Secure KVM Remote Controller-Indicator Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current secure KVM systems lack the necessary security measures for remote operation, particularly in high-security applications, as they are vulnerable to Man-In-The-Middle attacks and do not support communication media encryption, mutual authentication, and anti-tampering, which are crucial for secure remote extension of KVM control and indication functions.

Innovation Solution

A secure KVM system with a remote Controller-Indicator that employs encryption and authentication functions, including mutual authentication using SHA-0 to SHA-512 and AES encryption, and anti-tampering mechanisms to ensure secure remote operation, extending keyboard, mouse, display, and smart-card functions over a secure communication link.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a remote Controller-Indicator is added to extend KVM control functions, then remote operation capability is improved, but security vulnerabilities increase due to exposure to Man-In-The-Middle attacks

Engineering Contradiction:
Improveremote operation capabilityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an encryption module and authentication module as intermediaries between the remote Controller-Indicator and the KVM switch. These modules mediate all communications, encrypting data transmissions and verifying device identities, thereby protecting the remote operation capability from Man-In-The-Middle attacks while maintaining ease of remote control

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary security measures by incorporating authentication functionality that verifies the identity of the remote Controller-Indicator before allowing it to control the KVM switch. This preliminary anti-action prevents unauthorized devices from exploiting the remote operation capability, countering potential security threats before they can manifest

Inventive Principle:
Principle #9Preliminary anti-action

2Reliability

If encryption and authentication functions are implemented, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the encryption module, authentication module, and anti-tampering module into an integrated security system within the KVM switch architecture. By combining these security functions into a unified structure rather than separate components, the system achieves high security reliability while minimizing the increase in device complexity

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authentication module serves multiple functions: it authenticates remote controllers, encrypts communications, and works in conjunction with the anti-tampering module to provide comprehensive security. This multi-functionality reduces the need for separate dedicated components, thereby improving security without proportionally increasing device complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If anti-tampering means are built inside Secure KVMs, then security is improved, but manufacturing complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidmanufacturing complexity
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent implements anti-tampering means by nesting detection circuitry and protective mechanisms within the existing KVM switch architecture. The anti-tampering module is integrated into the internal structure, with sensors and detection logic nested within the device housing and circuit board layouts, allowing security enhancement without requiring complete redesign of manufacturing processes

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentEP2539847B1Secure KVM system having remote controller-indicator
Publication Date: 2019.06.12 HIGH SEC LABS LTD
  • EP2539847B1 patent drawingFigure 1
  • EP2539847B1 patent drawingFigure 2
  • EP2539847B1 patent drawingFigure 3

AI summary

As KVMs (Keyboard Video Mouse) may be abused by attackers to bridge or leak between isolated networks, Secure KVM typically used having isolated circuitry for each computer channel to reduce its vulnerability to leakages between channels. To enable remote installation of a KVM with isolated computers a remote Controller-Indicator is needed in order to present to the user the KVM front panel indications and to enable certain control functions. The current invention provides a KVM switch capable of providing secure remote extension of KVM control and indication functions. Another object of the present invention is to provide a KVM switch having secure remote extension of the complete user console with support of: remote keyboard, mouse, one or more displays, smart-card reader, audio devices, KVM control and KVM monitoring.