Peripheral Sharing Device Secure Clipboard Transfer
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies do not provide secure inter-host copy-paste operations between host computers that share peripheral devices through a peripheral sharing device, while maintaining isolation and security to prevent cyber-security attacks.
Innovation Solution
A peripheral sharing device equipped with copy-emulators, paste-emulators, and a security bridge that securely passes clipboard objects between hosts, enforcing unidirectional data transfer, monitoring clipboard objects, and applying security policies to ensure secure copy-paste operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a peripheral sharing device is used to share devices between multiple hosts, then device sharing capability is improved, but security isolation between hosts deteriorates
Solution Approach 1:
The system segments the data transfer path by introducing separate copy-emulators and paste-emulators for each host, with a security bridge that enforces unidirectional data flow. This segmentation allows device sharing while maintaining security isolation through controlled data paths.
Solution Approach 2:
The security bridge acts as an intermediary component between hosts, mediating all clipboard data transfers. It enforces security policies, monitors traffic, and controls data flow direction, enabling both device sharing and security isolation simultaneously.
2Reliability
If security isolation is enforced between hosts, then security is improved, but inter-host communication capability deteriorates
Solution Approach 1:
The security bridge serves as a mediator that enables controlled inter-host communication while maintaining security isolation. It implements security policies that allow legitimate clipboard operations between hosts while blocking malicious activities.
Solution Approach 2:
The peripheral sharing device is enhanced with multiple functions including copy-emulators, paste-emulators, security bridge, and monitoring capabilities. This multi-functionality allows the device to simultaneously provide security isolation and enable controlled inter-host communication.
3Reliability
If monitoring and security policies are implemented for clipboard operations, then security is improved, but system complexity deteriorates
Solution Approach 1:
The system merges multiple security functions (copy-emulation, paste-emulation, security bridging, monitoring, and policy enforcement) into a single integrated peripheral sharing device. This consolidation improves security while managing complexity through unified architecture.
4Reliability
If unidirectional data transfer is enforced, then data security is improved, but bidirectional communication capability deteriorates
Solution Approach 1:
The system implements dynamic data flow control where the direction of data transfer is determined by security policies and operational context. The security bridge can enable or disable bidirectional communication based on real-time security requirements, balancing security and communication needs.
Data Source
AI summary
A peripheral sharing device for supporting secure copy-paste operations between hosts comprising: a plurality of copy-emulators and a plurality of paste emulators, configured cach to be connected to a copy-paste driver, wherein cach copy-paste driver is running on one of a plurality of hosts that are connected to the peripheral sharing device, and the copy-paste driver is configured to fetch or store clipboard objects from the clipboard of the corresponding host, a security bridge that is configured to securely pass clipboard objects between pairs of copy emulator and paste emulator. The security bridge performs security operations, such as, enforce unidirectional data transfer of the clipboard object, monitor the clipboard object and enable or disable the copy-paste operation according to a set of security rules; enable or disable the copy-paste operation according to security policy, analyze clipboard object traffic to detect cybersecurity events, locking suspicious peripheral sharing devices, and preventing clipboard object transfer between pairs of copy-paste controllers according to security rules. The copy emulator receives the clipboard object from the copy-paste driver of a first host, transfer the clipboard object to the security bridge and conditioned upon passing the security conditions the security bridge transfer the clipboard object to the paste emulator that further pass the clipboard object to a second computer's copy-paste driver.


