Connection Protector Device for Secure External Interface

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for securing communication between external devices and host computers are inadequate, as they fail to prevent eavesdropping and do not ensure authentication, particularly for devices like keyboards and printers, which can be compromised by hardware bugs or modified to include keyloggers, leading to potential data breaches.

Innovation Solution

A method and system that utilize a Connection Protector Device (CPD) to monitor and secure the connection between external devices and host computers, employing encryption, authentication, and mechanical securing mechanisms to prevent disconnection and ensure data integrity, with the CPD being either external or integrated into the device, and utilizing a security server for policy management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a software program generates a virtual keyboard for password entry, then password security is improved, but the solution cannot be used for the entire user activity and is limited to certain time periods

Engineering Contradiction:
Improvepassword securityVSAvoidusage scope
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The security solution is divided into two distinct modes: a virtual keyboard mode for secure password entry and a transparent mode for normal operation. The system segments the protection scope into specific high-risk operations (password entry) and general operations, allowing each to be handled by the most appropriate mechanism without limiting overall versatility.

Inventive Principle:
Principle #1Segmentation

2Use of energy by moving object

If a hardware cipher device is activated only during password entry periods, then security resource usage is optimized, but the device cannot protect during the entire user activity

Engineering Contradiction:
Improvesecurity resource usageVSAvoidprotection coverage
Core Design Contradiction:
Use of energy by moving objectVSAdaptability or versatility

Solution Approach 1:

The security system dynamically switches between two operational states: an active encryption state during sensitive operations and a transparent pass-through state during normal operations. This dynamic adaptation allows the system to provide maximum security when needed while minimizing resource consumption during routine tasks, achieving both efficiency and comprehensive coverage.

Inventive Principle:
Principle #15Dynamics

3Reliability

If the connector of the external device is glued to its socket, then the connection security is improved, but the device cannot be easily replaced or transported

Engineering Contradiction:
Improveconnection securityVSAvoiddevice replaceability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

A mechanical securing mechanism is introduced as an intermediary component between the connector and socket that provides strong physical attachment during operation but allows for controlled release when needed. This intermediary element achieves both secure connection and easy replaceability without requiring permanent bonding.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If a mechanical securing mechanism is used to secure the connector, then connection integrity is improved, but the device complexity increases

Engineering Contradiction:
Improveconnection integrityVSAvoidmechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The mechanical securing mechanism uses simple geometric interlocking features and elastic retention forces rather than complex locking systems. The design replaces complicated multi-component locking mechanisms with a streamlined approach that achieves equivalent security through optimized mechanical geometry, thereby minimizing added complexity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS8954624B2Method and system for securing input from an external device to a host
Publication Date: 2015.02.10 SUPERCOM IP LLC
  • US8954624B2 patent drawing
  • US8954624B2 patent drawing
  • US8954624B2 patent drawing

AI summary

The pureness of a connection between an external device and a host computer can be inspected or monitored to determine the status: connected or disconnected. When it is determined that a disconnection state is entered, an indication can be sent to the host and, in parallel, the data transportation from and/or to the external device may be manipulated. In some embodiments an exemplary connection protector device (CPD) may be added to the connection in between the external device and the host. The CPD can have two connectors one for the host and one for the cable of the external device. The CPD can be adapted to identify any disconnection in the connection with the host and/or the connection with the external device on the other side of the CPD.