Security system and method defined by means of hardware

WO2026167520A1PCT designated stage Publication Date: 2026-08-13TT GROUP SRL
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2026-02-02
Publication Date
2026-08-13

Smart Images

  • Figure IB2026050959_13082026_PF_FP_ABST
    Figure IB2026050959_13082026_PF_FP_ABST
Patent Text Reader

Abstract

The present invention relates to a security system and method defined by means of hardware (1) (HDSec) for electronic devices. The system includes configurable hardware components on the printed circuit board, including DIP switches (2), PCB jumpers (3) and daughter cards (4). The system uses physical protection mechanisms (6) for interrupting communication channels such as HDMI, USB, UART, Ethernet, audio, optical and a logical protection unit (5) programmable to read and apply configurations based on the hardware states. The method allows setting and managing such configurations by means of physical access to the device, and allows setting the hardware states by means of specific components, visual or instrumental verification of the set configurations and restoration of the physical protections in order to prevent unauthorized access, remotely ensuring inviolable protections, adaptable for multiple application contexts.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] LEIBO. / 71e2025

[0002] “Security system and method defined by means of hardware”

[0003] Description

[0004] Field of the art

[0005] The invention refers to the field of computer protection, with particular reference to the systems and to the methods for ensuring the security of electronic devices by means of hardware configurations.

[0006] Prior art

[0007] In the field of protection of electronic devices, numerous solutions have been proposed for ensuring data security and the security of critical functions against remote attacks or physical tampering. In general, the pre-existing systems tend to be based on merely software approaches or on fixed hardware configurations, which do not offer an integrated protection against combined tampering attempts (physical and remote). Even if technologies are available on the market that use programmable logic units or secure memories for protecting configurations, these are vulnerable to firmware attacks or reguire highly specialized interventions for the installation and maintenance.

[0008] With regard to the industrial patents, it is observed that the patent application US2025021495A1 describes a system for the protected processing comprising: - an interconnection;

[0009] - a processing element connected in a communicative manner to the interconnection;

[0010] - a memory controller connected in a communicative manner to the interconnection and to a memory;

[0011] - in which the access of a memory block by the memory controller to and from the interconnection is accompanied by a security class of a plurality of security classes;LEIBO. / 71e2025

[0012] - each memory block is associated with a security class assigned to the content stored in the memory block between a plurality of security classes; the security class associated with each memory block travels in the system together with the content of the associated memory block.

[0013] The memory controller employs at least a matrix that defines the interactions between the security classes of the content memory blocks such as the content of the memory blocks which are managed at least by the memory controller.

[0014] According to the patent application KR20240176636, a system and method for security and acceleration is disclosed, based on hardware for the reliable serverless calculation, executed by a security system according to one embodiment, which includes: configuring a reliable execution area that comprises an enclave sandbox and an enclave monitor associated with the enclave sandbox; and providing two-way security between the enclave sandbox and the cloud platform within the configured reliable execution area.

[0015] In the prior art, as underlined in the analysis of the abovementioned documents, a system is neither present nor suggested that synergistically combines physical and logical protections based on hardware configurations for guaranteeing the security of electronic devices against remote and local attacks.

[0016] In light of that set forth above, the proposed invention is distinguished for the use of an integrated system that combines active physical protections, configurable by means of dedicated hardware components, with logical protections based programmable units. The presented invention is distinguished for the introduction of a security system defined by means of hardware that combines physical and logical protections in a unigue manner.

[0017] This innovative solution provides greater versatility and strength with respect to that present in the prior art, meeting operating needs that reguire high standards of security, configurability and reliability.

[0018] Description of the inventionLEIBO. / 71e2025

[0019] With the present industrial invention patent application, it is intended to describe and claim a system provided with at least a new solution, an alternative to the solutions known up to now, by introducing a security system and method defined by means of hardware (also HDSec) designed for ensuring a high level of protection against unauthorized modifications, both physical and remote. By integrating configurable hardware components, logic and physical protection mechanisms, the invention allows managing and protecting the critical functions of a device in a manner that is safe, reliable and adaptable to different application contexts. The solution is particularly suitable for devices which reguire advanced protections. Examples of devices and application fields:

[0020] A. In the audio-visual application field:

[0021] a. KVM (Keyboard Video Mouse) Systems: in this case, the Hdsec security system will protect, for example, the source and destinations connected to the system, in order to isolate them, or protect the system from external attacks;

[0022] b. Presentation switches,

[0023] c. video wall controllers.

[0024] B. In the application field IT:

[0025] a. Computer: the HDsec system isolates the computer and each of the relative interfaces from external attacks, e.g. video (HDMI, Display Port, DVI, etc..), audio, USB, USB-C, RS232, memory cards, network carriers, etc.

[0026] b. Network switch: the system HDsec protects network ports or isolates specific ports in order to create network divisions.

[0027] C. In the medical application field:

[0028] a. the system is configured for protecting each apparatus network connected to the network, or to other devices, for example, cameras and monitors, in the case of an endoscope.LEIBO. / 71e2025

[0029] In the rest of the document, we will take as example a KVM system based on SDVoE technology, belonging to the abovementioned case A.

[0030] The system is based on a plurality of configurable hardware components manually integrated directly on the printed circuit board of the device, each intended to carry out specific functions linked to security. The main components comprise:

[0031] • DIP switches: hardware switches which allow setting binary states on / off to enable or disable specific functions of the device. These components provide a simple and reliable configuration, accessible only by means of physical manipulation;

[0032] • PCB jumpers: removable physical connections designed to enable or disable electrical circuits. These jumpers are usable to selectively managing the power supply of specific modules or the communication on specific channels, such as digital or analog signals;

[0033] • Daughter cards: interchangeable hardware modules, connected by means of dedicated connectors to the main printed circuit board configurable to expand or customize security features, for example for adding new communication protocols or enhancing the protection capacities.

[0034] The present security system (HDSec) includes at least a physical protection mechanism, configured to directly interrupt one or more critical communication channels, selected from among HDMI, USB, UART, Ethernet, audio, optical or others. This ensures that specific signals or functions cannot be manipulated remotely or by means of software, thus protecting the critical functions of the device.

[0035] In an advantageous version, the present security system is provided with at least a programmable logical protection unit, such as a FPGA, a MCU or a SoC whose programming and firmware update, if provided, must be controlled by physical protection measures adapted to prevent unauthorized modifications. We clarify that with the expressions FPGA, MCU, SoC programmable logic devices, microcontrollers and systems on a chip are respectively intended, used for the processing and theLEIBO. / 71e2025

[0036] management of the security functions.

[0037] Said programmable logical protection unit is configured to read and apply operating configurations based on the set hardware states, translating such states into operative rules for the device. The combination of physical and logical protections renders the system high resistance to tampering and computer attacks, simultaneously ensuring flexibility and personalization for various application fields. The security system defined by means of hardware, in a particularly advantageous version, is provided with a physical protection mechanism adapted to ensure that the access to the hardware settings is possible only through controlled physical procedures, minimizing the risk of unauthorized manipulations, and includes a dedicated access interface designed for ensuring a rigorous control of the hardware configurations comprising:

[0038] • an interface access protection mechanism suitable for guaranteeing said access interface by means of a sealed enclosure that reguires the use of specific tools for opening, so as to prevent the accidental or malevolent opening of the hardware settings, providing a solid physical barrier against tampering attempts;

[0039] • at least an active visual or acoustic indicator suitable for signaling that the device is situated in hardware configuration mode during the accesso to the interface; said visual or acoustic indicator can include flashing LEDs, acoustic signals or other signals for indicating the operative status, providing transparency and security during the configuration process.

[0040] This approaches ensures that each modification of the hardware settings is carried out in a secure, traceable and protected manner, by offering a further level of physical and operating security to the electronic device.

[0041] In an advantageous version of the present invention, the security system includes a hardware configuration status verification system, designed for providing an immediate and precise feed-back on the hardware settings of the device. The latterLEIBO. / 71e2025

[0042] in turn integrates visual indicators which allow the operators of easily monitoring the state of the configurable hardware components and of detecting possible errors or operational anomalies, comprising:

[0043] • visual indicators constituted by configurable multi-colored LEDs associated with each configurable hardware component; said visual indicators visually represent the active or inactive state of the component by means of different chromatic configurations which allow a guick identification of the operative state, improving the efficiency and reducing the risk of incorrect interpretations;

[0044] • error signals or operational anomalies by means of flashing or sound seguences which indicate errors of configuration and / or operational anomalies.

[0045] Said hardware configuration status verification system provides a continuous and intuitive monitoring, ensuring that users can guickly diagnose possible problems and confirm the correct application of the hardware configurations. Thus function contributes to improving the security and the overall reliability of the device, rendering it particularly suitable for operating settings that reguire high standards of control and trackability.

[0046] In an advantageous version, said HDSec security system comprises an integrated diagnostic module, which monitors and verifies in real time the hardware configuration status of an electronic device. Said diagnostic module providing advanced diagnostic and report functions, improving the control and management of the security configurations of the system and characterized by:

[0047] • a communication interface which allows the connection to external devices, such as computers or dedicated diagnostic tools by means of standard ports come HDMI, USB, UART, Ethernet, audio, optical or other compatible interfaces, ensuring the compatibility with different operating settings; communication interface adapted to allow reading and verifying, in real time, the hardware configuration status, allowing an immediate and precise diagnosis of theLEIBO. / 71e2025

[0048] settings of the device;

[0049] • the capacity to produce detailed reports that include information on the current state of the configurable hardware components, such as DIP switches, PCB jumpers and daughter cards, storable in a volatile or non-volatile memory, allowing maintenance of a historical record of the configurations.

[0050] The aforesaid diagnostic module provides a continuous monitoring and a decisional support that is essential for the operators, facilitating the maintenance and increasing the reliability of the system. Due to its capacity to be connected to external devices and generate detailed documentation, said diagnostic module adds a further level of control and transparency to the security system hardware.

[0051] The invention includes a method associated with the security system defined by means of hardware, which allows the secure setting and management of hardware configurations by means of well-defined passages. The method ensures that each modification to the configurations is carried out in a controlled, physical and verifiable manner, improving the security of the device against unauthorized access. The method comprises the following steps:

[0052] • physical access to the device, removing possible protections or enclosures which ensure the integrity thereof, thus limiting the possibility or remote or software alterations, reguiring the direct intervention of an authorized operator;

[0053] • setting of the state of the configurable hardware components by an operator who can modify the state of the configurable hardware components through the following actions:

[0054] ■ positioning manually set DIP switches in predefined configurations, representing on / off binary states adapted to enable or disable specific device functions;

[0055] ■ insertion or removal of PCB jumpers used for completing or interrupting specific electrical circuits, controlling the power supply orLEIBO. / 71e2025

[0056] the communication on specific channels;

[0057] ■ installation or removal of daughter cards added or removed to enable or disable advanced or personalized hardware functions;

[0058] • verify the configuration set by means of:

[0059] ■ visual inspection in which the operator can directly observe the physical state of the components, such as the position of the DIP switches or the presence of the jumpers;

[0060] ■ integrated indicators of LED type or other visual signals for confirming the correct configuration of the hardware states.

[0061] • Restoral of the physical protections after having verified and correctly set the configurations, restored in order to prevent unauthorized access.

[0062] This method ensures a secure, transparent and physically controlled management of the hardware configurations, rendering the system suitable for operative contexts that reguire high standards of security and reliability.

[0063] The security method defined by means of hardware makes use of the security system defined by means of described hardware, allowing the physical interruption of one or more communication channels of the electronic device in order to ensure the protection against unauthorized access or remote manipulation. This method allows blocking, in a select and secure manner, specific communication functions by using configurable hardware components, eliminating software or firmware vulnerability. Hereinbelow, the security method defined by means of hardware is characterized by the following actions:

[0064] • selective disconnection of the HDMI channel by means of the use of a DIP switch, physically interrupting the CEC signal on the HDMI connection. This interruption prevents unauthorized bidirectional communications between the connected devices, blocking the transmission of control signals that could represent a security risk.

[0065] • disabling of the USB-HID channel, limiting the communication of the device toLEIBO. / 71e2025

[0066] one-way mode, configurable as host or guest. This physical disabling ensures that unauthorized USB peripheral devices cannot send or receive sensitive data through the device.

[0067] • interruption of the reception and transmission channel by means of configurable hardware components, such as PCB jumpers or DIP switches. This interruption prevents unauthorized firmware updates or the transmission of malevolent serial commands, protecting the device from data manipulations or exfiltration.

[0068] In this manner, the critical communication channels are protected from remote or software manipulations, providing a direct and verifiable physical control of the security configurations.

[0069] The security method defined by means of hardware provides that a programmable logic unit, such as a FPGA or a MCU, acguires and interprets the state of the configurable hardware components and uses them for activating the security configurations of the device. The main operating steps include:

[0070] • Acguisition of the hardware states:

[0071] o the hardware configuration states of hardware components such as DIP switches, PCB jumpers and daughter cards are read by means of a network of digital inputs of the programmable logic unit, which allows detecting the set configuration with precision.

[0072] • T ranslation of the hardware states into operating configurations:

[0073] o the acguired states are converted in operating configurations through predefined corresponding tables, allowing the device to employ specific behaviors based on the hardware settings.

[0074] • Activation or deactivation of the security functions:

[0075] o the programmable logic unit enables or disables device-specific security functions, such as the protection of communication channels or the block of unauthorized access, based on the acguired states.LEIBO. / 71e2025

[0076] • Automated consistency check:

[0077] o the programmable logic unit verifies that the hardware states correspond to a valid and uncompromised security configurations. Possible discrepancies are detected and signaled for preventing unpredicted or risky behaviors.

[0078] In order to ensure the security of the hardware configurations, the security method defined by means of hardware prevents unauthorized modifications by means of the following measures:

[0079] • Protection against the reprogramming of the firmware:

[0080] o the physical disabling of the firmware update ports update is carried out by means of configurable hardware components, preventing any remote attempt of alteration of the firmware.

[0081] • Recording the hardware states in non-volatile memory:

[0082] o the hardware security states are recorded in a non-volatile memory inside the device, ensuring that the configurations remain intact and non-modifiable by means of software commands.

[0083] • Continuous control of the operating configurations:

[0084] o the programmable logic unit continuously monitors the operating configurations of the device, verifying that they correspond with the set hardware states. Any attempt at remote modification is blocked, protecting the system from software or tampering attacks.

[0085] The advantages offered by the present invention are evident in light of the description made up to now and will be even clearer due to the enclosed figures and to the relative detailed description.

[0086] Description of the fiqures

[0087] The invention will be described hereinbelow in at least a preferred embodiment as a non-limiting example, with the aid of the enclosed figures, in which:

[0088] - FIGURE 1 illustrates the structural components of the present security system 1LEIBO. / 71e2025

[0089] and in particular a plurality of DIP switches 2, PCB jumpers 3, daughter card 4, at least a physical protection mechanism 6 and possibly a logical protection unit 5, provided with a physical protection mechanism 5.1 in order to prevent firmware updates.

[0090] - FIGURE 2 is a view of one of the configurations of the security system 1 defined by means of hardware (HDsec) and in particular of the case A.a. mentioned above of an audio-visual system, with KVM distribution system; in particular one observes a SDVoE transceiver comprising at least two switches S1 for mechanically disconnecting the communication UART between CPU and FPGA card, two switches S2 for mechanically disconnecting the communication UART between the CPU and the SDVoE chip. Two switches S3 are then observed, implemented for different functions and two switches S4 for deactivating the CEC (Consumer Electronics Control) channel. Also illustrated is the arrangement of USB HID filter connectors S5, MCU S6 micro-control units, an integrated circuit ASIC S7, a status LED block S10, protected USB channels S11.

[0091] Detailed description of the invention

[0092] The present invention will now be illustrated as merely exemplifying and non-limiting or non-binding, with reference to the figures which illustrate several embodiments relative to the present inventive concept.

[0093] With reference to FIG. 1, the security system is schematically illustrated, defined by means of hardware comprising its main components.

[0094] A practical example of application of the security system 1 defined by means of hardware is represented by its integration in a SDVoE transceiver card. In this context, the security system defined by means of hardware, also definable by means of its acronym HDSec, is used for implementing both physical and logical advanced security configurations, ensuring protection against unauthorized access and remote manipulations. In particular this provides for a plurality of DIP switches 2, PCB jumpers 3 and a daughter card 4, manually configurable devices that are directlyLEIBO. / 71e2025

[0095] integrated on the printed circuit board of the electronic device. The DIP switches 2 are hardware switches adapted to set binary states to enable or disable specific functions, while the PCB jumpers 3 constitute removable physical connections for managing the power supply and the communication on selected channels. The daughter card 4 represents an interchangeable hardware module, connected by means of dedicated connectors and configurable for amplifying or personalizing security features of the system.

[0096] Still in FIG. 1, the distinction between physical protection and logical protection within the HDSec is also illustrated. The first mechanism, the physical protection 6, is configured with DIP switch or with jumper in order to directly interrupt one or more critical communication channels, selected from among HDMI, USB, UART, Ethernet, audio, optical or others. This mechanism ensures a direct hardware protection and prevents the transmission or the unauthorized access to the selected channels. The logical protection unit 5 engages a programmable unit, such as a FPGA, a MCU or a SoC. The latter reads the hardware settings, for example a combination of DIP switches 2, and based on its reading the MCU sets a security configuration. Fig.1 also illustrates the fact that in this case it is necessary to have a physical protection mechanism in order to prevent an attack towards the programming unit, which would consist of modifying its firmware in order to alter the behavior thereof. The second protection mechanism underlined in FIG. 1 regards the logical protection unit 5, based on a programmable logic unit, such as a FPGA, a MCU or a SoC, whose configuration and firmware update determine the behavior of the system. This programmable unit reads the hardware settings, for example a specific combination of DIP switches 2, and conseguently sets a logical security configuration. Such configuration can dynamically adjust the behavior of the channels or implement further security levels. The component 5.1 represents a further physical protection mechanism in order to safeguard the logical protection unit 5. This is essential for preventing attacks that could compromise the firmware of the unit itself and modifyLEIBO. / 71e2025

[0097] the behavior in a non-authorized manner. In FIG. 2, a detailed view is represented of one of the configurations of the security system 1 defined hardware (HDsec), applied to an audio visual system with KVM distribution, and in particular to the case A.a., referred to a transceiver SDVoE. In this configuration, at least two switches S1 are observed for mechanically disconnecting the communication UART between the CPU and the FPGA card, as well as two switches S2 for mechanically disconnecting the communication UART between the CPU and the SDVoE chip, thus preventing the firmware update. Two switches S3, used for different functions, including the setting of the internal routing of the video source, allowing the system to operate as encoder or transceiver and managing the routing of the inputs towards the HDMI output, an LED wall or a SDVoE channel. A further switch, identified as S3, is dedicated to the configuration of the EDID reading mode, selectable between continuous reading, protected pass or default mode. Two switches S4 are also observed, designed for deactivating the channel Consumer Electronics Control (CEC) both on the input and on the output HDMI and for disabling the USB HID. In order to ensure a high level of security in the USB connections, the system comprises the arranging of USB HID filter connectors S5, which allows configuring a one-way connection and preventing the information leakage. The daughter card 4 associated with the filter includes further DIP switches for selecting from among four operating modes: no communication, one-way per host, one-way per device or two-way. The microcontroller unit S6 manages the security logic and the configuration of the system, while the integrated circuit ASIC S7 is dedicated to the management of the SDVoE protocol and to the processing of the video and audio transmissions. Also observed is a HDMI switch S8, designed for protecting and managing the HDMI signals in relation to the aforesaid video routing switches S3. The system includes channels HDMI S9, subject to the protection of S3, and USB channels S11, protecting by the filter USB HID S5. An essential element of the security system is the status LED block S10, which provides a clear visual indication of the current configurationLEIBO. / 71e2025

[0098] DIP switches and signals possible errors of configuration or operational anomalies through flashing seguences. In addition, the system provides for a possible interface for access protected by a physical mechanism, constituted by a sealed enclosure, openable only by means of specific tools such as special keys, security screws or irreversible seals. During the access to such interface, an active visual or acoustic indicator signals that the device is in hardware configuration mode.

[0099] Regarding methodology, the system allows the manual setting of the state of one or more configurable hardware components through a structured process which provides for the physical access to the device for the modification of the configurations, the selection of the states by means of DIP switch, PCB jumpers or daughter cards, and the successive verify the configuration by means of visual inspection or integrated indicators. Once the configuration is carried out, the restoral of the physical protections prevents unauthorized access. In addition, the security method allows the selective interruption of one or more communication channels, including the disconnection of the CEC signal by means of a DIP switch, the disabling of the USB HID channel in order to limit the communication in one-way mode and the blocking of the data transmission in order to prevent unauthorized firmware updates or damaging serial commands.

[0100] Finally, it is clear that modifications, additions or variations that are obvious for a man skilled in the art can be made to the invention described up to now, without departing from the protective scope that is provided by the enclosed claims.

Claims

LEIBO. / 71e2025Claims1. Security system (1) defined by hardware, characterized in that it includes:• a plurality of manually configurable devices integrated on the printed circuit board of the electronic device, selected from:o DIP switches (2), hardware switches that set binary states to enable or disable specific device functions,o PCB jumpers (3), removable physical connections to enable or disable electrical circuits; said PCB jumpers (3) managing power and / or communication on specific channels;o daughter cards such as interchangeable hardware modules connected via dedicated connectors, configurable to expand or customize security features;• at least a physical protection mechanism (6) configured to directly interrupt one or more selected communication channels among HDMI, USB, UART, Ethernet, audio, optical or other.

2. Security system (1) defined by hardware, according to the preceding claim 1, characterized in that it comprises at least a logical protection unit (5) programmable to read and apply configurations based on hardware states eguipped with a physical protection mechanism (5.1) that prevents the firmware from being updated, in order to guarantee the integrity of the system.

3. Security system (1) defined by hardware, according to one of the preceding claims 1 or 2, characterized in that said physical protection mechanism (6) provides a dedicated access interface, comprising:• an interface access protection mechanism, consisting of a sealed enclosure that can be opened using dedicated opening tools such as special keys, security screws or irreversible physical seals;LEIBO. / 71e2025a visual or acoustic indicator active during access to said interface, to indicate that the device is in hardware configuration mode.

4. Security system (1) defined by hardware, according to any of the preceding claims, characterized in that it comprises a hardware configuration status verification system; said hardware configuration status verification system comprising visual indicators consisting of configurable multi-colored LEDs; said visual indicators showing the active or inactive state of each hardware component and / or providing additional signals relating to configuration errors or operational anomalies via flashing seguences.

5. Security system (1) defined by hardware, according to any of the preceding claims, characterized in that it comprises an integrated diagnostic module, capable of:• connect to an external device via a diagnostic port to read and verify the status of hardware configurations in real time;• generate detailed reports of current hardware configurations, storing them in volatile and / or non-volatile memory.

6. Security system (1) defined by hardware, according to one of the preceding claims, comprising at least a switch (S1) for mechanically disconnecting the reception and transmission communication between the CPU and a peripheral card.

7. Security system (1) defined by hardware, according to one of the preceding claims, comprising at least two switches (S2) for mechanically disconnecting the reception and transmission communication between the CPU and another component, also blocking the firmware update.

8. Security system (1) defined by hardware, according to one of the preceding claims, comprising at least a switch (S3) for setting the internal routing of the video source, configuring the system to function as an encoder or transceiver, and for managing the routing of the inputs to the outputs of the card.LEIBO. / 71e20259. Security system (1) defined by hardware, according to one of the preceding claims, comprising at least a switch (S4) for deactivating the CEC (Consumer Electronics Control) channel on an HDMI input and output and for deactivating the USB HID.

10. Security system (1) defined by hardware, according to one of the preceding claims, alternatively or overall comprising:• USB HID filter connectors (S5) prepared for jumpers or for daughter card of said USB HID filter allowing to set a one-way USB HID connection preventing information leakage,• MCU (S6) micro-control unit responsible for managing the security logic and system configuration,• ASIC integrated circuit (S7) dedicated to managing the SDVoE protocol and processing video / audio transmissions.• status LED block (S10) used to signal the current configuration of said DIP switches to the outside;• protected USB channels (S11) subject to the protection of the USB HID filter (S5).

11. Security system (1) defined by hardware, according to one of the preceding claims, comprising at least a HDMI switch (S8) dedicated to the protection and management of HDMI signals, in relation to said video routing switches (S3).

12. Security system (1) defined by hardware, according to one of the preceding claims, comprising:• EDID configuration switch (S3) to set the EDID reading mode, selectable between continuous reading, protected pass or default mode,• protected HDMI channels (S9) subject to the protection of said EDID configuration switches (S3).LEIBO. / 71e202513. Security system (1) defined by hardware, according to one of the preceding claims, wherein said printed circuit includes two DIP switches for setting the following communication modes:- no communication,- one-way for host,- one-way for device,- two-way.

14. Security method defined by hardware, capable of exploiting the hardware- defined security system (1) of the preceding claims from 1 to 13, characterized in that it allows the setting of the state of one or more configurable hardware components, comprising the following steps:• physical access to the electronic device to allow modification of hardware configurations;• setting the state of configurable hardware components via:o positioning of DIP switches (2) in predefined configurations;o insertion or removal of PCB jumpers (3) to complete or interrupt specific circuits;o installation or removal of daughter cards to enable or disable hardware features;• verify the configuration set by visual inspection or the use of integrated indicators;• restore physical protections to prevent unauthorized access.

15. Security method defined by hardware, according to the preceding claim 14, characterized in that it allows the physical interruption of one or more communication channels via:• selective disconnection of the HDMI channel, including interruption of the CEC signal via a DIP switch (2) to prevent unauthorized bidirectional communications;LEIBO. / 71e2025• disabling the USB-HID channel by interrupting the physical path to limit communication to one-way host or guest mode;• interrupting the receive and transmit channel to prevent unauthorized firmware updates and / or sending serial commands through the device.

16. Security method defined by hardware according to the preceding claim 14, characterized in that it allows the reading and application of the hardware state by a programmable logic unit providing:• the acguisition of the states of configurable hardware components, selected from DIP switches (2), PCB jumpers (3) and daughter cards, via a network of digital inputs of the programmable logic unit;• the translation of the acguired hardware states into operational configurations for the device;• the activation or deactivation of device-specific security functions based on the acguired states;• an automated consistency check, performed by the programmable logic unit, to verify that the acguired states correspond to valid and uncompromised security configurations.

17. Security method defined by hardware according to claim 14, characterized in that it prevents remote or software changes to security configurations via:• protection against reprogramming of the firmware of the programmable logical protection unit (5):o physically disabling the firmware update ports using hardware components;• the configuration of a non-volatile memory inside the device, in which the security hardware states are recorded and made unchangeable by software commands;• a continuous check by the programmable logical protection unit (5) to verify that the operating configurations of the device correspond to theLEIBO. / 71e2025configured hardware states, and to block any attempt at modification via remote channels.