USB Port Consent Mediation for Malicious Input Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current computer security paradigms, relying on firewalls and antivirus software, are ineffective in preventing malicious attacks via USB devices, which can spread malware by masquerading as legitimate devices and submitting operational inputs without user consent.
Innovation Solution
Implementing a system that requires user consent data to allow USB devices to communicate operational inputs, using port number association to manage risk, and employing a service virtual environment to isolate USB device communications, thereby preventing unauthorized operational inputs and malicious activities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If USB devices are allowed to communicate operational inputs freely, then device functionality and user convenience are improved, but security risk and vulnerability to malicious attacks increase
Solution Approach 1:
The patent introduces an intermediary system consisting of consent data storage and verification mechanisms that mediate between USB devices and the computing device. Before allowing operational inputs from USB devices, the system checks for associated consent data, acting as a intermediary layer that enables legitimate communication while blocking malicious inputs without requiring user awareness of each interaction
Solution Approach 2:
The patent implements preliminary action by requiring consent data to be established and stored before USB devices are permitted to communicate operational inputs. This preliminary authorization step prevents malicious attacks by ensuring that only pre-approved devices can interact with the computing device, addressing the security vulnerability before it can be exploited
2Reliability
If security measures are implemented to block malicious USB devices, then security protection is improved, but user convenience and device functionality deteriorate
Solution Approach 1:
The patent implements self-service by allowing USB devices to autonomously provide their identification information and have consent data automatically associated with them. The system serves itself by maintaining a database of consent data and automatically verifying device identities without requiring manual user intervention or awareness, thus maintaining security while preserving user convenience
Solution Approach 2:
The consent data acts as an intermediary that enables secure automatic authentication. Rather than requiring users to manually approve or deny each USB device connection, the intermediary consent data system automatically facilitates legitimate device communications while blocking malicious ones, maintaining both security and usability
Data Source
AI summary
Approaches for protecting a computing device against malicious code using an attack vector involving a USB device. A computing device prevents a USB device from communicating operational input to the computing device using a USB port residing on or coupled to the computing device unless consent data is stored on the computing device. Consent data is data that affirms consent provided by a user of the computing device to allow the USB device to communicate with the computing device using the USB port. Note that the lack of consent data stored on the computing device does not prohibit the USB device from identifying itself to the computing device. In this way, if the USB device comprises malicious code or has been designed in a malicious manner, the USB device will be unable to submit operational input to the computing device without the consent of the user.


