Removable Storage Validation Token for Air-Gapped Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Air-gapped networks lack effective mechanisms for authorizing and validating removable storage devices, leading to security vulnerabilities such as unauthorized access and data breaches, as traditional solutions require central management consoles and fail to audit connections and file transfers.
Innovation Solution
A tokenization and validation process is implemented, where a validation/security token is bound to the removable storage device, using a software/hardware component within the air-gapped network to authenticate and audit connections, ensuring only authorized devices access the system and tracking interactions through a blockchain for immutable auditing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If air-gapped networks are used to isolate components from unsecured networks, then network security is improved, but protection against physical access to network components deteriorates
Solution Approach 1:
The system performs preliminary validation of removable storage devices before allowing them to access the air-gapped network. A validation token is generated and stored on the device prior to connection, containing cryptographic proofs of authorized content. This preliminary action ensures that even if physical access is granted, unauthorized devices cannot access the network without pre-approved validation tokens.
Solution Approach 2:
The patent introduces an intermediary validation mechanism between the removable storage device and the air-gapped network. The validation token acts as a mediator that verifies the device's authorization status without requiring continuous network connectivity. This intermediary layer maintains the air-gap security while enabling controlled physical access through cryptographic validation.
2Reliability
If traditional removable storage blocking solutions are used, then unauthorized device access is reduced, but ease of operation deteriorates due to requirement of central management consoles and file inputting
Solution Approach 1:
The system enables self-service authorization where removable storage devices automatically generate and store their own validation tokens without requiring manual file inputting or central management console intervention. The validation token is created locally on the device using cryptographic operations, eliminating the need for complex administrative processes while maintaining security.
Solution Approach 2:
Instead of requiring physical file inputting into central management consoles, the system creates a cryptographic copy (validation token) of the authorized content information directly on the removable storage device. This copy contains all necessary authorization data in a compact, machine-readable format that simplifies the authorization process while maintaining equivalent security controls.
3Reliability
If validation tokens are bound to removable storage devices, then unauthorized access is prevented, but device complexity increases due to tokenization and validation processes
Solution Approach 1:
The system transforms the authorization verification process from checking multiple device attributes to validating a single cryptographic parameter (the validation token). By changing the verification parameter from complex multi-factor checks to a unified cryptographic proof, the system maintains high security while reducing operational complexity during actual device validation.
4Reliability
If audit mechanisms are implemented to track connections and file transfers, then security monitoring is improved, but loss of time increases due to additional validation and tracking steps
Solution Approach 1:
The validation token is generated and stored on the removable storage device before connection to the air-gapped network. This preliminary action pre-computes all necessary audit information and cryptographic proofs, so that during actual connection, the system only needs to verify the pre-existing token rather than performing time-consuming real-time analysis of device contents and connection history.
Data Source
AI summary
An information processing system validates authorization of a removable storage device for accessing the system. For example, the system detects a removable storage device. A first content hash and a first set of device verification data are obtained from a validation token stored on the storage device. A second content hash is obtained based on hashing content currently stored on the storage device. A second set of device verification data is obtained from the storage device. The system denies the storage device access to the system based on at least one of the first and second content hashes failing to match and the first and second sets of device verification data failing to match. The system grants the storage device access to the system based on the first and second content hashes matching and the first and second sets of device verification data matching.


