Hardware Access Control Device for Universal Ports

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computer systems are vulnerable to security breaches through universal ports like USB, which allow malicious peripherals to connect and compromise system integrity, and existing software solutions are complex and circumventable.

Innovation Solution

A device with multifunction ports and access management means that physically authorize access only to specifically and permanently associated peripherals, using programmable circuits and identification modules to ensure secure connection and data verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If universal ports are used to allow connection of various peripherals, then flexibility and functionality are improved, but security vulnerability increases

Engineering Contradiction:
ImproveflexibilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

An access control device is introduced as an intermediary between the universal port and the computer system. This device includes a port for connecting peripherals and another port for connecting to the computer system, with access management means that physically authorize access based on peripheral identification. The intermediary filters and controls data flow, allowing legitimate peripherals to communicate while blocking malicious ones, thus resolving the contradiction between universal connectivity and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If software solutions are used to manage peripheral access, then access control functionality is provided, but system complexity increases and security can be circumvented

Engineering Contradiction:
Improveaccess control functionalityVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent replaces software-based access control with a hardware-based solution. The access management means are physically configured in the access control device to authorize access based on peripheral identification. This hardware implementation eliminates the vulnerabilities of software solutions (which can be compromised through OS vulnerabilities or administrative exploits) while providing more reliable and tamper-resistant access control, thus reducing overall system security complexity despite adding hardware components.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If access control device is introduced to secure the system, then security level is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity levelVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The access control device is designed as a segmented architecture with distinct functional modules: identification module for recognizing peripherals, access management means for authorization decisions, and verification module for data validation. This segmentation allows each module to perform its specific function efficiently while maintaining overall system manageability. The modular design reduces the complexity burden by organizing functions into separate, well-defined components rather than a monolithic complex system.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP2659419B1Method and device for controlling access to a computer system
Publication Date: 2017.03.15 ELECTRICITE DE FRANCE
  • EP2659419B1 patent drawing
  • EP2659419B1 patent drawing
  • EP2659419B1 patent drawing

AI summary

The present invention relates to a device for controlling access to a computer system, the device including at least one multifunctional port (Uj) capable of being connected to various categories of peripherals and an access interface (INT) capable of being connected to the computer system, the device being characterized in that same includes access management means (Macc) connected between the multifunctional port (Uj) and the interface (INT), the access management means being physically configured to authorize the interface access by means of a peripheral (P) connected to the multifunctional port (Uj), only if said peripheral belongs to a category of peripherals specifically and permanently associated with the multifunctional port (Uj) to which same is connected. The present invention likewise relates to the corresponding access control method.