Dedicated USB Controller Isolation for Hot-Plug Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Hot-pluggable ports, such as USB ports, pose security risks due to the ability of any device to connect, leading to data protection issues as disabling all ports also disables necessary devices.

Innovation Solution

A dedicated USB controller is isolated from the operating system, and devices are authenticated through hash signatures, allowing only authorized devices to connect by generating a BIOS SMI event and validating device types and class codes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all hot-pluggable ports are disabled to protect data, then security is improved, but device connectivity and functionality are lost

Engineering Contradiction:
ImprovesecurityVSAvoiddevice connectivity
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the hot-pluggable port management into two distinct parts: a secure authentication layer that validates device identities using hash signatures, and a functional layer that enables connectivity. This segmentation allows the system to maintain security while permitting authorized devices to connect, resolving the contradiction between security and connectivity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary authentication through hash signature verification before allowing device connectivity. By pre-establishing security credentials and validating devices before granting access, the system ensures security is maintained while enabling necessary device connections, thus resolving the contradiction between security and adaptability.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If hot-pluggable ports are enabled to allow device connectivity, then adaptability is improved, but security risks increase due to unauthorized device access

Engineering Contradiction:
Improvedevice connectivityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces hash signature verification as an intermediary mechanism between the hot-pluggable port and connecting devices. This intermediary layer authenticates device identities before granting connectivity, allowing the system to maintain adaptability while filtering out unauthorized devices, thus reducing security risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements a feedback mechanism where the system continuously monitors and validates device connections through hash signature verification. This feedback loop ensures that only authenticated devices maintain connectivity, allowing the system to adapt to legitimate devices while preventing unauthorized access, thereby resolving the security risk.

Inventive Principle:
Principle #23Feedback

3Reliability

If a dedicated USB controller is isolated from the operating system, then security is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidcontroller architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the USB controller from the main operating system environment and isolates it as a dedicated secure component. By separating the controller architecture, the system improves security by preventing operating system-level attacks while maintaining necessary functionality, accepting the increased architectural complexity as a trade-off for enhanced security.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11429288B1System and method to secure ports on a computer
Publication Date: 2022.08.30 DELL PROD LP
  • US11429288B1 patent drawing
  • US11429288B1 patent drawing
  • US11429288B1 patent drawing

AI summary

A system, method, and computer-readable medium are disclosed for securing hot-pluggable ports, such as USB ports, of an information handling system, by isolating a dedicated controller from the operating system of the information handling system. Devices that are to be allowed to be enabled at the ports are determined. A hash signature is created and saved to verify the devices. The controller and ports are held in reset until the devices are authenticated.