Secure KVM Remote Controller-Indicator Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current secure KVM systems lack the necessary security measures for remote operation, particularly in high-security applications, as they are vulnerable to Man-In-The-Middle attacks and do not support communication media encryption, mutual authentication, and anti-tampering, which are crucial for secure remote extension of KVM control and indication functions.
Innovation Solution
A secure KVM system with a remote Controller-Indicator that employs encryption and authentication functions, including mutual authentication using SHA-0 to SHA-512 and AES encryption, and anti-tampering mechanisms to ensure secure remote operation, extending keyboard, mouse, display, and smart-card functions over a secure communication link.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a remote Controller-Indicator is added to extend KVM control functions, then remote operation capability is improved, but security vulnerabilities increase due to exposure to Man-In-The-Middle attacks
Solution Approach 1:
The patent introduces an encryption module and authentication module as intermediaries between the remote Controller-Indicator and the KVM switch. These modules mediate all communications, encrypting data transmissions and verifying device identities, thereby protecting the remote operation capability from Man-In-The-Middle attacks while maintaining ease of remote control
Solution Approach 2:
The patent implements preliminary security measures by incorporating authentication functionality that verifies the identity of the remote Controller-Indicator before allowing it to control the KVM switch. This preliminary anti-action prevents unauthorized devices from exploiting the remote operation capability, countering potential security threats before they can manifest
2Reliability
If encryption and authentication functions are implemented, then security is improved, but device complexity increases
Solution Approach 1:
The patent merges the encryption module, authentication module, and anti-tampering module into an integrated security system within the KVM switch architecture. By combining these security functions into a unified structure rather than separate components, the system achieves high security reliability while minimizing the increase in device complexity
Solution Approach 2:
The authentication module serves multiple functions: it authenticates remote controllers, encrypts communications, and works in conjunction with the anti-tampering module to provide comprehensive security. This multi-functionality reduces the need for separate dedicated components, thereby improving security without proportionally increasing device complexity
3Reliability
If anti-tampering means are built inside Secure KVMs, then security is improved, but manufacturing complexity increases
Solution Approach 1:
The patent implements anti-tampering means by nesting detection circuitry and protective mechanisms within the existing KVM switch architecture. The anti-tampering module is integrated into the internal structure, with sensors and detection logic nested within the device housing and circuit board layouts, allowing security enhancement without requiring complete redesign of manufacturing processes
Data Source
Figure 1
Figure 2
Figure 3
AI summary
As KVMs (Keyboard Video Mouse) may be abused by attackers to bridge or leak between isolated networks, Secure KVM typically used having isolated circuitry for each computer channel to reduce its vulnerability to leakages between channels. To enable remote installation of a KVM with isolated computers a remote Controller-Indicator is needed in order to present to the user the KVM front panel indications and to enable certain control functions. The current invention provides a KVM switch capable of providing secure remote extension of KVM control and indication functions. Another object of the present invention is to provide a KVM switch having secure remote extension of the complete user console with support of: remote keyboard, mouse, one or more displays, smart-card reader, audio devices, KVM control and KVM monitoring.