USB Security Mediator for Malware-Free File Transfer

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Portable storage devices like USB drives can infect computers with viruses and malware, leading to security risks, and existing solutions either restrict their use or rely on user compliance, which may not be practical or secure for transferring large files.

Innovation Solution

A security device is placed between the computer system and the portable storage device, creating a virtual network to analyze and filter files without interacting directly with the computer's operating system, using a processor module with an Ethernet adapter, file analysis module, and a read-only file system to identify and transfer safe files, while optionally accessing anti-virus data locally or remotely.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If USB drives are used for file interchange, then file transfer convenience is improved, but security risk from viruses and malware increases

Engineering Contradiction:
Improvefile transfer convenienceVSAvoidsecurity risk from viruses and malware
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a mediating communication device positioned between the USB drive and the host computer. This intermediary device includes a hypervisor that intercepts and analyzes file operations, determining whether USB devices are authorized to communicate with the guest operating system. The mediator scans files for malware and controls the interaction between the USB drive and computer, allowing convenient file transfer while preventing direct infection of the host system.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If USB ports are blocked or USB drives are forbidden, then security risk is reduced, but file transfer capability deteriorates

Engineering Contradiction:
Improvesecurity riskVSAvoidfile transfer capability
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The patent segments the file transfer process into multiple controlled stages: USB device connection, file scanning by the hypervisor, security verification, and controlled file transfer. This segmentation allows the system to maintain USB functionality for file transfer while inserting security checkpoints at each stage, preventing malware propagation while enabling legitimate file exchange.

Inventive Principle:
Principle #1Segmentation

3Object-affected harmful factors

If independent computer with air gap is used, then security is improved, but practicality for moving large files deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidpracticality for moving large files
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent implements a nested virtualization structure where a hypervisor runs within the host computer's operating system, creating a nested virtual environment. This nested architecture allows the security device to operate within the existing computer system without requiring a separate physical machine, maintaining strong security isolation while enabling direct file transfer to the host system through the virtualized layer.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentEP3079334B1Device and method for transferring files from a portable storage device
Publication Date: 2019.03.13 THE BOEING CO
  • EP3079334B1 patent drawingFigure 1
  • EP3079334B1 patent drawingFigure 2

AI summary

The invention proposes a new device and method that allows scanning and downloading the content of a portable storage device (i.e., USB drive) from any computer with a portable storage device plug and a browser without the risk of having the computer infected by virus or malware resident in the portable storage device. The device can be manufactured in a small and portable device.