SECURITY MODULE AND METHOD FOR CONTROLLING AND MONITORING DATA TRAFFIC OF A PERSONAL COMPUTER
Patent Information
- Application Number
- DE502005016207
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2005-03-30
- Filing Date
- 2005-07-31
- Publication Date
- 2025-05-08
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Modern personnel computers face challenges in ensuring data security due to increasing complexity, software errors, operating errors, and the difficulty in preventing illegal access via computer viruses, especially with existing antivirus programs and security measures being ineffective against new viruses and errors.
A security module with a programmable logic module that independently controls and checks data traffic between the central processor, hard drive, and peripheral devices, preventing undesirable access and intervening during boot-up, thus enhancing security without relying on software-based solutions.
The security module effectively prevents unauthorized data access and intervention by software errors or viruses, ensuring increased security and reliability of data traffic, even against new threats, by operating independently of the central processor.
Description
[0001] The invention lies in the field of devices for ensuring data security of personal computers. State of the art
[0002] Modern personal computers exhibit increasing complexity both in terms of their hardware configuration and in relation to their software. They not only comprise a multitude of internal (i.e., located inside the housing) and external (i.e., located outside the housing) peripherals and other elements, such as clock generators, each with its own control electronics, but must also execute a multitude of processes simultaneously. Furthermore, today's personal computers are networked in a variety of ways with other personal computers and / or other data processing devices, such as servers, databases, printers, or the like, via communication networks, such as the Internet.
[0003] In addition to the speed of data processing and transmission, data security is of paramount importance. On the one hand, the growing complexity means that unwanted changes to data, whether due to software flaws or operator errors, cannot be prevented. On the other hand, increasing networking makes it increasingly difficult to prevent unauthorized access to data, such as through computer viruses.
[0004] Software errors, operator errors, and computer viruses are generally considered different sources of data errors that can even lead to data loss. Attempts to prevent these sources are accordingly based on very different approaches. For example, to reduce operator errors, user access to certain data is restricted, allowing free access only after correctly entering an authentication code. A hard disk can also be divided into segments, some of which are inaccessible to the user. Even though these precautions can be implemented via hardware, they only limit the amount of data that can be accessed insecurely. However, this data can still be corrupted, for example, due to operator errors.However, such security measures are usually implemented using software and can therefore be circumvented by computer viruses that have embedded themselves in the software.
[0005] Conventional anti-virus programs available on the market, known as virus protection or anti-virus programs, work by scanning the entire memory of the personal computer. The data stored in memory is compared with the program code of known computer viruses, and if a match is found, protective measures are taken to remove the malicious data. However, this can at best only provide protection against known computer viruses. Therefore, anti-virus programs are just as ineffective against new, previously unknown computer viruses as they are against operating and software errors. Furthermore, there is a risk that an anti-virus program, which is merely stored as software in the personal computer's memory, could itself become the target of a computer virus attack.
[0006] US Pat. No. 5,289,540 discloses a plug-in card that controls the data flow between drives and the rest of a personal computer's hardware. The plug-in card is configured by the personal computer's operating system during initialization. The program used to control the plug-in card is stored in the personal computer's RAM and verifies a user's access rights through authentication by requesting a user name and password. Similar to the case of an antivirus program, there is a risk that the program used to control the plug-in card, which is located in the personal computer's RAM, could be modified due to a software error, an operator error, and / or a computer virus.Furthermore, after authentication, it cannot be assumed that all user accesses to the data provided to him are permissible and interpreted correctly by the software.
[0007] Document US 6,564,326 discloses a method in which a coprocessor is installed in a personal computer with a processor. The coprocessor monitors the personal computer until it is ensured that it is free of malicious programs, such as computer viruses. The coprocessor then decouples itself from the personal computer's data traffic. The disadvantage of this method is that neither data damage due to operator errors nor data damage due to software errors is detected. Furthermore, there is a similar problem to antivirus programs: it must already be known which programs are malicious and which are not.
[0008] Document EP 1 076 279 A1 relates to a computer platform that uses a tamper-resistant component or "trusted module" of a platform in conjunction with software, preferably running within the tamper-resistant component, that controls the uploading and use of data on the platform as a generic dongle for that platform. Licensing checks may occur within a trusted environment (in other words, an environment that can be trusted to behave as the user expects). This may be ensured by integrity checks of the uploading and license-checking software. Metering records may be stored in the tamper-resistant device and reported back to administrators as required. There may be an associated clearinghouse mechanism to enable registration and payment for data.
[0009] US 2003 / 018892 describes a method and system for providing a secure boot process for a personal computer. A security kernel, which is part of the invention, typically resides in the upper memory area to encrypt or decrypt data from each application running under the operating system. The invention allows two operating systems to operate separately on the same hardware.
[0010] US 6,212,635 B1 discloses an apparatus and method for disabling a computer's access to all or part of its storage system or associated peripherals to protect the computer from accidental or malicious corruption of data files or programs that may result from the activity of computer users or computer viruses. This result is achieved by providing an authorized user with a token that allows the user to configure a security gateway to disable the peripheral completely or partially without disrupting the operation of the computer or other peripherals.The main hardware component of an embodiment of the device shown is the security gateway, which in a typical configuration adds new security features to the programmable controllers typically used for an I / O controller or hard disk controller. The invention
[0011] The object of the invention is to provide a security module for controlling and monitoring data traffic of a personal computer, which ensures increased security in the operation of the personal computer.
[0012] This object is achieved according to the invention by a security module according to independent claim 1.
[0013] A security module for controlling and monitoring data traffic of a personal computer with a plurality of functional components is disclosed, each of which is implemented by means of hardware and / or software, wherein the plurality of functional components comprises a programmable logic module in which a processing and control device for processing electronic data exchanged between the plurality of functional components is implemented by means of programming, a processor connection connected to the programmable logic module for exchanging electronic data with a central processor of the personal computer, a hard disk connection connected to the programmable logic module for exchanging electronic data with a hard disk of the personal computer,peripheral device connections connected to the programmable logic module for exchanging electronic data with peripheral devices coupled to the personal computer for data input and / or data output, and a memory module connected to the programmable logic module, which memory module comprises initialization data for the logic module, and wherein the programmable logic module is designed to be self-initializing in order to make the processing and control device in the programmable logic module independently functional with the aid of the initialization data.
[0014] The security module has the advantage over the state of the art in that a programmable logic module controls and monitors the personal computer's data traffic, operating independently of the personal computer. This means that the personal computer's central processor cannot control the programmable logic module. By checking the data exchanged between individual components of the personal computer during data traffic, for example, between the central processor, the hard drive, and the peripheral devices, the programmable logic module can prevent any unwanted access to the data due to software errors, operator errors, and / or computer viruses. Because the programmable logic module is self-initializing, it can also intervene to control and monitor the personal computer's boot process.
[0015] In an advantageous embodiment of the invention, the functional components are designed as an encapsulated system. This means that the functional components are combined into a self-operating system. This makes defects in the safety module easier to locate, and the safety module can be replaced more easily in such a case.
[0016] In a more user-friendly development of the invention, the multiple functional components are implemented on a plug-in card. This allows a conventional personal computer to be equipped with the security module without having to modify the architecture of the personal computer.
[0017] In a compact embodiment of the invention, the multiple functional components are implemented on a personal computer motherboard. This shortens the data traffic paths between the personal computer's central processor and the security module, resulting in increased performance. It also keeps additional external connections, such as plug-in card connections, to the motherboard free.
[0018] In a preferred embodiment of the invention, the plurality of functional components are at least partially formed in a chipset of the motherboard. This minimizes the space required for the security module, which is a significant advantage, for example, for use in a mobile personal computer.
[0019] In an expedient development of the invention, the plurality of functional components are at least partially formed in a northbridge chip of the motherboard chipset. Since northbridge chips connect the central processor to the remaining hardware of the personal computer, this embodiment can at least partially eliminate interfaces from the security module to the peripheral devices. This saving also results in an increase in speed, since the security module can now communicate directly with the central processor instead of relying on communication via a bus system.
[0020] In an advantageous embodiment of the invention, the memory module is incorporated into a RAM memory of the personal computer. This allows additional memory for the security module to be partially or completely eliminated, resulting in a more cost-effective and compact design.
[0021] In a preferred embodiment of the invention, the programmable logic component is an FPGA (Field Programmable Gate Array). This has the advantage that the security module can be manufactured using well-known FPGA technology, both for the programmable logic component itself and for the programming tools required for its programming. This allows computationally intensive processes to be executed in parallel in hardware, rather than sequentially in software, thus saving time.
[0022] An advantageous development of the invention provides that a comparison device, included in the processing and control device, is implemented in the programmable logic module by means of programming for comparing electronic data exchanged between the multiple functional components with predefined stored control data. This embodiment allows the programmable logic module to detect, for example, an exchange of faulty data and / or an unauthorized exchange of data and, if necessary, to intervene and correct the exchange, for example, by preventing such an exchange. Likewise, the stored control data can be adapted depending on the incoming electronic data.For example, a specific keystroke or a data sequence received via the network connection can be recognized by the comparison device and then trigger a predefined control function, the result of which is manifested in an adjustment of the control data.
[0023] Preferably, one embodiment of the invention provides that the multiple functional components for devices coupled to the multiple functional components are designed as transparently operating functional components during data exchange. This ensures that the software running on the personal computer is not affected by the presence of the security module. The software for controlling the personal computer therefore does not need to be adapted for use with the security module. As a further advantage of this embodiment, a computer virus embedded in the personal computer's software would not be able to determine whether a security module is present that should be bypassed.
[0024] Also disclosed is a method for controlling and monitoring data traffic of a personal computer using a security module as described above, wherein a processor port of the security module connected to a programmable logic module of the security module is connected to a central processor of the personal computer for exchanging electronic data, a hard disk of the personal computer is coupled to a hard disk port of the security module connected to the programmable logic module for exchanging electronic data, peripheral devices for data input and / or data output are coupled to peripheral device ports of the security module connected to the programmable logic module, and the programmable logic module is connected to a memory module containing initialization data for the programmable logic module, and wherein the method comprises the following steps: a processing and control device is made functional in the programmable logic module of the security module by means of self-initialization of the programmable logic module by using the initialization data from the memory module, and data traffic from and / or to the hard disk of the personal computer as well as data traffic between the peripheral devices for data input and / or data output and the central processor of the personal computer are carried out exclusively via the security module and are controlled and monitored by means of the processing and control device.
[0025] Advantageously, the method is designed such that the data traffic from and / or to the hard disk of the personal computer as well as the data traffic between the peripheral devices for data input and / or data output and the central processor of the personal computer are carried out via the security module in a manner transparent to the central processor, the hard disk and the peripheral devices for data input and / or data output.
[0026] In a further advantageous embodiment of the method, the data of the data traffic executed via the security module is compared in the security module with predefined stored comparison data using a comparison device. It may also be advantageous if the self-initialization of the programmable logic module occurs when an operating voltage is applied. Description of preferred embodiments
[0027] The invention is explained in more detail below using exemplary embodiments with reference to a drawing. The sole figure shows a schematic representation of a security module with a programmable logic component.
[0028] According to the figure, a security module 1 has several functional components, which include a programmable logic module 2, a processor port 3, a hard drive port 4, peripheral device ports 5, and a memory module 6. The security module 1 is installed in a personal computer 10, which is equipped with a central processor or microprocessor 11, a hard drive 12, a memory 14, and peripheral devices 13. The personal computer 10 can be any type of computer system with a central processor and a hard drive. For example, the personal computer 10 can include a mobile computer, such as a laptop or a PDA (Personal Digital Assistant).
[0029] The programmable logic device 2 can be formed using any type of programmable logic device (also called PLD - "Programmable Logic Device") that can be programmed to process electronic data exchanged between the multiple functional components. This can be either a multiple-programmable or a single-programmable logic device. With multiple-programmable logic devices, programming is performed using memory cells contained in the programmable logic device 2, for example, SRAM, EPROM, EEPROM, and / or flash memory cells. Preferably, an FPGA (Field Programmable Gate Array) device is used for the programmable logic device 2. However, a CPLD (Complex Programmable Logic Device) device or an ASIC (Application Specific Integrated Circuit) device can also be used as the programmable logic device 2.
[0030] The processor port 3 connected to the programmable logic module 2 is used for data exchange between the security module 1 and the microprocessor 11 of the personal computer 10. If the personal computer 10 comprises multiple microprocessors, i.e., if it is a so-called multiprocessor computer, the processor port 3 can be designed to enable data exchange either with just one or with two or more of the multiple microprocessors. The processor port 3 can also be designed to establish an indirect connection between the programmable logic module 2 and the microprocessor 11. For example, this connection can be established via a controller, in particular a hard disk controller. This ensures that the microprocessor continues to exchange its information with the peripheral devices via the controllers.This is important, for example, in embodiments of the invention in which a request from the microprocessor 11 to the hard disk 2 is made via the security module 10, but the microprocessor 11 does not notice the presence of the security module 10, i.e., when the functional components of the security module 1 operate transparently for the data exchange between the microprocessor 11 and the hard disk 12. To do this, the security module 10 must simulate the functions of the hard disk 12 to the microprocessor 11. This means that the security module 10 must send signals to the microprocessor 11 via the processor connection 3, which the microprocessor 11 interprets as originating from the hard disk 12.
[0031] The programmable logic module 2 is also connected to the hard drive connector 4, via which a connection is established to one or more hard drives 12 of the personal computer 10. The hard drive 12 can be a hard drive of any available technology, in particular of any size and / or storage capacity; for example, it can also comprise a so-called MicroDrive. Data transmission to and from the hard drive 12 can be carried out using any commonly used communication standard, for example, an IDE, an EIDE, or a SATA standard (IDE - "Integrated Drive Electronics", EIDE - "Enhanced IDE", SATA - "Serial Advanced Technology Attachments").
[0032] The peripheral device ports 5 can include ports to any type of peripheral device 13 that can be controlled by a personal computer 10. In particular, these are peripheral devices for data input, for example a keyboard, a mouse, a scanner, or the like, and peripheral devices for data output, for example a graphics card, a printer, a sound card, or the like. However, there can also be peripheral device ports 5 to peripheral devices that serve not only for data input but also for data output, for example to internal (i.e., located within a housing of the personal computer 10) or external (i.e., located outside a housing of the personal computer 10) storage devices, as well as to network cards with, for example, modem, ISDN, and / or LAN functionality.
[0033] Network cards 1, in particular, represent a significant source of malicious data because they connect the personal computer 10 to communications networks. Furthermore, the personal computer 10 can inadvertently use a network card to send messages, for example, via email, to other computer systems connected to the communications network, for example, due to software errors, operating errors, or computer viruses. Therefore, one embodiment of the invention provides that all data traffic between the microprocessor 11 of the personal computer 10 and the network cards (not shown) is routed via the security module 1 and controlled and / or monitored by the programmable logic module 2. Network cards with any desired communications standards or protocols can be present.
[0034] In particular, it can be provided that one or more of the network cards have two or more so-called MAC addresses (MAC - "Media Access Control"). The MAC address is an address that is assigned to each network card during its manufacture and with which the network card is addressed at a transmission level of a communications network that lies below the transmission level at which so-called IP addresses (IP - "Internet Protocol") are used. In order to be able to address a personal computer either at a system management level or at an operating system level, these must be uniquely addressable via a level-dependent MAC address of the network card or IP address of the computer. In order to eliminate the need for an additional network card for system management and the additional cable connection required for this, and to avoid having to change the existing IP addressing, the presence of multiple MAC addresses is advantageous.
[0035] The connections of the security module 1, which include the processor connection 3, the hard drive connection 4, and the peripheral device connections 5, can be designed as simple connections. However, they can also, at least in part, comprise more complex circuits, which, for example, perform protocol and / or level adaptation of exchanged signals. The security module 1 is equipped with coding and / or decoding means to convert signals between different communication standards used in the personal computer 10. The coding and / or decoding means can be implemented as parts of the programmable logic module 2 and / or the connections.
[0036] Finally, the memory module 6 serves to provide initialization data to the programmable logic module 2. At least part of the memory module 6 should be designed as a non-volatile memory module so that its memory content is not lost after the operating voltage is switched off. The initialization data is available to the programmable logic module 2 at any time, in particular immediately after an operating voltage is applied, and serves to ensure that the security module 1 can operate independently of external memory components, for example, the RAM memory of the personal computer 10. The non-volatile memory module can be any type of memory module that retains its content even after the operating voltage is switched off. For example, the memory module 6 can comprise a flash memory.It can also be a volatile memory chip, powered by its own energy source, such as a battery. The non-volatile memory chip can also be integrated into the programmable logic chip 2.
[0037] In addition to the non-volatile memory module, the memory module 6 can also include its own volatile memory module, for example, a RAM memory, in which the programmable logic module 2 can store data for later use during operation. However, a portion of the memory 14 of the personal computer 10 can also be used for this purpose by reserving this portion for the security module 1 during the self-initialization of the programmable logic module 2, and the microprocessor 11 can only freely access the remaining portion of the memory 14. Similarly, a portion of the storage capacity of the hard disk 12 can also be used by the security module 1.
[0038] The peripheral devices 13, the hard disk 12, and / or the microprocessor 11 can be addressed via a bus system of the personal computer 10. Particularly in an embodiment of the security module 1 as a PCI plug-in card, this eliminates the need for separate physical connections on the security module 1.
[0039] To ensure that the security module 1 performs its monitoring and control functions as comprehensively as possible, in one embodiment, all data traffic between the microprocessor 11, the hard disk 12, and the peripheral devices 13 is routed via the security module 1. For speed reasons, it may be advantageous for certain data to be exchanged without going through the security module 1. For example, if multiple hard disks are present, the hard disk containing less important data can also be connected directly to the microprocessor 11.
[0040] In order for the security module 1 to be able to control and monitor the data traffic of the personal computer 10, the functional components of the security module 1 must first be set to a defined initial state. For this purpose, after applying an operating voltage, the programmable logic module 2 is initialized. During this initialization, a processing and control device in the programmable logic module 2 is prepared and supplied with initialization data. The processing and control device serves to control all functional components of the security module 1 independently of the microprocessor 11.
[0041] After initialization, the programmable logic module 2 is able to receive data via the connections and compare it with data stored in the memory module 6 in order to perform an action in response, for example, to generate a warning message if important data is to be deleted.
[0042] An important process is the initialization of the hard disk 12 using program routines stored in the BIOS, an intermediary program between the software and hardware of a personal computer. During an initialization process of the personal computer 10 (also called the boot process), technical data of the hard disk 12, for example, concerning the hard disk storage capacity, are queried via a hard disk controller. This request is received by the programmable logic module 2 via the processor port 3 and answered with the help of data relating to the hard disk 12 stored in the memory module 6. If, for example, an area of the hard disk 12 is occupied by the security module 1, the microprocessor 11 is informed of a hard disk storage capacity that is reduced by the storage capacity of the occupied area.
[0043] According to this, access by the microprocessor 11 to the hard disk 12 occurs in such a way that instructions from the microprocessor 11 to the hard disk 12 are first received by the programmable logic module 2 via the processor connection 3. These instructions are then checked by the processing and control device and compared with data stored in the memory module 6. If the processing and control device determines that an action corresponding to the instruction is not permitted, i.e., if the microprocessor 11 attempts to perform an unauthorized action, for example, access an inaccessible area of the hard disk 12, then this instruction is not forwarded to the hard disk 12. Instead, an error message is transmitted to the microprocessor 11 via the processor connection 3, which is identical to an error message from the hard disk 12.In this way, the microprocessor 11 is tricked into believing that a direct data exchange has taken place between it and the hard disk 12. The error message can, for example, be a message informing that the relevant area of the hard disk 12 is not present. Valid instructions and data are transmitted unchanged to the hard disk 12 via the hard disk connection 4. This means that the programmable logic module 2, the processor connection 3, and the hard disk connection 4 operate transparently.
[0044] Data exchange with the peripheral devices 13 for data input and / or output is handled in a similar manner. Data input can be performed, for example, using a keyboard. When a key or key combination is pressed, a signal is first sent to a peripheral device connection 5 of the security module 1. The signal is decoded there or forwarded directly to the programmable logic module 2. If the processing and control device of the programmable logic module 2 determines, based on the data stored in the memory module 6, that the execution of an instruction associated with the key combination will lead to an unauthorized action, the signal is either completely ignored and / or a corresponding warning is displayed via another peripheral device, for example, a monitor.In this way, a command can also be sent to the processing and control device itself, using it exclusively within the processing and control device to start a software routine, but the keystroke is not forwarded to the microprocessor 11. This also prevents malicious software running on the microprocessor 11 from monitoring the operation of the processing and control device.
[0045] The features of the invention disclosed in the above description, the claims and the drawings may be important both individually and in any combination for the realization of the invention in its various embodiments.
Claims
1. Security module (1) for controlling and monitoring data traffic of a personal computer (10), comprising a plurality of functional components each implemented by means of hardware and software, the plurality of functional components comprising: - a programmable logic component (2) in which a processing and control device for processing electronic data exchanged between components of the personal computer is implemented by means of programming; - a processor connection (3) connected to the programmable logic module (2) for exchanging electronic data with the central processor (11) of the personal computer (10); - peripheral device connections (5) connected to the programmable logic component (2) for exchanging electronic data with peripheral devices (13) coupled to the personal computer (10) for data input and / or data output; and - a memory module (6) connected to the programmable logic component (2), which comprises initialisation data for the logic component (2) and control data, wherein the programmable logic component (2) is designed to be self-initialising, wherein in the programmable logic component (2), by means of programming, a comparison means comprised by the processing and control means for comparing electronic data exchanged between the plurality of components of the personal computer with stored control data is implemented, wherein the programmable logic component (2) is designed in such a way that it can detect an unauthorised exchange of data by means of the comparison means on the basis of the control data stored in the memory module (6) and, if necessary, take corrective action, wherein, when a key is pressed on a keyboard, a signal is transmitted via this to one of the peripheral device connections (5) and wherein the signal is decoded in the security module and wherein, if the comparison device determines on the basis of the control data stored in the memory module (6) that a command to the processing and control device is associated with the keystroke, the command is used exclusively within the processing and control device to start a software routine, but the keystroke is not forwarded to the microprocessor (11).
2. Security module (1) according to claim 1, wherein the programmable logic component (2) is designed to be self-initialising after an operating voltage is switched on.
3. Security module (1) according to one of the preceding claims, wherein the plurality of functional components for devices coupled to the plurality of functional components are designed as transparently operating functional components during data exchange.
4. Security module (1) according to one of the preceding claims, wherein the peripheral devices (13) comprise a network card and wherein the data traffic between the central processor (11) of the computer system (10) and the network card takes place via the security module (1).
5. Security module (1) according to the previous claim, wherein the programmable logic component (2) is designed such that it can detect an unauthorised exchange of data between the central processor (11) and the network card and, if necessary, intervene to correct it.
6. Security module (1) according to any one of claims 4 or 5, wherein the comparison means is configured to compare data exchanged between the network card and the central processor (11).
7. Security module (1) according to one of the preceding claims, characterised in that the plurality of functional components are designed as an encapsulated system.
8. Security module (1) according to one of the preceding claims, additionally comprising: a hard disk connection (4) connected to the programmable logic component (2) for exchanging electronic data with a hard disk (12) of the personal computer (10).
9. Security module (1) according to claim 8, wherein an instruction from the central processor (11) to the hard disk (12) is first received by the programmable logic component (2) via the processor connection (3), then checked by means of the processing and control device and compared with data stored in the memory module (6) and, if the processing and control device determines that an action corresponding to the instruction is not permitted, the instruction is not forwarded to the hard disk (12), but instead an error message is transmitted to the central processor (11) via the processor connection, which is identical to an error message from the hard disk (12), wherein a permissible instruction is transmitted unchanged via the hard disk connection (4) to the hard disk (12).
10. Security module (1) according to any one of the preceding claims, wherein the connections at least partially comprise circuits for protocol and / or level adaptation.
11. Security module (1) according to one of the preceding claims 2 to 10, characterised in that it can also intervene in a controlling and, if necessary, monitoring manner during a boot process of the personal computer.