USB Access Control via Digital Signature Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems lack sufficient file system access control for externally attached storage devices, making them vulnerable to unauthorized access and corruption, particularly in mission-critical environments, as existing password and physical protection methods are inadequate and can be compromised.
Innovation Solution
A method and system that utilize digital signatures, calculated using cryptographic hashing algorithms like SHA-512, to verify the authenticity of files on external USB devices, with encrypted signature files ensuring only authorized programs can access system resources, and any alterations are detected and prevented.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If open USB I/O data ports are provided for external device access, then system functionality and user flexibility are improved, but system security and data integrity are worsened
Solution Approach 1:
The system performs preliminary verification of digital signatures before allowing execution of software from external USB devices. The access control mechanism checks the digital signature of each executable file against a trusted certificate authority before permitting the program to run, preventing malicious code execution while allowing legitimate software to function normally.
Solution Approach 2:
The patent introduces an intermediary access control mechanism that sits between the USB device and system resources. This intermediary layer verifies digital signatures and controls access to system resources, acting as a mediator that allows legitimate external devices to access the system while blocking malicious ones without requiring physical port restrictions.
2Object-affected harmful factors
If password protection is implemented for USB device access, then unauthorized access is reduced, but user convenience and access speed are worsened
Solution Approach 1:
The patent replaces mechanical/password-based protection systems with a digital signature verification system. Instead of requiring users to enter passwords or use physical locks, the system automatically verifies digital signatures of executable files, providing security through cryptographic validation rather than user memorized credentials.
3Object-affected harmful factors
If physical protection devices are used to block USB ports, then only authorized users can access the system, but the system becomes vulnerable to forced access and loses operational flexibility
Solution Approach 1:
The patent replaces physical protection mechanisms with a software-based digital signature verification system. This eliminates the need for physical locks and keys, allowing USB ports to remain physically accessible while providing logical security through automatic signature verification, thereby maintaining operational flexibility without sacrificing security.
Solution Approach 2:
The access control mechanism serves as an intermediary layer that provides security without physical intervention. It automatically verifies digital signatures of executable files from external devices, allowing authorized software to execute while blocking malicious programs, without requiring physical port blocking or user authentication.
4Productivity
If external USB devices are allowed to execute programs directly, then user productivity is improved, but system integrity and safety are worsened
Solution Approach 1:
The system performs preliminary verification of digital signatures before allowing execution of any program from external USB devices. The access control mechanism checks each executable file against trusted certificate authorities in advance, ensuring system integrity is maintained while allowing legitimate productivity-enhancing software to execute without restriction.
Data Source
AI summary
A method and apparatus of controlling access to a system containing vital corporation software and storing confidential data assets situated in an open accessible environment is provided. The method includes calculating a signature value for at least one file usable with the system, transferring the calculated signature value to a signature file, and providing at least one signature value in the signature file and at least one associated file to a file system configured to be received by the system. At least one signature value and at least one associated file are inspected by the system to verify the associated file is a known system software application asset. The system comprises an input/output data port configured to receive the external memory storage device, and an operating system capable of reading system data from and writing system data to the memory storage device.


