KVM Matrix Security Isolators for Data Leakage Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing KVM Matrix systems face significant security vulnerabilities, allowing data leakage between connected computers and users, particularly between high-security and low-security networks, which poses a severe risk of unauthorized data access and compromise.

Innovation Solution

The implementation of input and output security isolators within the KVM Matrix system, combined with Bit-Rate Limited audio channels, to prevent unauthorized data transfer and enhance security by isolating user and administrator permissions, mitigating risks of data leakage and user spoofing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If KVM Matrix systems allow dynamic switching of computer resources to users, then productivity and resource utilization are improved, but security vulnerabilities and data leakage risks increase

Engineering Contradiction:
Improveresource utilizationVSAvoiddata leakage risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the data transmission path by inserting security isolators at both the input and output sides of the KVM matrix. These isolators create separate security domains that prevent direct data flow between users and computers, thereby segmenting the system into isolated security zones that maintain productivity while blocking data leakage pathways.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces security isolators as intermediary devices between users and computers in the KVM matrix system. These isolators act as mediators that allow controlled interaction while preventing unauthorized data transfer, thus maintaining resource utilization benefits while eliminating security vulnerabilities through the intermediary security layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If KVM Matrix systems co-locate computer resources to enable scalable deployment, then device complexity and deployment ease are improved, but security isolation between high-security and low-security networks deteriorates

Engineering Contradiction:
Improvedeployment complexityVSAvoidsecurity isolation
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent applies segmentation by dividing the co-located computer system into isolated security domains using security isolators. Each computer connected to the KVM matrix is separated by isolators that enforce security boundaries, allowing scalable deployment of computers while maintaining strict security isolation between high-security and low-security networks despite physical co-location.

Inventive Principle:
Principle #1Segmentation

3Speed

If KVM Matrix systems use digital signal switching with high-speed cables, then transmission speed and bandwidth are improved, but susceptibility to data interception and spoofing increases

Engineering Contradiction:
Improvesignal transmission speedVSAvoiddata interception risk
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent introduces security isolators as intermediary devices in the digital signal transmission path of the KVM matrix system. These isolators maintain the high-speed digital signal transmission capability while preventing data interception and spoofing attacks by blocking unauthorized access to the digital signal pathway between users and computers.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3586235B1Method and apparatus for securing KVM matrix
Publication Date: 2025.10.22 HIGH SEC LABS LTD
  • EP3586235B1 patent drawingFigure 1
  • EP3586235B1 patent drawingFigure 2
  • EP3586235B1 patent drawingFigure 3

AI summary

A method for securing a KVM Matrix system by inserting a plurality of input security isolators, each of the input security isolators is placed between a host computer and matrix host adapter of the KVM matrix system to enforce security data flow policy that is applicable for the corresponding host computer. Additionally, a security isolator is placed between peripheral devices and a matrix console adapter to enforce security data flow policy that is applicable for the corresponding peripheral devices.