Peripheral Hardware Security Control for Terminal Privacy Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing pure-software protection solutions for terminal peripherals are vulnerable to deception and bypass by third-party apps, leading to unauthorized access and leakage of personal privacy information, with complex authentication manners complicating implementation.

Innovation Solution

A hardware-based peripheral system with a hardware security unit controlling communication, power, and startup statuses of peripherals, using protection switches and power supplies to prevent unauthorized access and invocation by third-party apps.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If pure-software protection solution is used, then implementation is easier, but security level is low and susceptible to being deceived and bypassed by third-party apps

Engineering Contradiction:
ImproveEase of implementationVSAvoidSecurity level
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent replaces the software-based authentication system with a hardware-based authentication system. The hardware security unit is integrated into the processor core and uses hardware-level authentication mechanisms to control access to peripherals, making it impossible for third-party apps to bypass through software vulnerabilities. This substitution of software with hardware directly resolves the contradiction by maintaining ease of implementation while dramatically improving security reliability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If hardware security unit is introduced, then security level is improved, but device complexity increases

Engineering Contradiction:
ImproveSecurity levelVSAvoidSystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The hardware security unit is merged with the processor core in a tightly integrated design. Rather than being a separate external component, the security unit shares the same physical substrate and communication interfaces with the processor, reducing the number of external connections and simplifying the overall system architecture. This merging approach improves security while minimizing the increase in device complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The hardware security unit is designed to provide multiple security functions including authentication, authorization, and access control for various peripherals through a single unified interface. This multi-functional design reduces the need for multiple separate security components, thereby improving security capabilities without proportionally increasing device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If frequent interaction between security software and peripheral driver is required, then authentication is achieved, but authentication manner becomes complex and difficult to implement

Engineering Contradiction:
ImproveAuthentication capabilityVSAvoidAuthentication complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication logic from the complex interaction between security software and peripheral drivers, and consolidates it into a dedicated hardware security unit. This unit handles all authentication operations independently at the hardware level, eliminating the need for frequent software-driver interactions and significantly simplifying the authentication manner while maintaining strong authentication capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20260023694A1Terminal and peripheral system thereof
Publication Date: 2026.01.22 HUAWEI TECH CO LTD
  • US20260023694A1 patent drawing
  • US20260023694A1 patent drawing
  • US20260023694A1 patent drawing

AI summary

This application provides a terminal and a peripheral system thereof. The peripheral system includes an input module, a processing module, and a plurality of peripheral modules. The input module is connected to the processing module. The input module is configured to receive input information and transmit the input information to the processing module. The processing module is connected to the plurality of peripheral modules. The processing module includes a hardware security unit. The hardware security unit is configured to: receive the input information and output a control signal corresponding to the input information to a part or all of the peripheral modules, to control communication statuses, power supply statuses, and/or startup statuses of the part or all of the peripheral modules.