Peripheral Device Quarantine and User Verification Mechanism

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Protected systems face threats from unintended or unauthorized peripheral device connectivity, particularly through USB devices, which can be modified or infected with malware, leading to physical and cyberattacks that are difficult to detect and prevent.

Innovation Solution

Implementing a method that quarantines peripheral devices upon connection and requires an authorized human response to verify their legitimacy before allowing access to the host system, using a processor to detect connection attempts, present authorization challenges, and grant access only if the response is correct.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If peripheral devices are allowed to connect to the host system without verification, then device connectivity and operational flexibility are improved, but security and protection against malicious devices deteriorate

Engineering Contradiction:
Improvedevice connectivityVSAvoidmalware infection and cyberattacks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary verification of peripheral devices before allowing them to connect to the host system. The processor detects connection attempts, quarantines the device, and presents authorization challenges to verify legitimacy before granting access, thereby preventing malware-infected devices from entering the protected environment.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system introduces an intermediary verification layer between the peripheral device and the host system. This intermediary mechanism includes the processor that detects connection attempts, the quarantine function that isolates unknown devices, and the authorization challenge presentation that mediates the connection decision, requiring explicit user approval before allowing device access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If authorization verification is required for all peripheral devices, then security against unauthorized devices is improved, but operational complexity and user burden increase

Engineering Contradiction:
Improveunauthorized device accessVSAvoidverification process complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The system performs preliminary verification of peripheral devices before allowing them to connect to the host system. The processor detects connection attempts, quarantines the device, and presents authorization challenges to verify legitimacy before granting access, thereby preventing malware-infected devices from entering the protected environment.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system introduces an intermediary verification layer between the peripheral device and the host system. This intermediary mechanism includes the processor that detects connection attempts, the quarantine function that isolates unknown devices, and the authorization challenge presentation that mediates the connection decision, requiring explicit user approval before allowing device access.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If automatic device recognition and access is implemented, then ease of operation is improved, but vulnerability to spoofing and device manipulation increases

Engineering Contradiction:
Improvedevice connection easeVSAvoiddevice spoofing and parameter alteration
Core Design Contradiction:
Ease of operationVSObject-generated harmful factors

Solution Approach 1:

The system performs preliminary verification of peripheral devices before allowing them to connect to the host system. The processor detects connection attempts, quarantines the device, and presents authorization challenges to verify legitimacy before granting access, thereby preventing malware-infected devices from entering the protected environment.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where the processor continuously monitors device behavior and presentation after connection. Authorization challenges are presented to verify device identity, and the system provides feedback to users about device status, requiring explicit confirmation before allowing full access, thus detecting and preventing spoofing attempts.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11301548B2Apparatus and method for preventing unintended or unauthorized peripheral device connectivity by requiring authorized human response
Publication Date: 2022.04.12 OSR OPEN SYST RESOURCES
  • US11301548B2 patent drawing
  • US11301548B2 patent drawing
  • US11301548B2 patent drawing

AI summary

A method includes detecting a connection attempt from a device, quarantining the device to prevent the device from substantially interacting with a host system, and determining whether the device requires verification while the device is quarantined. The method also includes, in response to determining that the device requires verification, presenting at least one authorization challenge to a user while the device is quarantined. The at least one authorization challenge requests that the user provide at least one specified response. The method further includes, in response to determining that the device requires verification, determining whether the user correctly provided the at least one specified response while the device is quarantined, granting access to the device in response to determining that the user correctly provided the at least one specified response, and continuing to quarantine the device in response to determining that the user did not correctly provide the at least one specified response.