USB Mediation Module for Host Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need to effectively mediate communication between host computing devices and USB devices, ensuring only authorized devices can communicate and operate properly to prevent unauthorized access and malicious activities.

Innovation Solution

A system that includes a mediation module interposed between the host computing device and the USB device, which authenticates devices by comparing identifying characteristics to a stored set of authorized devices, and if unauthorized, inhibits communication, while also ensuring proper communication protocols are followed to prevent attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If USB devices are freely connected to host computing devices, then ease of operation and connectivity are improved, but security and risk of unauthorized access deteriorate

Engineering Contradiction:
ImproveUSB device connectivityVSAvoidunauthorized access and malicious activities
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a mediation module as an intermediary component between the host computing device and USB devices. This module performs authentication by comparing identifying characteristics of USB devices against a stored set of authorized devices, and only permits communication for authorized devices. The mediator thus enables secure connectivity while blocking unauthorized access, resolving the contradiction between ease of connection and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If communication mediation and authentication are implemented, then security against unauthorized access is improved, but device complexity and communication overhead increase

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidcommunication mediation system
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The mediation module is designed as a dedicated intermediary that handles authentication and communication mediation. By isolating these security functions in a separate module, the host computing device's core functionality remains relatively simple while the mediator manages the complexity of authentication and authorized communication.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If USB devices must be authenticated against stored authorized devices, then security is improved, but time for device connection and communication establishment increases

Engineering Contradiction:
Improvedevice authorization controlVSAvoiddevice connection establishment time
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-storing identifying characteristics of authorized USB devices in the mediation module before actual communication occurs. When a USB device connects, the mediator can quickly compare the device's identifying characteristics against the pre-stored authorized list rather than performing complex authentication in real-time, thus reducing connection establishment time while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9081911B2Mediating communication of a universal serial bus device
Publication Date: 2015.07.14 ARCHITECTURE TECH CORP
  • US9081911B2 patent drawing
  • US9081911B2 patent drawing
  • US9081911B2 patent drawing

AI summary

In an example, an apparatus includes a memory storing a hypervisor, where the hypervisor is configured to determine whether one or more universal serial bus (USB) devices in communication with the hypervisor are authorized to communicate with a guest operating system of the hypervisor and, after determining that the one or more USB devices are authorized to communicate with the guest, virtualize the one or more USB devices at the guest operating system and transfer messages between the one or more USB devices and the virtualized USB device.