USB Connector Security via Inhibited Negotiation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Secure devices cannot be equipped with USB connectors due to potential security breaches from bugs in the USB standard implementation, leading to attacks like buffer overflow and packet falsification, which compromises their security.

Innovation Solution

A method that inhibits the USB negotiation stage until the device is securely unlocked, using a secret identifier or biometric sign, and sets the battery charge level to a predetermined range, ensuring that USB management code execution is prevented until the device is in a secure mode.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a USB connector is embedded in a secure device, then connectivity and charging functionality are improved, but security is compromised due to potential bugs in USB standard implementation

Engineering Contradiction:
Improveconnectivity functionalityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary authentication and establishes a secure trusted environment before enabling USB connector functionality. The secure boot process and authentication mechanisms are executed in advance to ensure the device is in a secure state before allowing USB management code execution, thus preventing security vulnerabilities from being exploited.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The USB connector functionality is segmented into separate authenticated and unauthenticated modes. The authentication module acts as an independent security layer that controls access to USB management code. By dividing the system into secure core components and peripheral USB functionality, the patent isolates potential security risks while maintaining essential connectivity when authenticated.

Inventive Principle:
Principle #1Segmentation

2Speed

If USB management code is executed immediately upon connection, then connectivity speed is improved, but security vulnerability increases due to potential buffer overflow and packet falsification attacks

Engineering Contradiction:
Improveconnection speedVSAvoidsecurity attacks
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The system applies preliminary anti-action by implementing authentication and security checks before USB management code execution. The secure environment verification and biometric authentication processes are performed in advance to prevent buffer overflow and packet falsification attacks. This preemptive security measure blocks potential attack vectors before they can affect the system.

Inventive Principle:
Principle #9Preliminary anti-action

3Reliability

If USB connector is removed from secure devices, then security is maintained, but usability and convenience are reduced

Engineering Contradiction:
ImprovesecurityVSAvoidusability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The USB connector functionality transitions from a static removed state to a dynamic conditionally enabled state. The system dynamically adjusts USB connectivity based on authentication status and secure environment verification. When authenticated, USB functionality is activated; when unauthenticated, it remains disabled. This dynamic approach maintains security while restoring usability when needed.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

An authentication module acts as an intermediary between the USB connector hardware and the USB management code. This intermediary layer verifies security conditions, authenticates users through biometric or credential verification, and controls the execution of USB management code. The intermediary ensures that USB functionality is only accessible when security requirements are met, thus maintaining both security and usability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3053090B1Method for protection of a USB connector
Publication Date: 2018.12.19 AVANTIX
  • EP3053090B1 patent drawingFigure 1~2

AI summary

The invention relates to a method for the secured connection of a first device to a second device via a USB connection, each device comprising a USB connector, characterised in that the method comprises the following steps, which are implemented by the first device: detection of the connection of the second device; locking of the first device; and inhibition of the step of USB negotiation before the electrical stimulation according to the USB standard.