Secure KVM Switch Assembly with Dual Isolation Elements
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional KVM switches pose a security risk due to potential data transfer between computers with different security levels, as they lack effective isolation mechanisms.
Innovation Solution
A secure switch assembly with dedicated switching elements and a secure controller for each computer, which receives selection signals and generates enabling signals to isolate data paths between the common keyboard and mouse inputs and each computer, ensuring high-grade assurance by preventing unauthorized data transfer.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a conventional KVM switch is used to control multiple computers from a single keyboard, video display and mouse, then operational flexibility and ease of use are improved, but security is worsened due to potential data transfer paths between computers with different security levels
Solution Approach 1:
The KVM switch is divided into multiple isolated switching elements (first switching element, second switching element, etc.), each dedicated to a specific computer. These switching elements are physically or logically separated to prevent data leakage between computers while maintaining individual control functionality.
Solution Approach 2:
A secure controller acts as an intermediary between the common input devices (keyboard, mouse) and the individual computer switching elements. It receives selection signals, validates them through determining means, and generates enabling signals to activate the appropriate switching element, thereby controlling data flow and preventing unauthorized transfer.
2Adaptability or versatility
If hard wire links are used to connect each computer to the KVM switch, then connectivity and adaptability are improved, but security is worsened due to potential information leakage along the data paths
Solution Approach 1:
The data path is segmented into separate channels for each computer through dedicated switching elements. Each switching element handles only its assigned computer's data, creating isolated communication paths that maintain connectivity while preventing cross-contamination of data between security zones.
Solution Approach 2:
Each switching element is configured with specific local properties (dedicated to a particular computer) rather than being a generic shared resource. This local specialization ensures that data transmitted through each element remains confined to its intended destination, preventing unauthorized access to other computers.
3Object-affected harmful factors
If isolation mechanisms are implemented to prevent data transfer between computers, then security is improved, but device complexity increases due to dedicated switching elements for each computer
Solution Approach 1:
The secure controller serves multiple functions: it receives selection signals from the keyboard, determines their validity through determining means, generates enabling signals for the appropriate switching elements, and coordinates the overall switching operation. This multi-functionality reduces the need for separate dedicated control units for each computer.
Solution Approach 2:
The switching elements are pre-configured and ready to receive data from their designated computers. When a valid selection signal is received, the secure controller quickly activates the appropriate switching element through pre-established enabling signals, eliminating the need for complex real-time configuration routines.
Data Source
Figure 1~2
AI summary
A secure switch assembly for controlling first and second computers using a common keyboard and a common mouse is provided. The switch assembly comprises a secure controller together with first and second switching elements. The secure controller comprises receiving means, configured to receive a selection signal from a user, determining means configured to determine whether the selection signal represents a single, coherent selection and transmitting means configured to emit first and second enabling signals. The first switching element is associated with a first computer and is configured to receive a signal indicative of a mouse instruction from a mouse, a signal indicative of a keyboard instruction from a keyboard and a first enabling signal from the secure controller. The second switching element is also associated with the first computer and is configured to receive a signal indicative of a mouse instruction from the first switching element, a signal indicative of a keyboard instruction from the first switching element and a second enabling signal from the secure controller. The first and second switching elements are configured to enable transmission of the mouse and keyboard instructions therethrough if both the first and second enabling signals are respectively received. The first and second computers are effectively isolated by the first and second switching elements and thereby effect assurance to a high grade.