HID Switch with Unidirectional Data Flow for Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing human interface device (HID) switches, such as KVM switches, do not adequately protect against information leakage between connected computers, which is a concern for secure applications like banking transactions.
Innovation Solution
A HID switch with physically isolated pathways and unidirectional data flow circuits ensures that data from one host computer cannot be accessed by another, using separate coupling modules and physical switches to enforce one-way data transmission, preventing information leakage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a KVM switch allows simultaneous viewing and access of multiple computers, then user convenience and information acquisition speed are improved, but information security and isolation between computers deteriorate
Solution Approach 1:
The patent divides the data transmission path into separate isolated pathways for each computer connection. Each computer has its own dedicated coupling module and data transmission path, preventing data from one computer from mixing with or being accessed by other computers, thus maintaining security while enabling multi-computer access
Solution Approach 2:
The patent introduces a controller as an intermediary that manages data flow between computers and peripheral devices. The controller receives data from one computer at a time through isolated pathways and forwards it to peripheral devices, ensuring that only authorized data transmission occurs while maintaining physical isolation between computer connections
2Reliability
If data transmission pathways are physically isolated and unidirectional, then information security is improved, but device complexity increases
Solution Approach 1:
The patent segments the data transmission system into distinct isolated pathways with dedicated coupling modules for each computer. This segmentation creates clear physical boundaries that enforce security requirements while organizing complexity into manageable, standardized units that can be systematically implemented
Solution Approach 2:
The patent replaces complex electronic data routing mechanisms with a simpler physical isolation approach using separate transmission pathways and unidirectional data flow. This mechanical/physical separation method achieves security goals more straightforwardly than attempting to manage security through complex electronic control systems
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Present disclosure is a HID switch connected to at least one user input peripheral device and at least two host computers. The HID switch incudes two peripheral emulators each stored with one addressing data. A controller being connected to the user input peripheral device receives peripheral data and generates unidirectional serial output signals accordingly. Two addressing logic data latches receive the unidirectional serial output signals broadcasted from the controller. An encryption unit provides the controller with an encryption command including one of the addressing data for the controller to encrypt the unidirectional serial output signals. Two unidirectional enforcing circuits enforce data flow only from the data latches to the peripheral emulators. When the peripheral emulators receives the unidirectional serial output signals from the controller, the peripheral emulator decrypts the unidirectional serial output signals according to the addressing data and sends the unidirectional serial output signal to the host computer.