USB Security Device with Uni-Directional Data Flow Limiter

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

USB connections in computer systems are vulnerable to attacks, allowing unauthorized data injection and exfiltration, which can lead to system compromise and data theft, especially in critical infrastructure and retail environments.

Innovation Solution

A system with uni-directional data flow limitations and authentication mechanisms, using a Protection Device with CPUs acting as virtual peripherals and computers, and behavioral analysis to ensure secure communication between computer systems and peripherals, preventing data leakage and detecting malicious devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If USB connections are made open and generic for peripheral compatibility, then ease of operation and adaptability are improved, but vulnerability to attacks and data leakage increases

Engineering Contradiction:
Improveperipheral compatibilityVSAvoidvulnerability to attacks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a USB security device as an intermediary component between the computer system and peripheral devices. This device includes a controller that intercepts and monitors all USB communications, implementing authentication mechanisms and data flow control to prevent attacks while maintaining USB compatibility. The intermediary device validates peripheral authenticity and controls data injection/exfiltration without requiring changes to the open USB standard itself.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If USB data flow is unrestricted for device functionality, then ease of operation is improved, but data leakage and system compromise increase

Engineering Contradiction:
Improvedevice functionalityVSAvoiddata leakage
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The USB security device implements feedback mechanisms by continuously monitoring USB data traffic and comparing it against security policies and authentication credentials. The controller analyzes data flow patterns, device identifiers, and communication protocols in real-time, providing feedback control that allows legitimate device functionality while blocking suspicious data exfiltration attempts. This feedback loop enables dynamic security enforcement without disrupting normal USB operations.

Inventive Principle:
Principle #23Feedback

3Reliability

If authentication mechanisms are implemented for USB devices, then reliability and security are improved, but device complexity increases

Engineering Contradiction:
Improvesystem securityVSAvoidUSB connection complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts authentication and security control functions from the main computer system into a dedicated USB security device. This separate unit contains the authentication logic, credential storage, and data flow control mechanisms, isolating complexity from the host system. The security device presents a simple authenticated interface to the computer while handling all complex security operations independently, including device verification, encryption key management, and attack prevention.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11250132B2System, method and computer program product for protecting a computer system from attacks
Publication Date: 2022.02.15 CYBER SEPIO SYST LTD
  • US11250132B2 patent drawing
  • US11250132B2 patent drawing
  • US11250132B2 patent drawing

AI summary

A system for protecting a computer system interfacing with peripheral elements via a generic port associated with an open standard interface, the system comprising at least one protection device configured for installation between the computer system and its peripheral element/s and including a pair of computer-peripheral interfaces and a uni-directional data flow limiter (e.g. Uni-directional buffer) intermediate the computer-peripheral interfaces.