Bus Controller Authentication for PCI Endpoint Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing number of endpoint devices connected to computing devices has heightened security threats, as malicious parties can gain control of internal buses and issue unauthorized commands, posing risks to critical systems like government and financial networks.
Innovation Solution
A bus management system that employs a challenge-response authentication mechanism between a bus controller and endpoint devices, using a predefined hashing algorithm and encryption keys to authenticate and authorize commands, ensuring only authorized controllers can manage the internal bus.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the number of endpoint devices connected to computing devices increases, then the functionality and control capabilities of the computing device are improved, but the security threats and risk of unauthorized access increase
Solution Approach 1:
The patent implements preliminary authentication actions before allowing endpoint devices to access the internal bus. The BMC performs challenge-response authentication with endpoint devices before granting bus access, preventing unauthorized devices from connecting to the internal bus in the first place
Solution Approach 2:
The BMC acts as an intermediary between the internal bus and endpoint devices. It mediates all communications by authenticating devices before allowing them to send or receive messages, and by filtering and monitoring all traffic passing through the bus to prevent unauthorized commands
2Reliability
If authentication mechanisms are implemented on the internal bus, then security against unauthorized commands is improved, but the complexity of the bus management system increases
Solution Approach 1:
The authentication mechanism is self-service in that the BMC automatically performs challenge-response authentication with endpoint devices without requiring manual intervention. The system self-manages security credentials and automatically filters unauthorized commands, reducing operational complexity despite the added security layer
3Reliability
If the BMC monitors and authenticates all commands on the internal bus, then unauthorized access is prevented, but the processing overhead and communication delay increase
Solution Approach 1:
Authentication is performed in advance before endpoint devices are allowed to communicate over the internal bus. Once authenticated, devices receive authorization tokens that allow them to send commands without requiring continuous authentication, reducing real-time processing overhead
Solution Approach 2:
The BMC implements feedback mechanisms where authenticated endpoint devices receive confirmation of their authorized status. The system continuously monitors bus traffic and provides feedback by blocking unauthorized commands while allowing authenticated commands to pass through with minimal delay
Data Source
AI summary
A computing device includes a bus controller and an endpoint device that are in communication over an internal bus. The bus controller initiates a discovery message to the endpoint device requesting a computational value based on the discovery message, wherein the computational value is generated by the endpoint device using a predefined algorithm and the discovery message includes a preconfigured identification code associated with the bus controller. The bus controller receives a response from the endpoint device, which includes the computational value, when the endpoint device authenticates the controller based on the preconfigured identification code. If the bus controller successfully authenticates the endpoint device based on the computational value, the controller sends an acknowledgment message to the endpoint device and registers it as being owned by the bus controller. Otherwise, the bus controller sends a failure message to the endpoint device and logs it as being unmanageable by the controller.


