The present invention will be understood and appreciated more fully from the following detailed description, taken in conjunction with the drawings in which:
While the invention is described herein by way of example for several embodiments and illustrative drawings, those skilled in the art will recognize that the invention is not limited to the embodiments or drawings described. It should be understood that the drawings and detailed description thereto are not intended to limit the invention to the particular form disclosed, but on the contrary, the invention is to cover all modifications, equivalents and alternatives falling within the spirit and scope of the present invention. As used throughout this application, the word “may” is used in a permissive sense (i.e., meaning “having the potential to’), rather than the mandatory sense (i.e. meaning “must”).
The present invention will now be described in terms of specific, example embodiments. It is to be understood that the invention is not limited to the example embodiments disclosed. It should also be understood that not every feature of the presently disclosed method, device and system for regulating host-access to an onboard non-volatile user memory of a portable storage device is necessary to implement the invention as claimed in any particular one of the appended claims. Various elements and features of devices are described to fully enable the invention. It should also be understood that throughout this disclosure, where a process or method is shown or described, the steps of the method may be performed in any order or simultaneously, unless it is clear from the context that one step depends on another being performed first.
For convenience, certain terms employed in the specification, examples, and appended claims are collected here.
For the present disclosure, a “institution” is an entity that owns propriety information. Non limiting examples are a company, organization or government agency.
For the present disclosure, a “service center” is a computer system that is operated by or for an institution and can be contacted via a communication network such as the Internet, mobile telephony or land telephony.
For the present disclosure, a “user” is a person authorized by an institution to carry and access proprietary information of the institution.
For the present disclosure, a “host” is a user-operated device that includes a processor that allows access to the content of a portable storage device and communication means for connecting to a service center. Non-limiting examples for a host are a desktop or laptop personal computer, a cellular telephone or a two-way pager.
For the present disclosure, a “portable storage device” is a storage device that stores proprietary information of an institution and is carried by a user for interfacing with selectable hosts in order to access the information stored in the portable storage device and/or to communicate with a service center of the respective institution that owns the proprietary information. Non-limiting examples for a portable storage device include a USB flash drive, a memory card, or a digital appliance (portable music player, cellular telephone) that doubles as a storage device accessible by an external host.
It will be noted that the definitions above are sensitive to specific roles of hosts and storage devices. In an example of a pair of a memory card and a cellular telephone that can both access the content of the memory card and contact a service center, the memory card can be seen as a portable storage device and the cellular telephone can be seen a host. But if part of a memory of a cellular telephone is allocated for storage functionality that is inaccessible to the telephone and is accessible to personal computers through a USB interface, then the entire cellular telephone can be considered a portable storage device and the personal computer becomes the host. Accordingly, portable music players that double as USB disks will be considered portable storage devices that interface with hosts that are personal computers.
Portable storage device 110 includes a non-volatile memory 114 controlled by a programmed controller 140. Thus, any access to any data stored within non-volatile memory 114 is made under the control of controller 140, according to access rules programmed into controller 140, including access rules according to the present invention as depicted below. In some cases, portable storage device 110 also includes other functions 148, such as cellular telephony, picture taking, music playing, etc., that may include access to the memory portion user's data 124.
Proprietary data 120 is a portion of non-volatile memory 114 allocated for storing proprietary data of an institution that is protected according to the teachings of the present invention. Optionally, part of proprietary data 120 is log 120L, that records all data traffic into and from proprietary data 120, a recording made under the operating system of host 150 or by the programming of controller 140. User's data 124 is a portion of non-volatile memory 114 allocated for access by host 150 or other functions 148 out of the controls and restrictions of the present invention.
For the present disclosure, the proprietary data 120 and the user's data 124 reside in what is collectively referred to as the non-volatile “user memory” for storing “user data.” This is the workspace of files and folders that may be visible in a directory or file listing. In one example, access to the entirety of the “user memory” for storing user data may be allowed or disallowed in accordance with the permission indicia rather than on a file-by-file basis or a folder-by-folder basis or on a file-type basis, etc.
Optionally, the portable storage device includes a loss protection application 134 for protecting data from unauthorized third parties who get a hold of the storage device 110.
In the current example, access control application 130 is software code to be run on controller 140 of portable storage device 110 and/or data processor 158 of host 150 in order to implement the teachings of the present invention as depicted below. For example, access control application 130 may be composed of two applications: a first application running on data processor 158 to manage access to proprietary data 120 only according to the current content of permission register 132, and a second application running on data processor 158 of host 150 to manage or enable communication with service center 190 via public network 180. In one example, access control application 130 checks the current access permissions from permission register 132, updates them through communication with a service center 190 and control the access from a host 150 to proprietary data 120 according to the current permissions. A detailed description of the functions and steps of access control application 130 will be brought below with respect to
Host 150, such as a personal computer, cellular telephone or personal digital assistance that includes Internet or cellular connectivity, is a standard device providing user 170 with access, via user interface 162 (for example, screen and keyboard) to the data stored in portable storage device 110. Data processor 158 represents herein the processor, memory, operating system, drivers and application software common in general computing to the respective type of host 150.
Service center 190 is operated by or for the institution that owns the proprietary information stored in the memory portion allocated for proprietary data 120. It includes a data processor 194, that can be best visualized as an internet or cellular network server, which can be communicated by host 150 for updating permission register 132 of portable storage device 110. Permission database 192 includes that current permissions granted to each every portable storage device 110, and is updatable by an administrator of service center 190 (not shown); thus, for example, if a certain user turn to become untrusted, the respective record in permission database 192 will be updated by the system administrator of service center 190, which will affect an update of the permission register 132 of the respective portable storage device 110 upon the next communication between portable storage device 110 and service center 190 through any host 150.
In some embodiments of the present invention, it may be desirable to have a manual alternative for updating permission register 132 from permission database 192 if a public network 180 is not readily available. For example, when traveling a user may have access to a telephone but not to an Internet connection. For such a case, support desk 198 and manual connection 174 are added. Support desk 198 is either a manned workstation or an automated voice answering facility that can affect data transfer between permission database 192 and permission register 132 via manual connection 174, user 170, user interface 162, data processor 158, device interface 154, host interface 144 and controller 140. The manual process will be described in more below with respect to
The restriction by expiration date/time 132E may need special attention in the common situation where portable storage device 110 lacks a power supply of it own, hence lacks a trustworthy real-time clock. While a real-time clock of host 150 can be accessed by access control application 130 even in offline situations, such a clock can be easily readjusted by the user for showing a false time which falls within the allowed usage quota of expiration date/time 132E. In online situations an access to a trusted clock (not shown) through public network 180 can be mandated by access control application 130, but in online situations mandating access to service center 190 could offer better control. Thus, when portable storage device 110 lack a real-time clock of its own, expiration date/time 132E restriction is preferably accompanied by requiring other permission forms from
A second solution for connecting portable storage device 110 to service center 190 is based on host is a conduit 200C. Under this approach, portable storage device 110 has sufficient processing and communication power to act as a client of public network 180, and needs host 150 as a conduit to public network 180 on the one hand, and for its user interface 162 on the other hand. Thus, after establishing connection between portable storage device 110 and public network 180 with the aid of host 150, which may include user identification through user interface 162, controller 140 communicates with data processor 194 for identifying and authenticating portable storage device 110 to service center 190, followed by updating permission register 132 according to the respective record of permission database 192. A exemplary mechanism for doing this may be using a secure session between the service center 190 and the device 110.
Following is a non-limiting example of an exchange of credentials using this exemplary non-limiting mechanism:
Host interface 144 initiates a 1667 handshake with device 110 using the Probe commands as defined in IEEE 1667, Page 27.
Device 110 responds to host 144 with a Probe response that includes an Authentication Silo ID as defined in IEEE 1667, Page 30-31.
Host 144 initiates a connection via HTTP/SSL (as defined in RFC 2616 and the W3C SSL Standard version 3.0) to service center 180, and POSTs the response received from Device 110.
Service Center 180 authenticates the device 110 using the workflow described in Page 23 of the IEEE 1667 standard. Each command payload cited in Annex A of the standard is generated by Service Center 180 and passed to device 110 via host 144, and each response payload generated by device 110 is passed to Service Center 180 via host 144.
Following authentication, session keys are derived from the certificate presented by device 110 and the certificate presented by the Service Center 180. These keys are used to re-negotiate a SSL connection (as described in Section 5.3 of the SSL 3.0 protocol).
The SSL connection is now encrypted using a key-pair that is stored in hardware at device 110 and at the server side in Service Center 180. Data relating to policy is encrypted end-to-end and host 144 is not privy to the content of the messages.
A third solution for connecting portable storage device 110 to service center 190 for renewing permissions assumes that public network 180 is unavailable. For example, a traveling user has no Internet access by still need to access proprietary data 120 of his/her portable storage device 110. Presuming that the user has an alternative access method, e.g. a telephone, for communicating with support desk 198 of service center 190, the user relays messages between portable storage device 110 and service center 190. For example, the user reads from user interface 162 an identification/authentication numeric message of portable storage device 110 that is generated by controller 140 under access control application 130. The user keys-in the numeric message using his telephone keypad, which is received by support desk 198 and verified by data processor 194. On successful identification/authentication by service center 190, a voice message which represents a coded permission renewal is generated by data processor 194 according to the respective record of permission database 192, and this message is heard by user 170 via manual connection 174. The user keys-in the message into user interface 162, and data processor 158 sends the message to portable storage device 110 for updating the content of permission register 132. It will be noted that if support desk 198 is manned by a human operator, user 170 can talk to that operator via manual connection 174 instead of pushing telephone buttons and listening to a synthesized voice message.
Steps step 205-255 below describe the cooperative operation of portable storage device 110 and host 150 under access control application 130 running on both controller 140 and data processor 158. In a step 205, access control application 130 is loaded into controller 140 and data processor 158. In a step 211 access control application 130 checks whether host 150 is online or offline, i.e. whether it can or cannot communicate with service center 190 via public network 180, respectively. In the online situation, in step 215 portable storage device 110 communicates with service center 190 under either of the arrangements 200H or 200C of
Also optionally in step 221, log 120L is uploaded to service center 190 for monitoring. A step 225 that follows either step 221 or an offline result in step 211, the current access permission according to permission register 132 is checked by controller 140, to determine whether the user is permitted to access proprietary data 120; in the event of an “offline” situation, this check may involve comparing the current date/time retrieved from host 150 or from an Internet host with the expiration date/time 132E (
In the event that access permission is not granted in step 255, in either online or offline situation, a step 231 checks whether a manual permission procedure (involving user 170, manual connection 174 and support desk 198 of
In the description and claims of the present application, each of the verbs, “comprise” “include” and “have”, and conjugates thereof, are used to indicate that the object or objects of the verb are not necessarily a complete listing of members, components, elements or parts of the subject or subjects of the verb.
All references cited herein are incorporated by reference in their entirety. Citation of a reference does not constitute an admission that the reference is prior art.
The articles “a” and “an” are used herein to refer to one or to more than one (i.e., to at least one) of the grammatical object of the article. By way of example, “an element” means one element or more than one element.
The term “including” is used herein to mean, and is used interchangeably with, the phrase “including but not limited” to.
The term “or” is used herein to mean, and is used interchangeably with, the term “and/or,” unless context clearly indicates otherwise.
The term “such as” is used herein to mean, and is used interchangeably, with the phrase “such as but not limited to”.
The present invention has been described using detailed descriptions of embodiments thereof that are provided by way of example and are not intended to limit the scope of the invention. The described embodiments comprise different features, not all of which are required in all embodiments of the invention. Some embodiments of the present invention utilize only some of the features or possible combinations of the features. Variations of embodiments of the present invention that are described and embodiments of the present invention comprising different combinations of features noted in the described embodiments will occur to persons of the art.
This application claims the benefit of U.S. provisional patent application 60/806,628 filed on 6 Jul. 2006 by the present inventors.
| Number | Date | Country | |
|---|---|---|---|
| 60806628 | Jul 2006 | US |