Port Management IC for Peripheral Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security measures for preventing unauthorized access to peripheral ports, such as USB ports, in host computing systems are inadequate, as they can be vulnerable to tampering and do not effectively prevent unauthorized access or data theft, especially when the system is powered off.

Innovation Solution

A port management integrated-circuit chip (IC) is used to control access to peripheral ports by communicating with a manageability controller to enforce security actions like accepting, rejecting, or disabling devices, ensuring secure access even when the system is powered off.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional software-based security measures are used to control peripheral port access, then the system can manage device access, but the security measures are vulnerable to tampering and ineffective when the system is powered off

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidvulnerability to tampering
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a dedicated port management IC as an intermediary component between the peripheral ports and the host computing system. This separate hardware module enforces security policies independently, preventing direct tampering with the host system while maintaining effective access control. The port management IC acts as a security gateway that mediates all connections to peripheral ports.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces software-based security mechanisms with hardware-based enforcement through a dedicated port management IC. This substitution moves security control from the vulnerable software layer to a more tamper-resistant hardware layer, ensuring security measures remain effective even when the host system is powered off or compromised.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If a dedicated port management IC is implemented to enforce security policies, then security against tampering is improved, but the device complexity increases

Engineering Contradiction:
Improvesecurity enforcementVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security management functionality into a separate, dedicated port management IC distinct from the main host computing system. This segmentation isolates security-critical functions in a specialized component, making the overall system architecture more modular. While it adds a component, it simplifies the security implementation by concentrating security logic in one dedicated module rather than distributing it across the entire system.

Inventive Principle:
Principle #1Segmentation

3Reliability

If security control is centralized in a port management IC, then access regulation is effective, but the ease of operation for users is reduced

Engineering Contradiction:
Improveaccess controlVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The port management IC is pre-configured with security policies and device identification information before operation. This preliminary setup allows the IC to automatically enforce access control decisions without requiring real-time user intervention. Users simply connect devices, and the pre-configured IC handles security verification, maintaining both security and ease of operation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11373014B2Controlling access to peripheral ports of a host computing system
Publication Date: 2022.06.28 HEWLETT PACKARD ENTERPRISE DEV LP
  • US11373014B2 patent drawing
  • US11373014B2 patent drawing
  • US11373014B2 patent drawing

AI summary

Example implementations relate to system and method of controlling access to ports of a host computing system having a port management integrated-circuit chip (IC), a manageability controller, and a plurality of peripheral device hubs having ports. The IC is to receive a first data from the plurality of peripheral device hubs and communicate the first data to the manageability controller. The first data includes device identifiers of a first peripheral device and a port identifier of the port. Further, the IC is to receive a security action from the manageability controller and implement the security action on the port. The security action is determined based on comparison of the first data and the second data including access control rules, where the security action is linked to each access control rule, and where each access control rule has the port identifier mapped to predetermined device identifiers of a second peripheral device.