Host-Based Peripheral Authorization via Hardware Decoupling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The introduction of malicious software via personal portable peripherals poses a significant vulnerability to user equipment and networks, as these devices can download malware and introduce it to company networks when connected to company devices, compromising security.

Innovation Solution

An authorization component is integrated into user equipment hardware, which receives authorization data from a central system via wireless communication, stores it, and only allows peripherals to access the equipment after successful authentication, ensuring only authorized devices can connect and preventing malicious software from accessing the system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If personal portable peripherals are allowed to connect to company devices, then employees can use personal devices for work purposes, but malicious software on these peripherals can introduce security vulnerabilities to the company network

Engineering Contradiction:
Improveperipheral device compatibilityVSAvoidmalicious software introduction
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

An authorization component is introduced as an intermediary between the hardware interface and system components. This component receives and validates authorization credentials from peripheral devices before allowing access to system resources, thereby mediating between personal peripherals and company network security

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary authorization validation before allowing peripheral devices to access company equipment. The authorization component checks credentials in advance, preventing malicious software from being introduced to the network

Inventive Principle:
Principle #10Preliminary action

2Reliability

If authorization validation is implemented for all peripheral connections, then network security is improved, but the complexity of the system increases due to additional authorization components and validation processes

Engineering Contradiction:
Improvenetwork securityVSAvoidauthorization system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authorization validation functionality is extracted as a separate, dedicated authorization component that operates independently from the main system. This modular approach manages complexity by isolating security functions while maintaining reliable network protection

Inventive Principle:
Principle #2Taking out (Extraction)

3Object-affected harmful factors

If unauthorized peripherals are blocked from accessing the system, then malicious software is prevented from entering the network, but legitimate personal peripherals may also be denied access reducing employee productivity

Engineering Contradiction:
Improvemalicious software preventionVSAvoidemployee workflow efficiency
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The authorization component provides feedback mechanisms to users about connection status. When a peripheral is connected, the system validates credentials and communicates authorization status, allowing employees to understand why certain devices are blocked or permitted, thereby maintaining productivity through transparent security enforcement

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11663313B2Host-based hardware peripheral authorization system
Publication Date: 2023.05.30 T MOBILE US INC
  • US11663313B2 patent drawing
  • US11663313B2 patent drawing
  • US11663313B2 patent drawing

AI summary

Systems and methods for authenticating a peripheral device prior to allowing the peripheral device access to components and data stored on user equipment. In some examples, the user equipment may include an authorization component that is configured to physically decouple a hardware interface from other components of the user equipment until the authorization component is able to authenticate the peripheral device. Both authorized peripheral devices and the user equipment may be provisioned with authorization data and/or credentials from a system outside the control of the individual users of the user equipment.