USB Hardware Firewall Adaptor for Secure SAMM Execution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current storage devices are vulnerable to security compromises when used in uncontrolled environments due to the execution of security, access management, and monitoring (SAMM) software on host systems, which increases costs when high-performance processors and additional RAM are required for secure operations.

Innovation Solution

A hardware firewall adaptor with a high performance processor and application RAM provides a secure environment for SAMM applications to operate when connected to uncontrolled host systems, separating the processing power from the storage device and reducing costs by only requiring the adaptor for specific, unsecured connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If SAMM applications are executed on the host system, then security management is simplified, but the system becomes vulnerable to compromise in uncontrolled environments

Engineering Contradiction:
Improvesecurity managementVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a hardware firewall adaptor as an intermediary device between the host system and storage device. This adaptor contains a dedicated processor that executes SAMM applications in a controlled hardware environment, isolating them from the untrusted host system while maintaining security management capabilities. The adaptor acts as a mediator that enables secure operation without requiring the host system to be trusted.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If high performance processor and additional RAM are incorporated into every USB storage device, then secure operations in uncontrolled environments are enabled, but the cost increases significantly

Engineering Contradiction:
Improvesecurity capabilityVSAvoiddevice cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent segments the security functionality from the storage device by placing it in a separate hardware firewall adaptor. This allows the storage device to remain simple and inexpensive, while the security capabilities are concentrated in the adaptor. Only users needing secure operations in uncontrolled environments require the adaptor, reducing the need for expensive hardware in every device.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The hardware firewall adaptor serves multiple functions: it provides a secure execution environment for SAMM applications, acts as a firewall between the host and storage device, and enables both controlled and uncontrolled environment operations. This multi-functionality consolidates security capabilities that would otherwise require separate components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If encryption engine is provided in the storage device, then data protection is achieved, but the device remains vulnerable to viruses and malware from uncontrolled host systems

Engineering Contradiction:
Improvedata protectionVSAvoidvirus and malware vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The hardware firewall adaptor implements preliminary anti-action by establishing a secure execution environment before any host system interactions occur. SAMM applications execute in this protected environment, preventing malware or viruses from the host system from compromising security functions. The adaptor proactively blocks harmful factors before they can affect the storage device or data.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS8209739B2Universal serial bus—hardware firewall (USB-HF) adaptor
Publication Date: 2012.06.26 KINGSTON TECHNOLOGY CORP
  • US8209739B2 patent drawing
  • US8209739B2 patent drawing
  • US8209739B2 patent drawing

AI summary

A system and method in accordance with the present invention provides a protected area for software to execute on a separate hardware firewall adaptor when a storage device is operating in an unprotected environment when connected to an uncontrolled or unmonitored host system. This software provides security through a plurality of security, access management and monitoring (SAMM) applications when a USB storage device is connected to a computer in an uncontrolled, unprotected environment.