HID Switch with Unidirectional Data Flow for Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing human interface device (HID) switches, such as KVM switches, do not adequately protect against information leakage between connected computers, which is a concern for secure applications like banking transactions.

Innovation Solution

A HID switch with physically isolated pathways and unidirectional data flow circuits ensures that data from one host computer cannot be accessed by another, using separate coupling modules and physical switches to enforce one-way data transmission, preventing information leakage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a KVM switch allows simultaneous viewing and access of multiple computers, then user convenience and information acquisition speed are improved, but information security and isolation between computers deteriorate

Engineering Contradiction:
Improveuser convenienceVSAvoidinformation security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent divides the data transmission path into separate isolated pathways for each computer connection. Each computer has its own dedicated coupling module and data transmission path, preventing data from one computer from mixing with or being accessed by other computers, thus maintaining security while enabling multi-computer access

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a controller as an intermediary that manages data flow between computers and peripheral devices. The controller receives data from one computer at a time through isolated pathways and forwards it to peripheral devices, ensuring that only authorized data transmission occurs while maintaining physical isolation between computer connections

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If data transmission pathways are physically isolated and unidirectional, then information security is improved, but device complexity increases

Engineering Contradiction:
Improveinformation securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the data transmission system into distinct isolated pathways with dedicated coupling modules for each computer. This segmentation creates clear physical boundaries that enforce security requirements while organizing complexity into manageable, standardized units that can be systematically implemented

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent replaces complex electronic data routing mechanisms with a simpler physical isolation approach using separate transmission pathways and unidirectional data flow. This mechanical/physical separation method achieves security goals more straightforwardly than attempting to manage security through complex electronic control systems

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentEP3564795B1Human interface device switch with security function
Publication Date: 2021.07.07 I O INTERCONNECT LTD
  • EP3564795B1 patent drawingFigure 1
  • EP3564795B1 patent drawingFigure 2
  • EP3564795B1 patent drawingFigure 3

AI summary

Present disclosure is a HID switch connected to at least one user input peripheral device and at least two host computers. The HID switch incudes two peripheral emulators each stored with one addressing data. A controller being connected to the user input peripheral device receives peripheral data and generates unidirectional serial output signals accordingly. Two addressing logic data latches receive the unidirectional serial output signals broadcasted from the controller. An encryption unit provides the controller with an encryption command including one of the addressing data for the controller to encrypt the unidirectional serial output signals. Two unidirectional enforcing circuits enforce data flow only from the data latches to the peripheral emulators. When the peripheral emulators receives the unidirectional serial output signals from the controller, the peripheral emulator decrypts the unidirectional serial output signals according to the addressing data and sends the unidirectional serial output signal to the host computer.