USB Access Control via Digital Signature Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack sufficient file system access control for externally attached storage devices, making them vulnerable to unauthorized access and corruption, particularly in mission-critical environments, as existing password and physical protection methods are inadequate and can be compromised.

Innovation Solution

A method and system that utilize digital signatures, calculated using cryptographic hashing algorithms like SHA-512, to verify the authenticity of files on external USB devices, with encrypted signature files ensuring only authorized programs can access system resources, and any alterations are detected and prevented.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If open USB I/O data ports are provided for external device access, then system functionality and user flexibility are improved, but system security and data integrity are worsened

Engineering Contradiction:
Improvesystem functionalityVSAvoidsystem security
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary verification of digital signatures before allowing execution of software from external USB devices. The access control mechanism checks the digital signature of each executable file against a trusted certificate authority before permitting the program to run, preventing malicious code execution while allowing legitimate software to function normally.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary access control mechanism that sits between the USB device and system resources. This intermediary layer verifies digital signatures and controls access to system resources, acting as a mediator that allows legitimate external devices to access the system while blocking malicious ones without requiring physical port restrictions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If password protection is implemented for USB device access, then unauthorized access is reduced, but user convenience and access speed are worsened

Engineering Contradiction:
Improveunauthorized accessVSAvoiduser convenience
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent replaces mechanical/password-based protection systems with a digital signature verification system. Instead of requiring users to enter passwords or use physical locks, the system automatically verifies digital signatures of executable files, providing security through cryptographic validation rather than user memorized credentials.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Object-affected harmful factors

If physical protection devices are used to block USB ports, then only authorized users can access the system, but the system becomes vulnerable to forced access and loses operational flexibility

Engineering Contradiction:
Improvephysical securityVSAvoidoperational flexibility
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent replaces physical protection mechanisms with a software-based digital signature verification system. This eliminates the need for physical locks and keys, allowing USB ports to remain physically accessible while providing logical security through automatic signature verification, thereby maintaining operational flexibility without sacrificing security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The access control mechanism serves as an intermediary layer that provides security without physical intervention. It automatically verifies digital signatures of executable files from external devices, allowing authorized software to execute while blocking malicious programs, without requiring physical port blocking or user authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Productivity

If external USB devices are allowed to execute programs directly, then user productivity is improved, but system integrity and safety are worsened

Engineering Contradiction:
Improveuser productivityVSAvoidsystem integrity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary verification of digital signatures before allowing execution of any program from external USB devices. The access control mechanism checks each executable file against trusted certificate authorities in advance, ensuring system integrity is maintained while allowing legitimate productivity-enhancing software to execute without restriction.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8555410B2External interface access control
Publication Date: 2013.10.08 JOHNSON & JOHNSON SURGICAL VISION INC
  • US8555410B2 patent drawing
  • US8555410B2 patent drawing
  • US8555410B2 patent drawing

AI summary

A method and apparatus of controlling access to a system containing vital corporation software and storing confidential data assets situated in an open accessible environment is provided. The method includes calculating a signature value for at least one file usable with the system, transferring the calculated signature value to a signature file, and providing at least one signature value in the signature file and at least one associated file to a file system configured to be received by the system. At least one signature value and at least one associated file are inspected by the system to verify the associated file is a known system software application asset. The system comprises an input/output data port configured to receive the external memory storage device, and an operating system capable of reading system data from and writing system data to the memory storage device.