Intermediary Security Module for Host Peripheral Data Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data communication between host computing devices and peripheral devices lacks effective security measures to identify and mitigate security risks in real-time, potentially leading to unauthorized access or data disruption.

Innovation Solution

A method and apparatus that transparently receive and store data from either device, analyze it for security risks, and implement a security process defined by rules, which may include encryption, data modification, or isolation, to prevent communication termination and ensure secure data transfer.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is transparently received and analyzed in real-time, then security risk identification is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity risk identificationVSAvoiddata processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A security module is introduced as an intermediary component between the host computing device and peripheral device. This module receives data from either device, analyzes it for security risks, and controls the echo response. By isolating the security analysis function in a separate module, the complexity is contained within the module rather than distributing throughout the entire system, thus improving security identification while managing device complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security analysis is performed on all data, then security protection is improved, but communication speed decreases

Engineering Contradiction:
Improvesecurity protectionVSAvoiddata communication speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The system performs security analysis on all data passing through the module (excessive action), ensuring comprehensive security protection. The module analyzes data characteristics, protocols, and patterns to identify security risks. While this may temporarily slow individual data transmissions, the overall system maintains high communication speed by processing data efficiently and only blocking or encrypting when necessary, rather than slowing down all data for extensive analysis.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The security module operates continuously, analyzing data in real-time without interrupting the overall communication flow between host and peripheral devices. The module maintains constant surveillance of data traffic, identifying and responding to security threats as they occur, ensuring continuous security protection while minimizing impact on communication speed through efficient real-time processing.

Inventive Principle:
Principle #20Continuity of useful action

3Reliability

If encryption and security processes are applied, then data security is improved, but ease of operation decreases

Engineering Contradiction:
Improvedata securityVSAvoiddata transfer operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The security module operates autonomously, automatically analyzing data, identifying security risks, and applying appropriate responses without requiring user intervention. The module self-manages the security processes, including encryption, data modification, and communication control, based on predefined security rules and real-time analysis. This automation maintains high data security while preserving ease of operation for users.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system dynamically adjusts security parameters based on the analyzed data characteristics and identified risks. When security risks are detected, the module changes parameters such as encryption level, data modification程度, and communication protocols accordingly. This dynamic parameter adjustment ensures high data security for compromised data while maintaining normal operation parameters for secure data, thus balancing security improvement with ease of operation.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8566934B2Apparatus and method for enhancing security of data on a host computing device and a peripheral device
Publication Date: 2013.10.22 NETSCOUT SYSTEMS INC
  • US8566934B2 patent drawing
  • US8566934B2 patent drawing
  • US8566934B2 patent drawing

AI summary

A method is provided of enhancing security of at least one of a host computing device and a peripheral device. In the method, the host computing device is coupled to the peripheral device through a communication interface. The method includes transparently receiving data from one of the peripheral device and the host computing device, and storing the received data. The method further includes analyzing the stored data to identify a circumstance posing a security risk. If analyzing does not identify such a circumstance, then the method includes transparently echoing the data to the other of the peripheral device and the host. If analyzing does identify such a circumstance, then the method includes performing a security process defined by a rule. Related apparatus is provided, as well as other methods and apparatus.