Self-Locking USB Filter Device with Authentication Chip

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing USB port protection methods, such as mechanical locks and software solutions, are inadequate as they can be easily bypassed, lack secure key management, and do not effectively secure authorized use of USB keyboards and mice, while also failing to provide real-time monitoring and tampering detection.

Innovation Solution

A self-locking USB port device with internal circuitry and a spring-loaded mechanism that physically blocks unused ports, combined with a management software application for real-time monitoring and authentication, ensuring only authorized devices can connect and providing visual indicators of security status.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If mechanical locks are used to physically block USB ports, then unauthorized access is prevented, but the locks can be easily bypassed and require master keys or large sets of keys for each computer

Engineering Contradiction:
Improvesecurity protectionVSAvoidkey management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces mechanical locking systems with electronic authentication. The USB port protection device uses an authentication chip that communicates with security software via USB data lines to verify authorization, eliminating the need for physical keys and mechanical locking mechanisms while maintaining security protection.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces an authentication chip as an intermediary between the USB port and connected devices. This chip acts as a mediator that verifies authorization credentials and controls access to the USB port, replacing the direct mechanical lock system with an electronic authentication layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If software-based USB port control is implemented, then device access can be managed, but the software may be bypassed if the computer is infected or administrator permissions are obtained

Engineering Contradiction:
Improvedevice managementVSAvoidsecurity protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the security system into separate functional components: an authentication chip residing in the USB port protection device, security software on the host computer, and a centralized management server. This segmentation distributes security functions across multiple independent elements, making the system more resilient to attacks on any single component.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The authentication chip serves as a hardware intermediary that enforces security policies independently of the host operating system. By placing authentication logic in a separate hardware component rather than relying solely on software, the system prevents bypass through software attacks or compromised administrator permissions.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If USB ports are left accessible for keyboard and mouse usage, then ease of operation is maintained, but security protection is compromised

Engineering Contradiction:
Improveperipheral device accessVSAvoidsecurity protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements dynamic access control where the USB port protection device can be electronically authenticated and authorized for specific devices like keyboards and mice. The authentication chip dynamically enables or disables port access based on real-time verification of authorization credentials, allowing legitimate devices to connect while maintaining security.

Inventive Principle:
Principle #15Dynamics

4Reliability

If existing mechanical USB port locks are deployed, then physical blocking is achieved, but real-time monitoring and tampering detection are not provided

Engineering Contradiction:
Improvephysical blockingVSAvoidtampering detection
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements feedback mechanisms where the authentication chip continuously communicates with the security software to report the status of the USB port protection device. This enables real-time monitoring of device presence, authentication status, and tampering attempts, providing immediate feedback to both local and centralized security systems.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The authentication chip acts as an intermediary monitoring system that detects tampering attempts and communicates this information to the security software and centralized management server, enabling real-time detection and response to security threats.

Inventive Principle:
Principle #24Intermediary (Mediator)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

The solution effectively prevents unauthorized access to USB ports, ensures secure connection of authorized devices, and provides continuous monitoring and tampering detection, enhancing computer information security by physically blocking unused ports and authenticating connected devices.

Implementation Method 1

A self-locking USB port device with internal circuitry and a spring-loaded mechanism that physically blocks unused ports

Methodology Applied
Scientific EffectSpring mechanism: Spring

Implementation Method 2

an LED indicator attached to said printed circuit board assembly and visible on said faceplate

Methodology Applied
Scientific EffectLED emission: Light Emitting Diode

Data Source

PatentUS10460132B2Security keys associated with identification of physical USB protection devices
Publication Date: 2019.10.29 HIGH SEC LABS LTD
  • US10460132B2 patent drawing
  • US10460132B2 patent drawing
  • US10460132B2 patent drawing

AI summary

A self-locking USB filter device is disclosed that comprises at least one permanently attachable self-locking USB plug having at least one locking tooth to permanently connect the permanently attachable self-locking USB plug to a USB jack of a protected computing apparatus. The self-locking USB filter protects the protected computing apparatus by blocking unauthorized data transfer and blocks all communication unless the authenticator is authenticated by software installed in the protected computing apparatus. A method of protecting USB jacks of a computing device is also disclosed.