USB Hardware Firewall for Malicious Packet Blocking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The USB infrastructure is vulnerable to malicious attacks through malformed packets, device spoofing, and electrical tricks, as existing technologies fail to effectively prevent malicious data transmission from unauthorized or compromised USB devices.

Innovation Solution

A hardware firewall device is interposed between USB devices and hosts, monitoring and filtering communication packets, blocking unwanted data, and providing packet validation and shallow or deep inspection to prevent malicious activity, while optionally acting as a hub or using an optically isolated bus for enhanced security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a hardware firewall is introduced between USB devices and host, then security against malicious data transmission is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a hardware firewall device as an intermediary component positioned between USB devices and the host system. This firewall monitors, validates, and filters USB communication packets, blocking malicious data while allowing legitimate traffic. The intermediary approach resolves the contradiction by providing enhanced security through a dedicated security device that handles the complexity of packet inspection and filtering, thereby protecting the host without requiring the host itself to become more complex.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If packet inspection and validation are performed, then security against malformed packets is improved, but processing time increases

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary packet validation and inspection at the hardware firewall level before packets reach the host system. By performing validation checks, malformed packet detection, and filtering actions in advance at the hardware level, the system prevents malicious or corrupted packets from consuming host processing resources. This preliminary action reduces the time the host would otherwise spend processing potentially harmful traffic, thereby resolving the contradiction between security enhancement and processing time.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If deep packet inspection is implemented, then detection of malicious data is improved, but device complexity and processing overhead increase

Engineering Contradiction:
Improvedetection capabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent positions the hardware firewall as an intermediary that performs deep packet inspection and malicious data detection before packets reach the host. By implementing sophisticated inspection capabilities at this dedicated security device rather than within the host system, the patent enhances detection capability while isolating the complexity to the firewall component. This allows the host to maintain simpler architecture while still benefiting from advanced malicious data detection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

Effectively prevents malicious data transmission by blocking unauthorized devices and malformed packets, ensuring secure communication between USB devices and hosts, thereby enhancing computer security against various USB-based attacks.

Implementation Method 1

the device may be interfaced to the host through an optically isolated bus

Methodology Applied
Scientific EffectOptical isolation: Optical Fibre

Data Source

PatentUS8646082B2USB firewall apparatus and method
Publication Date: 2014.02.04 CYBERNET SYSTEMS CORP
  • US8646082B2 patent drawing
  • US8646082B2 patent drawing
  • US8646082B2 patent drawing

AI summary

Apparatus and methods prevent malicious data in Universal Serial Bus (USB) configurations by providing a hardware firewall. A hardware device interconnected between a host and the USB monitors communication packets and blocks packets having unwanted or malicious intent. The device may act as a hub, enabling multiple devices to connect to a single host. The device may only allow mass storage packets from a device recognized as a mass storage device. The device may block enumeration of unwanted devices by not forwarding packets between the device and the host. The device may be operative to assign a bogus address to a malicious device so as not to transfer communications from the device further up the chain to the host. The device may provide shallow or deep packet inspection to determine when a trusted device is sending possible malicious data, or provide packet validation to block packets that are malformed.