Secure I/O Module Peripheral Authentication via Provisioning Manifest

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems fail to efficiently authenticate and secure new peripherals attached to computer terminals, leading to potential security threats and downtime, as existing security methods do not recognize new peripherals and require time-consuming authorization processes.

Innovation Solution

A secure provisioning manifest and a secure I/O module are implemented to authenticate and communicate with authenticated peripherals, identify unauthorized ones, and request authorization for new peripherals, establishing a secure encrypted session and monitoring for security threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If existing security methods are used to authenticate peripherals, then system security is maintained, but new peripherals cannot be recognized and require time-consuming authorization processes

Engineering Contradiction:
Improveperipheral authorization speedVSAvoidsystem security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The secure provisioning manifest pre-approves specific peripheral devices by ID before they are needed. When a new peripheral is attached, the system checks its ID against the manifest in advance-prepared authorization lists, allowing immediate recognition and authentication without requiring time-consuming real-time authorization processes, thus improving productivity while maintaining reliability

Inventive Principle:
Principle #10Preliminary action

2Loss of time

If new peripherals are quickly authorized to minimize downtime, then system functionality is restored faster, but security verification may be insufficient

Engineering Contradiction:
Improvedowntime during peripheral replacementVSAvoidsecurity threats
Core Design Contradiction:
Loss of timeVSObject-affected harmful factors

Solution Approach 1:

The secure provisioning manifest acts as an intermediary authorization mechanism between the peripheral device and the security system. It provides pre-vetted peripheral IDs that the system can quickly verify without extensive security checks, enabling fast peripheral replacement and minimal downtime while maintaining security through the trusted manifest database

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If strict security authentication is enforced for all peripherals, then system security is enhanced, but peripheral replacement and system adaptability are reduced

Engineering Contradiction:
Improveperipheral authentication securityVSAvoidperipheral replacement flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The authorization system is segmented into two paths: a fast track using the secure provisioning manifest for pre-approved peripherals, and a standard security verification path for other cases. This segmentation allows the system to maintain strict security standards while providing flexibility and speed for routine peripheral replacements through the manifest-based fast authorization channel

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10025957B2Learning a new peripheral using a security provisioning manifest
Publication Date: 2018.07.17 NCR VOYIX CORP
  • US10025957B2 patent drawing
  • US10025957B2 patent drawing
  • US10025957B2 patent drawing

AI summary

A secure provisioning manifest used to authenticate and securely communicate with peripherals attached to a computer is provided with techniques to learn about a new peripheral not authorized to be attached to the computer and possibly gain authorization for the peripheral. A secure I/O module, that is separate from an operating system and transaction software executed by a processor of the computer, uses the secure provisioning manifest to authenticate and establish a secure encrypted session for communicating with each peripheral authorized to be attached to the computer. When an unauthorized peripheral is found, identifying information for the peripheral is transmitted to an enterprise provisioning server with a request to authorize the peripheral.