IP Library Granted Patent US 11,461,490
Granted Patent B1
US 11,461,490 · App. 17/030,119 · Granted Oct 4, 2022

Systems, methods, and devices for conditionally allowing processes to alter data on a storage device

Inventors: William Livengood (Andover, KS); William M. Head, II (Bel Aire, KS); Dean L. Mehler (Bel Aire, KS)
Assignee: CRU Data Security Group, LLC
G06F21/6218G06F3/0622G06F3/0655G06F3/0676G06F3/0677G06F3/0679G06F21/56
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,461,490
App. No.
17/030,119
Granted
Oct 4, 2022
Kind
B1
Abstract

A combination default write-blocking system may include a host computer. The host computer may include at least one general storage device storing program instructions for a blocking driver assembly and a host processor configured as the blocking driver assembly while executing the program instructions for the blocking driver assembly. A connection interface device physically separate from the host processor, and the connection interface device is configured to be operatively coupled to the host processor and to a protected storage device physically separate from the general storage device, receive a communication from the blocking driver assembly, and establish communication between the protected storage device and the host processor after receiving the communication from the blocking driver assembly. The blocking driver assembly is further configured to communicate with the connection interface device and conditionally allow a host computer process to alter data stored on the protected storage device.

Claims (53)

1. A combination default write-blocking system comprising:

a host computer including:

at least one general storage device configured to store program instructions for a blocking driver assembly; and

a host processor operatively coupled to the at least one general storage device and configured as the blocking driver assembly while executing the program instructions for the blocking driver assembly; and

a connection interface device physically separate from the host processor and configured to be operatively coupled to the host processor and to a protected storage device physically separate from the at least one general storage device, receive a communication from the blocking driver assembly, and establish communication between the protected storage device and the host processor after receiving the communication from the blocking driver assembly; and

wherein the blocking driver assembly is further configured to communicate with the connection interface device and conditionally allow a host computer process to alter data stored on the protected storage device.

2. The combination default write-blocking system of claim 1 , wherein the at least one general storage device is further configured to store at least one authorized identifier associated with at least one authorized host computer process authorized to alter data stored on the protected storage device, and the blocking driver assembly is further configured to allow the at least one authorized host computer process to alter data stored on the protected storage device based on the at least one authorized identifier, and prevent a host computer process not associated with an authorized identifier, including the at least one authorized identifier, from altering data stored on the connected protected storage device.

3. The combination default write-blocking system of claim 2 , wherein:

the blocking driver assembly includes a high-level driver and a low-level driver,

the high-level driver is configured to associate a command with a host computer process that issued the command and further to determine if the associated host computer process is associated with the authorized identifier, and

the low-level driver is configured to establish communication with the connection interface device before the connection interface device establishes communication between the protected storage device and the host processor, and communicate the command with the protected storage device when the associated host computer process is associated with the at least one authorized identifier.

4. The combination default write-blocking system of claim 3 , wherein the high-level driver is further configured to add a tag to the command indicating whether the associated host computer process is associated with the authorized identifier, and the low-level driver is further configured to block or pass the command, based on the tag added to the command.

5. The combination default write-blocking system of claim 4 , wherein the high-level driver is further configured to block the command if the associated host computer process is not associated with the authorized identifier and the command would alter data stored on the protected storage device.

6. The combination default write-blocking system of claim 4 , wherein the low-level driver is further configured to allow the command having the tag indicating that the associated host computer process has the authorized identifier.

7. The combination default write-blocking system of claim 4 , wherein the low-level driver is further configured to block the command not having the tag indicating that the associated host computer process is associated with the at least one authorized identifier.

8. The combination default write-blocking system of claim 3 , wherein the high-level driver is further configured to block the command from being communicated to the low-level driver if the command is from a host computer process not associated with the at least one authorized identifier.

9. The combination default write-blocking system of claim 2 , wherein the program instructions for the blocking driver assembly includes instructions for a supplemental process configured to:

access authorization information identifying one or more authorized host computer process, including the at least one authorized host computer process, authorized to alter data stored on the protected storage device;

generate, from the accessed authorization information, a first list of one or more process-related identifier, wherein each of the one or more process-related identifier is associated with one or more of the identified authorized host computer process; and

store, on the at least one general storage device, the first list of the one or more process-related identifier and associated one or more of the identified authorized host computer process.

10. The combination default write-blocking system of claim 9 , wherein the supplemental process is further configured to store, on the at least one general storage device, a second list of each of the one or more authorized identifier for which the associated one or more authorized host computer process is currently active.

11. The combination default write-blocking system of claim 10 , wherein the supplemental process is further configured to:

monitor each of the one or more authorized host computer process that is currently active; and

remove from the second list the authorized identifier of the one or more authorized identifier when the associated one of the one or more associated authorized host computer process becomes inactive.

12. The combination default write-blocking system of claim 11 , wherein the supplemental process is further configured to:

determine when no authorized host computer process is active; and

send to the connection interface device an instruction to disconnect the protected storage device when no authorized host computer process is active.

13. The combination default write-blocking system of claim 10 , wherein the program instructions for the blocking driver assembly includes instructions for at least a first driver for driving the protected storage device, and the supplemental process is further configured to send to the first driver the second list, and the first driver is configured to determine if an associated host computer process that issued a command received by the first driver is associated with an authorized identifier on the second list.

14. The combination default write-blocking system of claim 13 , wherein the first driver is configured, when the first driver determines the associated host computer process that issued the command is not associated with an authorized identifier on the second list, to:

send a communication to the supplemental process inquiring as to whether the associated host computer process that issued the received command is an authorized host computer process;

receive a response from the supplemental process indicating whether or not the associated host computer process that issued the received command is associated with a process-related identifier on the first list and has an associated authorized identifier; and

add the associated authorized identifier to the second list if the associated host computer process that issued the received command is associated with a process-related identifier on the first list.

15. The combination default write-blocking system of claim 13 , wherein, if the supplemental process notifies the first driver that the command is from a host computer process that is not associated with a process-related identifier on the first list, the first driver adds an unauthorized identifier to a third list of unauthorized identifiers associated with unauthorized host computer processes.

16. The combination default write-blocking system of claim 15 , wherein, if the host computer process that issued the received command is not associated with an authorized identifier on the second list, and prior to sending the inquiry to the supplemental process asking if the host computer process that issued the received command is associated with a process-related identifier on the first list, the first driver determines if the host computer process that issued the received command is associated with an unauthorized identifier on the third list.

17. The combination default write-blocking system of claim 13 , wherein the first driver is a high-level driver and the program instructions for the blocking driver assembly includes instructions for a low-level driver, the supplemental process is configured to send to the low-level driver the second list, and the low-level driver is configured to receive the second list from the supplemental process.

18. The combination default write-blocking system of claim 17 , wherein the low-level driver is configured to receive a command issued by a host computer process, and determine if the host computer process that issued the received command is associated with an authorized identifier on the second list.

19. The combination default write-blocking system of claim 9 , wherein the supplemental process is further configured to communicate with the connection interface device; and the connection interface device is configured to communicate with the supplemental process, and establish communication between the protected storage device and the host computer only after communication with both the blocking driver assembly and the supplemental process.

20. The combination default write-blocking system of claim 9 , wherein the at least one general storage device is further configured to store an authorized identifier associated with an associated plurality of authorized host computer processes authorized to alter data stored on the protected storage device, including the at least one authorized host computer process, and the blocking driver assembly is further configured to block each of the associated plurality of authorized host computer processes from altering data stored on the connected protected storage device when at least one of the associated plurality of authorized host computer processes is inactive.

21. The combination default write-blocking system of claim 20 , wherein the supplemental process is further configured to:

store on the at least one general storage device an indication of the authorized identifier for which each of the associated plurality of authorized host computer processes are currently active;

monitor the associated plurality of authorized host computer processes; and

remove the indication of the authorized identifier when at least one of the associated plurality of authorized host computer processes becomes inactive.

22. The combination default write-blocking system of claim 3 , wherein the at least one general storage device is further configured to store instructions for a supplemental process configured to:

monitor the high-level driver and the low-level driver; and

send to the connection interface device an instruction to disconnect the protected storage device when either one of the high-level driver and the low-level driver ceases to be active.

23. The combination default write-blocking system of claim 2 , wherein the at least one general storage device is further configured to store an authorized identifier for each of an associated plurality of authorized host computer processes authorized to alter data stored on the protected storage device, including the authorized host computer process, and the blocking driver assembly is further configured to block each of the associated plurality of authorized host computer processes from altering data stored on the connected protected storage device when at least one of the associated plurality of authorized host computer processes becomes inactive.

24. The combination default write-blocking system of claim 23 , wherein the at least one general storage device is configured to store instructions for a supplemental process configured to:

store, on the at least one general storage device when the associated plurality of authorized host computer processes is currently active on the host computer, an indication that the associated plurality of authorized host computer processes associated with the authorized identifier are currently active;

monitor an activity of each of the associated plurality of authorized host computer processes; and

remove the indication when at least one of the associated plurality of authorized host computer processes becomes inactive.

25. The combination default write-blocking system of claim 2 , wherein:

the blocking driver assembly is further configured to monitor an activity of each of the at least one authorized host computer process, and send to the connection interface device an instruction to connect the protected storage device to the host computer when at least one authorized host computer process becomes active; and

the connection interface device is further configured to connect the protected storage device to the host processor only after the connection interface device receives the instruction from the blocking driver assembly to connect the protected storage device to the host processor when at least one authorized host computer process becomes active.

Assignments (2)
SECURITY INTEREST Recorded Sep 9, 2025
From: CRU DATA SECURITY GROUP, LLC; DATA MATRIX INTERMEDIATE HOLDINGS, LLC
To: ZIONS BANCORPORATION, N.A.
Reel/Frame 072203/0964 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 24, 2020
From: LIVENGOOD, WILLIAM; HEAD, WILLIAM M., II; MEHLER, DEAN L.
To: CRU DATA SECURITY GROUP, LLC
Reel/Frame 053871/0807 →