KVM Appliance Intercepts Status Data to Prevent Leakage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Secure peripheral sharing switch systems, such as KVM systems, face challenges in preventing data leakage of status information from one target computer to another when a peripheral is shared across computers with different security levels, which is undesirable, especially in sensitive applications like governmental and military settings.
Innovation Solution
A KVM appliance with a main processing unit and status indicators that intercepts specific status information intended for peripherals, using it to set indicators on the appliance instead of passing it to the peripherals, thereby preventing data leakage while still informing the user of the peripheral's status.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If status information is passed to the peripheral to maintain user awareness, then user convenience is improved, but data leakage risk increases
Solution Approach 1:
The KVM appliance acts as an intermediary between the target computer and the peripheral. It intercepts status information intended for the peripheral, processes it through its processor, and either blocks it or provides an alternative notification mechanism. This mediator approach allows the system to maintain user awareness through the appliance's indicator while preventing sensitive status information from being passed to the peripheral, thereby resolving the contradiction between user convenience and data leakage prevention.
2Reliability
If status information is blocked from the peripheral to prevent data leakage, then security is improved, but user awareness of peripheral status deteriorates
Solution Approach 1:
The KVM appliance serves as a mediator that receives status information from the target computer, processes it through its processor to determine if it should be blocked, and simultaneously provides alternative notification to the user through its indicator. This ensures security by blocking sensitive information from the peripheral while maintaining user awareness through the appliance's own indication mechanism, thus resolving the contradiction between security and information loss.
Solution Approach 2:
The KVM appliance creates a copy of the status information notification function. Instead of allowing the original status information to reach the peripheral, the appliance's processor intercepts it and generates an alternative notification through its indicator. This copying approach preserves the essential function of informing the user about peripheral status while preventing the actual sensitive data from being transmitted to the peripheral, thereby resolving the contradiction between security and user awareness.
Data Source
AI summary
The present disclosure relates to a KVM appliance for preventing the passing of status information between a target computer, which is in communication with the KVM appliance, and a peripheral of a user. The KVM appliance may comprise a housing, an indicator supported on the housing, and a main processing unit (MPU) for receiving status information. The MPU monitors status information received by it and determines when the received status information is of a specific type which is used to set the indicator, which in turn apprises the user of a real time status of a feature of the peripheral. When the status information is identified as being of the type to set the indicator, it is then used to set the indicator to indicate the real time status of the feature to the user of the peripheral.


