Secure KVM with Emulated EDID Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current secure KVM devices are vulnerable to sophisticated attacks and data leakage, despite having anti-tampering systems and isolation features, as they can be exploited through EDID channels, audio channels, and USB ports, posing risks to high-security networks.

Innovation Solution

A secure KVM device with Display Plug and Play Emulated Memory (DPPEM) devices and a switching matrix, coupled with a controller function that reads and writes EDID data, ensures isolation and unidirectional data flow, using anti-tampering measures and secure channel selection to prevent data leakage, and integrates features like audio switching and indicators for user interaction.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If commercial KVM devices are used to enable single console access to multiple hosts, then ease of operation is improved, but security reliability deteriorates due to potential data leakage through EDID channels, USB ports, and buffer storage

Engineering Contradiction:
Improvesingle console accessVSAvoidnetwork isolation
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent divides the EDID data path into separate segments for each host, with individual EDID buffers and isolation circuitry. Each host's EDID data is kept in its dedicated buffer memory, preventing cross-contamination between hosts while maintaining the convenience of single-console access to multiple hosts.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary isolation mechanism between the KVM controller and host EDID channels. This intermediary layer includes isolation circuitry and controlled data transfer pathways that mediate all EDID data flow, ensuring that data cannot leak between hosts while still allowing legitimate EDID communication for display configuration.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If anti-tampering systems are added to secure KVM devices, then security reliability is improved, but device complexity increases due to additional sensors, micro-switches, and monitoring circuitry

Engineering Contradiction:
Improvesecurity protectionVSAvoidanti-tampering structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines the anti-tampering detection functionality with the existing KVM control circuitry. The micro-switch sensors and monitoring functions are integrated into the device's existing structural framework, allowing security protection to be achieved without proportionally increasing overall device complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The anti-tampering system is designed to be self-monitoring and self-activating. The micro-switches automatically detect enclosure intrusion and trigger deactivation of the device without requiring external monitoring systems, reducing the complexity burden of additional control circuitry.

Inventive Principle:
Principle #25Self-service

3Reliability

If buffer reset functionality is implemented to prevent keyboard channel data leakage, then security reliability is improved, but loss of time occurs during host switching due to buffer clearing operations

Engineering Contradiction:
Improvedata leakage preventionVSAvoidhost switching time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts the keyboard buffer management function into a separate, dedicated buffer reset mechanism that operates independently from the main host switching control. This allows buffer clearing to be performed asynchronously or in parallel with switching operations, minimizing the time impact on host transitions while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

4Adaptability or versatility

If multiple DPPEM devices are used to support multiple displays per host, then adaptability is improved, but device complexity increases due to additional switching matrix connections and memory devices

Engineering Contradiction:
Improvemulti-display supportVSAvoidswitching matrix structure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent designs the switching matrix and DPPEM devices with universal functionality that can accommodate varying numbers of displays per host. The same basic matrix structure and memory device architecture can support single-display or multi-display configurations through software control, avoiding the need for physically different hardware configurations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9501157B2Secure KVM system having multiple emulated EDID functions
Publication Date: 2016.11.22 HIGH SEC LABS LTD
  • US9501157B2 patent drawing
  • US9501157B2 patent drawing
  • US9501157B2 patent drawing

AI summary

The present invention discloses a KVM (Keyboard Video Mouse) device for operation in high security environments. More specifically, this invention discloses a secure KVM built to prevent data leakages between two or more coupled computer hosts. The invention also discloses methods of operation of the secure KVM. Further more particularly, the invention presents a special secure KVM device for interacting with computers using a single user console, while preventing data leakage between the connected computers and attached networks.