Removable Storage Validation Token for Air-Gapped Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Air-gapped networks lack effective mechanisms for authorizing and validating removable storage devices, leading to security vulnerabilities such as unauthorized access and data breaches, as traditional solutions require central management consoles and fail to audit connections and file transfers.

Innovation Solution

A tokenization and validation process is implemented, where a validation/security token is bound to the removable storage device, using a software/hardware component within the air-gapped network to authenticate and audit connections, ensuring only authorized devices access the system and tracking interactions through a blockchain for immutable auditing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If air-gapped networks are used to isolate components from unsecured networks, then network security is improved, but protection against physical access to network components deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoidphysical access vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary validation of removable storage devices before allowing them to access the air-gapped network. A validation token is generated and stored on the device prior to connection, containing cryptographic proofs of authorized content. This preliminary action ensures that even if physical access is granted, unauthorized devices cannot access the network without pre-approved validation tokens.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary validation mechanism between the removable storage device and the air-gapped network. The validation token acts as a mediator that verifies the device's authorization status without requiring continuous network connectivity. This intermediary layer maintains the air-gap security while enabling controlled physical access through cryptographic validation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional removable storage blocking solutions are used, then unauthorized device access is reduced, but ease of operation deteriorates due to requirement of central management consoles and file inputting

Engineering Contradiction:
Improveunauthorized access preventionVSAvoiddevice authorization process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables self-service authorization where removable storage devices automatically generate and store their own validation tokens without requiring manual file inputting or central management console intervention. The validation token is created locally on the device using cryptographic operations, eliminating the need for complex administrative processes while maintaining security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Instead of requiring physical file inputting into central management consoles, the system creates a cryptographic copy (validation token) of the authorized content information directly on the removable storage device. This copy contains all necessary authorization data in a compact, machine-readable format that simplifies the authorization process while maintaining equivalent security controls.

Inventive Principle:
Principle #26Copying

3Reliability

If validation tokens are bound to removable storage devices, then unauthorized access is prevented, but device complexity increases due to tokenization and validation processes

Engineering Contradiction:
Improveauthorized device accessVSAvoidvalidation process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system transforms the authorization verification process from checking multiple device attributes to validating a single cryptographic parameter (the validation token). By changing the verification parameter from complex multi-factor checks to a unified cryptographic proof, the system maintains high security while reducing operational complexity during actual device validation.

Inventive Principle:
Principle #35Parameter changes

4Reliability

If audit mechanisms are implemented to track connections and file transfers, then security monitoring is improved, but loss of time increases due to additional validation and tracking steps

Engineering Contradiction:
Improvesecurity audit capabilityVSAvoidconnection validation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The validation token is generated and stored on the removable storage device before connection to the air-gapped network. This preliminary action pre-computes all necessary audit information and cryptographic proofs, so that during actual connection, the system only needs to verify the pre-existing token rather than performing time-consuming real-time analysis of device contents and connection history.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20210111870A1Authorizing and validating removable storage for use with critical infrastrcture computing systems
Publication Date: 2021.04.15 INVENTUS HOLDINGS LLC
  • US20210111870A1 patent drawing
  • US20210111870A1 patent drawing
  • US20210111870A1 patent drawing

AI summary

An information processing system validates authorization of a removable storage device for accessing the system. For example, the system detects a removable storage device. A first content hash and a first set of device verification data are obtained from a validation token stored on the storage device. A second content hash is obtained based on hashing content currently stored on the storage device. A second set of device verification data is obtained from the storage device. The system denies the storage device access to the system based on at least one of the first and second content hashes failing to match and the first and second sets of device verification data failing to match. The system grants the storage device access to the system based on the first and second content hashes matching and the first and second sets of device verification data matching.