Secure KVM Remote Controller-Indicator with Anti-Tampering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current secure KVM systems lack the necessary security measures for remote operation, particularly in high-security applications, as they do not provide adequate encryption, mutual authentication, and anti-tampering features, making them vulnerable to attacks like Man-In-The-Middle and data leakage between isolated networks.

Innovation Solution

A secure KVM switch with a remote Controller-Indicator that employs encryption/decryption functions using algorithms like SHA and AES, mutual authentication through secret key pairing, and anti-tampering mechanisms to ensure secure remote operation and extension of user console functions, including keyboard, mouse, display, and smart-card access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a remote controller is added to extend user console functions remotely, then ease of operation is improved, but security vulnerability increases due to lack of encryption and authentication

Engineering Contradiction:
Improveremote operation capabilityVSAvoidsecurity protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary security processing unit that mediates between the remote controller and the KVM switch. This unit implements encryption/decryption functions and mutual authentication mechanisms, acting as a security gateway that enables remote operation while protecting against security threats. The intermediary processess encrypted signals from the remote controller before forwarding them to the KVM switch, thus resolving the contradiction by adding security infrastructure without eliminating remote functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encryption and mutual authentication mechanisms are implemented, then security is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by implementing security functions in a dedicated, localized security processing unit rather than distributing security logic throughout the entire system. The encryption/decryption and authentication mechanisms are concentrated in this specific component, which interacts with the remote controller through defined interfaces. This localization reduces overall system complexity by creating a modular security subsystem that can be managed independently from the rest of the KVM functionality.

Inventive Principle:
Principle #3Local quality

3Reliability

If anti-tampering mechanisms are added to prevent unauthorized access, then security is improved, but ease of operation may deteriorate due to additional authentication requirements

Engineering Contradiction:
Improvesecurity protectionVSAvoiduser access convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements preliminary action by performing mutual authentication between the remote controller and the security processing unit before establishing the remote control connection. The authentication process occurs in advance, verifying the legitimacy of both parties before allowing any control operations. Once authenticated, the connection remains valid for the duration of the session, avoiding repeated authentication prompts during normal operation. This preliminary verification balances security requirements with operational convenience.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9791944B2Secured KVM system having remote controller-indicator
Publication Date: 2017.10.17 HIGH SEC LABS LTD
  • US9791944B2 patent drawing
  • US9791944B2 patent drawing
  • US9791944B2 patent drawing

AI summary

A secure peripheral switching system comprises a secure peripheral switch remotely coupled to a secure remote controller-indicator, wherein the secure peripheral switch is capable of interfacing with at least two coupled host computers while ensuring data isolation among said at least two coupled host computers, said secure peripheral switch comprising a first interface circuitry to securely link the secure peripheral switch with said secure remote controller-indicator; and a secure remote controller-indicator. The secure remote controller-indicator comprises a second interface circuitry to securely link said secure remote controller-indicator with said secure peripheral switch; a control function capable of enabling a remote user control of said coupled secure peripheral switch; an indication function capable of providing a remote user indications of coupled secure peripheral switch; and an anti-tampering circuitry to detect physical tampering event and report such event to said secure peripheral switch.