IP Library › Granted Patent US 12,475,223
Granted Patent B2
US 12,475,223 · App. 18/622,917 · Granted Nov 18, 2025

File protection using an external data storage device

Inventors: Wei Hong Tew (Penang, MY); Tze Ping Chan (Penang, MY); Jun Jeen Heng (Perak, MY)
Assignee: Sandisk Technologies, Inc.
G06F21/565G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,475,223
App. No.
18/622,917
Filed
Mar 30, 2024
Granted
Nov 18, 2025
Kind
B2
Art Unit
2438
USPC
726/23
Abstract

A host system is configured to sequester protected data files to a separate data storage device. The host system includes an input device for receiving commands from a user, storage media for storing data files including the protected data files, a communication interface configured to communicate with the separate data storage device, and a network interface configured to communicate with a network server. The host system includes one or more processors configured, individually or in combination, to receive from the user, via the input device, a request to download a file from the network server. In response to determining that the file is a potential risk to the host system, the one or more processors are further configured, individually or in combination, to transfer the first subset of files to the separate data storage device and subsequent to transferring the first subset of files, complete downloading the file.

Claims (72)

1 . A host system comprising:

an input device configured to receive commands from a user;

storage media configured to store data files, the data files including a first subset of files designated for enhanced protection;

a communication interface configured to communicate with a first data storage device that is a separate device from the host system;

a network interface configured to communicate with a network server, and

one or more processors configured, individually or in combination, to:

initialize a connection with the first data storage device via the communication interface;

receive, from the user via the input device, a request to download a first file from the network server,

initiate downloading of the first file via the network interface; and

in response to determining that the first file is a potential risk to the host system:

pause the downloading of the first file;

transfer the first subset of files to the first data storage device; and

subsequent to transferring the first subset of files;

remove the connection with the first data storage device;

delete the first subset of files from the storage media;

complete downloading the first file;

determine that the first file is not a risk to the host system:

re-initialize the connection with the first data storage device via the communication interface; and

transfer the first subset of files from the first data storage device to the storage media.

2 . The host system of claim 1 , the one or more processors further configured, individually or in combination, to:

delete the first subset of files from the first data storage device subsequent to transferring from the first data storage device to the storage media.

3 . The host system of claim 1 , wherein determining that the first file is a potential risk comprises comparing a signature from the first file with a data store of signatures of dangerous files.

4 . The host system of claim 1 , the one or more processors further configured, individually or in combination, to:

designate a first selected file for the enhanced protection and part of the first subset of files based on a selection made by the user.

5 . The host system of claim 1 , the one or more processors further configured, individually or in combination, to:

designate a first selected file for the enhanced protection and part of the first subset of files based on a frequency of use of the first file.

6 . The host system of claim 1 , the one or more processors further configured, individually or in combination, to:

operate an artificial intelligence (AI) program to identify one or more files of the first subset of files based at least in part on importance to the user.

7 . The host system of claim 1 , wherein the first subset of files comprises a number of files that can be transferred in under 60 seconds.

8 . The host system of claim 1 , wherein the first subset of files comprises a number of files that can be transferred in under 10 seconds.

9 . The host system of claim 1 , wherein the first data storage device is an external storage drive.

10 . A method for sequestering protected data files to a separate data storage device from a host system, the method comprising:

identifying a first subset of files stored in a storage media of the host system that are designated for enhanced protection;

initializing a connection with the separate data storage device;

receiving from a user, via in input device of the host system, a request to download a first file from a network server;

initiating downloading of the first file; and

in response to determining that the first file is a potential risk to the host system:

pausing the downloading of the first file;

transferring the first subset of files to the separate data storage device; and

subsequent to transferring the first subset of files:

removing the connection with the separate data storage device;

deleting the first subset of files from the storage media;

completing downloading the first file;

determining that the first file is not a risk to the host system:

re-initializing the connection with the separate data storage device; and

transferring the first subset of files from the separate data storage device to the storage media.

11 . The method of claim 10 , further comprising:

deleting the first subset of files from the separate data storage device subsequent to transferring from the separate data storage device to the storage media.

12 . The method of claim 10 , wherein determining that the first file is a potential risk comprises comparing a signature from the first file with a data store of signatures of dangerous files.

13 . The method of claim 10 , wherein determining that the first file is a potential risk comprises operating an artificial intelligence (AI) program to identify potentially risky files.

14 . The method of claim 10 , further comprising:

subsequent to transferring the first subset of files to the separate data storage device, deleting the first subset of files from the storage media.

15 . A host system configured to sequester protected data files to a separate data storage device, the host system comprising:

means for receiving commands from a user,

means for storing data files, the data files including a first subset of files designated for an enhanced protection level;

means for communicating with a first data storage device that is a separate device from the host system, and

one or more processors configured, individually or in combination, to:

initialize a connection with the first data storage device via the communication interface;

receive, from the user via the means for receiving commands, a request to download a first file from a network server;

initiate downloading of the first file via the network interface; and

in response to determining that the first file is a potential risk to the host system:

pause the downloading of the first file;

transfer the first subset of files to the first data storage device; and

subsequent to transferring the first subset of files;

remove the connection with the first data storage device;

delete the first subset of files from the storage media;

complete downloading the first file;

determine that the first file is not a risk to the host system:

re-initialize the connection with the first data storage device via the communication interface; and

transfer the first subset of files from the first data storage device to the storage media.

16 . The host system of claim 1 , wherein the communication interface comprises a universal serial bus (USB) interface.

17 . The method of claim 10 , wherein the first data storage device is an external storage drive.

Assignments (4)
PARTIAL RELEASE OF SECURITY INTERESTS Recorded Apr 25, 2025
From: JPMORGAN CHASE BANK, N.A., AS AGENT
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 071382/0001 →
SECURITY AGREEMENT Recorded Apr 25, 2025
From: SANDISK TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 071050/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 31, 2024
From: SANDISK TECHNOLOGIES LLC
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 069796/0423 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 2, 2024
From: TEW, WEI HONG; CHAN, TZE PING; HENG, JUN JEEN
To: SANDISK TECHNOLOGIES LLC
Reel/Frame 066979/0281 →
Continuity (1)
Related Publication 20250307398A1 · Oct 2, 2025
References Cited (11)
US 10503904B1 · Singh · 2019 [cited by examiner]
US 10887371B2 · Schneider · 2021 [cited by examiner]
US 11681591B2 · Kulaga et al. · 2023 [cited by applicant]
US 20050120082A1 · Hesselink · 2005 [cited by examiner]
US 20120117650A1 · Nachenberg · 2012 [cited by examiner]
US 20130254878A1 · Clarke · 2013 [cited by examiner]
US 20180373722A1 · Ulasen et al. · 2018 [cited by applicant]
US 20200036731A1 · Bochare · 2020 [cited by examiner]
US 20220083659A1 · Ma · 2022 [cited by examiner]
US 20220174078A1 · Yanagi · 2022 [cited by examiner]
Acronis Cyber Protect Cloud, Advanced Backup, 5 pages, https://www.acronis.com/en-eu/products/cloud/cyber-protect/features/#backup. [cited by applicant]