Bus Security Device Disrupting Unauthorized Peripheral Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing electronic systems lack effective methods to secure access to peripheral devices over bus interfaces, particularly against unauthorized transactions, which can compromise sensitive data and system security.

Innovation Solution

A security device with a processor and interface is connected to the bus, capable of disrupting unauthorized transactions by forcing dummy values on dedicated or shared signals, thereby overriding unauthorized access and ensuring secure communication between host and peripheral devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a security device is added to the bus to secure access to peripheral devices, then system security is improved, but device complexity increases

Engineering Contradiction:
Improvesystem securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security device functions as an intermediary component inserted between the bus master and peripheral devices on the I2C bus. It monitors bus transactions and selectively disrupts unauthorized access attempts by forcing dummy values on dedicated signals (such as chip select lines) without requiring changes to the existing bus architecture or additional pins.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security device autonomously monitors bus transactions and independently determines whether to allow or disrupt access based on pre-configured security policies. It self-manages the disruption process by directly manipulating bus signals without requiring external intervention or complex system-wide coordination.

Inventive Principle:
Principle #25Self-service

2Reliability

If the security device disrupts transactions by forcing dummy values on bus signals, then unauthorized access is prevented, but transaction speed may be affected

Engineering Contradiction:
Improveaccess securityVSAvoidtransaction speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The security device rapidly forces dummy values onto bus signals during unauthorized transactions, effectively skipping or aborting the illegitimate access attempt before it can complete. This rapid disruption minimizes the time penalty imposed on legitimate transactions while quickly eliminating security threats.

Inventive Principle:
Principle #21Skipping (Rushing through)

Solution Approach 2:

The security device takes preliminary action by monitoring bus transactions in real-time and preemptively disrupting unauthorized access attempts before they can successfully access protected peripheral devices. This prevents harmful actions from completing while allowing legitimate transactions to proceed uninterrupted.

Inventive Principle:
Principle #9Preliminary anti-action

3Reliability

If the security device monitors bus transactions in real-time, then unauthorized access is detected promptly, but energy consumption increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The security device employs periodic monitoring of bus transactions rather than continuous full-spectrum analysis. It selectively activates monitoring and disruption functions based on detected transaction patterns, energy-efficient sleep modes, or predefined triggers, reducing overall power consumption while maintaining effective security detection.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS10452582B2Secure access to peripheral devices over a bus
Publication Date: 2019.10.22 NUVOTON
  • US10452582B2 patent drawing
  • US10452582B2 patent drawing
  • US10452582B2 patent drawing

AI summary

A security device includes an interface and a processor. The interface is configured for connecting to a bus that serves one or more peripheral devices. The bus includes (i) one or more dedicated signals that are each dedicated to a respective one of the peripheral devices, and (ii) one or more shared signals that are shared among the peripheral devices served by the bus. The processor is connected to the bus as an additional device in addition to the peripheral devices, and is configured to disrupt on the bus a transaction in which a bus-master device attempts to access a given peripheral device, by disrupting a dedicated signal associated with the given peripheral device.