USB Protection Device String Descriptor Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Modern communication devices are vulnerable to malicious USB attacks, such as BadUSB, which can reprogram USB devices to propagate malware, and existing techniques lack effective proof of hardware filtering.
Innovation Solution
A method involving a protection device inserted between the communication device and accessory device via a USB link, which memorizes the highest value of string descriptor indexes, sends a request for a string descriptor with a value higher than the highest index, and authenticates the protection device using cryptographic functions or one-time passwords, ensuring the presence of a known hardware filtering solution.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If USB devices are made highly portable and universally compatible, then ease of operation and adaptability improve, but vulnerability to malicious attacks increases
Solution Approach 1:
The patent introduces a protection device as an intermediary component inserted between the USB host and USB accessory. This protection device intercepts and filters USB communications, preventing malicious devices from directly accessing the host while allowing legitimate devices to communicate normally. The intermediary validates each USB device through string descriptor requests, creating a security barrier that maintains universal compatibility while blocking attacks.
Solution Approach 2:
The protection device performs preliminary validation actions before allowing USB device communication. By sending string descriptor requests with indexes higher than the highest value in the USB Device Descriptor during the initial enumeration phase, the system proactively identifies and blocks malicious devices before they can execute attacks, rather than reacting to attacks after they occur.
2Ease of operation
If USB protocol compatibility is maintained for universal device support, then ease of operation improves, but ability to detect and prove hardware filtering decreases
Solution Approach 1:
The patent modifies the USB communication protocol by introducing special string descriptor requests with indexes higher than the highest value in the USB Device Descriptor. These unusual requests act as 'color changes' or markers that differentiate protected communications from standard USB traffic, providing detectable proof that hardware filtering is active while maintaining overall USB protocol compatibility for legitimate devices.
3Reliability
If comprehensive USB security validation is implemented, then reliability improves, but device complexity increases
Solution Approach 1:
The protection device is designed to perform multiple functions within a single unified component. It simultaneously filters USB devices, validates string descriptors, intercepts malicious communications, and maintains USB protocol compatibility. This multi-functionality reduces the need for separate security components and simplifies the overall system architecture while providing comprehensive USB attack protection.
Data Source
AI summary
For ensuring a universal serial bus, USB, attack protection between a communication device (CD) and an accessory device (AD), a protection device (PD) being inserted between the communication device (CD) and the accessory device (AD) through a USB link, the communication device (CD): memorizes the highest value (HV) of indexes of string descriptor found in a USB Device Descriptor received from the accessory device (AD), sends a request (Req) for a string descriptor to the accessory device (AD) with a value (Val1) of index higher than said highest value (HV), receives a response (Res) generated and sent from the protection device (PD), the response containing an identifier (Id P) of the protection device validates the presence of the protection device (PD) if the identifier (Id P) is found in a database.

