US2013074178A1PendingUtilityA1

Preventing access of a host device to malicious data in a portable device

Assignee: SOBOL EYALPriority: Sep 15, 2011Filed: Sep 15, 2011Published: Mar 21, 2013
Est. expirySep 15, 2031(~5.1 yrs left)· nominal 20-yr term from priority
G06F 21/56G06F 21/78
45
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A storage device comprising a memory, a controller, and a host interface operative to connect with a host. The memory contains data locations that are controllable by a protection application which is executable on a host. When the host interface is operatively coupled to a host, data locations in the memory are accessible to an operating system of the host under permission from the protection application. The controller communicates with the protection application running on the host for allowing the protection application access to data locations in the memory. Upon a host request for access to a data location, the controller determines if permission to access the requested data location is acquired from the protection application. The permission is based on a determination by the protection application that the data location does not contain malicious data.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method of communicating data between a storage device and a host, comprising:
 in a storage device having a memory, a controller and a host interface, the memory containing data locations access to which is controllable by a protection application which is executable on a host, such that when the storage device is operatively coupled to the host via the host interface data locations in the memory are accessible to an operating system of the host only under permission from the protection application, with the controller performing:
 communicating with the protection application running on the host for allowing the protection application access to data locations in the memory; and 
 upon a host request for access to a data location received by the controller, determining if permission to access the requested data location is acquired from the protection application, the permission being based on determination of the protection application that the requested data location does not contain malicious data harmful to the host operating system, to any application and/or to any data on the host. 
   
     
     
         2 . The method of  claim 1 , wherein with the storage device is operationally coupled to a host, the storage device is recognized by the host such that the data locations in the memory are inaccessible by the host operating system. 
     
     
         3 . The method of  claim 1 , wherein the storage device is a removable external storage device or a storage device embedded in a host. 
     
     
         4 . The method of  claim 1 , wherein the protection application resides on the storage device and is executed from the storage device. 
     
     
         5 . The method of  claim 1 , wherein the protection application employs an antivirus protection application operative to identify infected files. 
     
     
         6 . The method of  claim 1 , wherein the communicating with the protection application on the host is contingent on the controller performing mutual authentication with the host. 
     
     
         7 . The method of  claim 1 , wherein proving the host operating system access to the host requested data is conditioned on an indication coming in from the protection application, the indication notifying the controller that the requested data location does not contain malicious data harmful to the host operating system, to any application and/or to any data on the host. 
     
     
         8 . The method of  claim 1 , wherein communicating with the protection application on the host is performed by using a set of commands that conform to a communication protocol. 
     
     
         9 . The method of  claim 8 , wherein at least one command from the set of commands includes an operation code that is interpreted by the controller as a command to read from a data location in the memory, to write to a data location in the memory, or to make a data location in the memory accessible to the operating system of the host. 
     
     
         10 . The method of  claim 1 , wherein the data locations in the memory are associated with a portion of the memory that is presented to the host as a removable memory. 
     
     
         11 . A storage device comprising:
 a memory for storing data, the memory containing data locations access to which is controllable by a protection application which is executable on a host;   a host interface operative to connect with a host; and   a controller configured to, when the host interface is operatively coupled to a host data locations in the memory are assessable to an operating system of the host only under permission from the protection application:
 communicate with the protection application running on the host for allowing the protection application access to data locations in the memory; and 
 upon a host request for access to a data location received by the controller, determine if permission to access the requested data location is acquired from the protection application, the permission being based on determination of the protection application that the requested data location does not contain malicious data harmful to the host operating system, to any application and/or to any data on the host. 
   
     
     
         12 . The storage device of  claim 11 , wherein when the host interface is operationally coupled to a host the storage device is recognized by the host such that the data locations in the memory are inaccessible by the host operating system. 
     
     
         13 . The storage device of  claim 11 , wherein the host interface is removable external to a host or embedded in a host. 
     
     
         14 . The storage device of  claim 11 , wherein the protection application resides on the storage device and is executed from the storage device. 
     
     
         15 . The storage device of  claim 11 , wherein the protection application employs an antivirus protection application operative to identify infected files. 
     
     
         16 . The storage device of  claim 11 , wherein the controller communicates with the protection application on the host contingent on the controller performing mutual authentication with the host. 
     
     
         17 . The storage device of  claim 11 , wherein the controller is configured to provide the host operating system access to the host requested data conditioned on an indication coming in from the protection application, the indication notifying the controller that the requested data location does not contain malicious data harmful to the host operating system, to any application and/or to any data on the host. 
     
     
         18 . The storage device of  claim 11 , wherein the controller communicates with the protection application on the host by using a set of commands that conform to a communication protocol. 
     
     
         19 . The storage device of  claim 18 , wherein at least one command from the set of commands includes an operation code that is interpreted by the controller as a command to read from a data location in the memory, to write to a data location in the memory, or to make a data location in the memory accessible to the operating system of the host. 
     
     
         20 . The storage device of  claim 11 , wherein at least a portion of the memory is presented to the host as a removable memory, such that the data locations in the memory are associated with the removable memory.

Join the waitlist — get patent alerts

Track US2013074178A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.