USB Port Control via Software Intermediary Layer

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods are insufficient to prevent or detect the use of unauthorized devices and applications from USB ports, particularly in preventing the exposure of sensitive data and information, as they lack the ability to effectively control types of USB devices and applications accessed on personal computers.

Innovation Solution

A software method that monitors USB ports, detects connected devices, compares them to a user-defined list of authorized devices, and allows or denies access based on security parameters, which can be configured locally or via a central database, to ensure only authorized devices and applications are used.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional methods are used to control USB ports, then device compatibility and ease of operation are maintained, but security reliability and detection capability are insufficient

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidcontrol system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a software intermediary layer that sits between the USB port and connected devices. This software monitors device connections, compares device identifiers against an authorized list, and controls access accordingly. The intermediary approach enhances security without requiring hardware modifications to the USB port itself, resolving the contradiction between improved security and system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary actions by pre-configuring a list of authorized devices and their identifiers before USB devices are connected. When a device is plugged in, the software immediately checks its identifier against the pre-established authorized list. This preliminary preparation enables rapid security verification without complex real-time analysis, improving both security reliability and operational efficiency.

Inventive Principle:
Principle #10Preliminary action

2Object-affected harmful factors

If USB device usage is unrestricted, then ease of operation and device versatility are maintained, but data security and protection of sensitive information deteriorate

Engineering Contradiction:
Improvedata exposure riskVSAvoidUSB device usability
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The USB device control system provides self-service functionality by automatically monitoring device connections, identifying devices through their unique identifiers, and enforcing access control policies without requiring manual user intervention. The software autonomously determines whether a connected device is authorized and either permits or blocks its operation, thereby protecting data security while maintaining ease of operation for authorized devices.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback mechanisms by continuously monitoring USB port status and device identifiers. When an unauthorized device is detected, the system provides feedback by blocking access and can alert users or administrators. This feedback loop ensures that data exposure risks are immediately addressed while maintaining seamless operation for authorized devices, resolving the contradiction between security and usability.

Inventive Principle:
Principle #23Feedback

3Difficulty of detecting and measuring

If comprehensive device monitoring is implemented, then detection capability and security control are improved, but system complexity and processing requirements increase

Engineering Contradiction:
Improvedevice detection capabilityVSAvoidmonitoring system complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The patent extracts the essential identifying characteristics of USB devices (such as device identifiers, serial numbers, or manufacturer codes) and uses only these specific features for authorization verification. Rather than analyzing all possible device attributes, the system focuses on extracting and comparing key identifying information against the authorized list. This extraction approach improves detection capability while minimizing system complexity by avoiding unnecessary analysis of unrelated device characteristics.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8566924B2Method and system for controlling communication ports
Publication Date: 2013.10.22 OL SECURITY LLC
  • US8566924B2 patent drawing
  • US8566924B2 patent drawing
  • US8566924B2 patent drawing

AI summary

A method for limiting devices and controlling the applications executed from USB ports on personal computers (PCs). More specifically, the present invention relates to a method for ensuring that only authorized devices and applications are accessed from USB ports using software and configuration files on the PC. Using the software application stored on the PC storage device in conjunction with functionality performed by a designed security file server, the use of USB applications and devices is limited to authorized applications and devices.