Centralized USB Management Server Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing USB connections in host devices is labor-intensive and time-consuming due to the need for manual configuration and certification of each device, especially in environments with multiple USB devices and host devices, which hampers efficient security management.

Innovation Solution

Implementing a client-server architecture for USB connection management, where a USB management client at the host device obtains and transmits USB ID information to a USB management server for authentication based on predefined policies, allowing or forbidding connections according to validity, thereby reducing manual labor and enhancing security strategies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual configuration and certification of each USB device is performed, then security management is achieved, but labor intensity and time consumption increase significantly

Engineering Contradiction:
Improvesecurity managementVSAvoidmanagement efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces a USB management server as an intermediary between USB devices and host devices. The server automatically authenticates USB devices by obtaining their ID information, verifying it against stored records, and managing connection permissions centrally. This eliminates manual configuration and certification work, resolving the contradiction between maintaining security and improving management efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If USB ports are disabled one by one for security reasons, then security is maintained, but manual labor and time cost increase

Engineering Contradiction:
ImprovesecurityVSAvoidtime cost
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-registering USB device ID information in the USB management server before actual connection occurs. When a USB device connects, the server automatically verifies its ID against the pre-stored records and grants or denies access accordingly. This preliminary configuration eliminates the need for time-consuming manual port disabling while maintaining security.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If centralized USB device management is implemented, then manual operations are reduced, but system complexity increases

Engineering Contradiction:
Improvemanagement efficiencyVSAvoidsystem architecture
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The USB management server acts as a centralized intermediary that handles all authentication and permission management operations. By consolidating these functions in a single server rather than distributing complexity across multiple host devices, the system achieves automated management while keeping the added complexity localized to one component, making the overall system easier to manage.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11561917B2USB connection management
Publication Date: 2023.01.24 HEWLETT PACKARD ENTERPRISE DEV LP
  • US11561917B2 patent drawing
  • US11561917B2 patent drawing
  • US11561917B2 patent drawing

AI summary

In embodiments of the present disclosure, there is provided a solution for managing a USB connection between a USB device and a host device. According to embodiments of the present disclosure, a USB management server receives, from a USB management client at a host device, USB ID information for identifying a USB device that is plugged into the host device. Whether the USB ID information is valid is determined based on an authentication policy for authenticating the USB device. If the USB ID information is valid, the USB management client is instructed to permit a connection between the USB device and the host device. Accordingly, the connection may be managed by the USB management server. Embodiments of the present disclosure present an effective way for managing USB connections in a centralized way, which provides various flexible authentication policies and requires less manual operations.