USB Host Security Control Module for Unauthorized Device Blocking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The USB protocol lacks security features to prevent malicious activity from unauthorized USB devices, allowing potential access, interference, or data breaches without authentication.

Innovation Solution

The implementation of a security control module within the USB protocol stack, including a security control application interface, run-time device identification module, and admission control module, which examines USB device descriptors, performs analysis, and provides user notification or automatic blocking of suspicious devices, utilizing a whitelist and blacklist database for authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If USB protocol allows any device to communicate without authentication, then ease of operation is improved, but security is worsened

Engineering Contradiction:
Improveease of USB device connectionVSAvoidmalicious activity from unauthorized devices
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary authentication actions before allowing USB device communication. The host system performs device identification, descriptor examination, and authentication checks before establishing communication, preventing unauthorized devices from accessing the system while maintaining ease of use for legitimate devices

Inventive Principle:
Principle #10Preliminary action

2Object-affected harmful factors

If USB protocol includes authentication and security features, then security is improved, but device complexity is worsened

Engineering Contradiction:
Improveprotection from malicious activityVSAvoidcomplexity of USB protocol stack
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent segments the USB protocol stack into distinct functional layers: standard USB protocol handling, device identification module, authentication module, and security control module. This segmentation allows security features to be added without fundamentally redesigning the entire protocol stack, managing complexity through modular architecture

Inventive Principle:
Principle #1Segmentation

3Object-affected harmful factors

If USB protocol examines device descriptors and performs security analysis, then security is improved, but loss of time is worsened

Engineering Contradiction:
Improvedetection of suspicious activityVSAvoidtime for device authentication
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The patent performs preliminary device identification and descriptor examination during the USB device enumeration process, which occurs anyway before full communication begins. By integrating security checks into existing USB protocol steps rather than adding separate authentication phases, the system minimizes additional time requirements

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9021597B2Security arrangements for extended USB protocol stack of a USB host system
Publication Date: 2015.04.28 MCCI CORP
  • US9021597B2 patent drawing
  • US9021597B2 patent drawing
  • US9021597B2 patent drawing

AI summary

Security arrangements for a universal serial bus (USB) protocol stack of a USB host system are provided. The security arrangements prevent an unauthorized or suspicious USB device from communicating with the host system, detect suspicious activity originating from a device which is already communicating with the host system and may provide notification to a user.