between computer devices and removable storage devices, then data security can be improved, but the system becomes more complex, consumes more resources, and increases cost

Engineering Contradiction:
Improvedata securityVSAvoidsecurity software
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a protection module as an intermediary component that sits between the computer device and the removable storage device. This module intercepts and controls data interaction instructions, performing permission verification and security checks without requiring complex security software on the computer itself. The protection module simplifies the security architecture by consolidating security functions into a dedicated hardware or firmware component at the storage device end.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If permission control is implemented at the computer device level using software, then data security is improved, but system resources are consumed and operation speed decreases

Engineering Contradiction:
Improvedata securityVSAvoiddata interaction speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The protection module performs permission control and security verification in advance, before actual data transfer operations. By pre-establishing permission rules and conducting authentication upfront, the system avoids repeated security checks during data interaction, thereby maintaining security while minimizing impact on data transfer speed.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If comprehensive security measures are implemented to prevent all potential threats, then data security is improved, but the ease of operation and user convenience deteriorates

Engineering Contradiction:
Improvedata securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The protection module implements dynamic permission control that can adapt to different usage scenarios. Users can configure different protection modes (such as read-only, read-write, or restricted access) based on their needs. The system dynamically adjusts security measures according to the specific data interaction context, balancing security requirements with operational convenience without requiring users to manually configure complex security settings for each operation.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20250390232A1Data security protection method, device, system, security control framework, and storage medium
Publication Date: 2025.12.25 HUANG JIANBANG
  • US20250390232A1 patent drawing
  • US20250390232A1 patent drawing
  • US20250390232A1 patent drawing

AI summary

A data security protection method, device, system, security control framework and storage medium. A protection module is arranged on the target device to control the read/write permission of the computer device on the storage device, so as to ensure the communication security between the storage devices, avoid the computer security risk caused by the malicious storage device accessing the computer device, and avoid the data leakage of the storage device caused by the computer device maliciously accessing the data of the storage device. Based on the current protection mode of the target device, the data interaction instruction sent by the computer device is controlled.