Selective USB Encryption via Policy Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Thin clients used in USB networks face challenges in protecting sensitive information such as user names and passwords, as they are transmitted over devices that also handle non-sensitive data, leading to potential security risks and inefficiencies in resource usage.

Innovation Solution

Implementing a system that uses a thin network protocol to tunnel driver-level messages, including a packet encoder and decoder, assistance engine, message analyzer, and security engine, which allows for selective encryption of sensitive USB transfers, reducing resource usage and enhancing security by parsing data locally and encrypting only necessary information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all USB data transfers are encrypted to protect sensitive information, then security is improved, but resource consumption and network latency increase

Engineering Contradiction:
ImprovesecurityVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent segments USB data transfers into sensitive and non-sensitive categories, applying encryption only to sensitive data (e.g., credentials, personal information) while leaving non-sensitive data (e.g., printer commands, file transfers) unencrypted. This selective approach reduces computational overhead and resource consumption while maintaining security for critical information.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements different security policies for different USB devices and data types based on their sensitivity requirements. High-security devices (e.g., authentication tokens) receive full encryption, while low-security devices (e.g., printers) use minimal or no encryption, optimizing resource usage according to local security needs.

Inventive Principle:
Principle #3Local quality

2Reliability

If all USB data transfers are encrypted to protect sensitive information, then security is improved, but network latency increases

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent divides USB data transfers into sensitive and non-sensitive segments, applying encryption only where necessary. This reduces the total volume of encrypted data, thereby reducing processing time and network latency while maintaining security for sensitive information.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies encryption with varying intensity based on data sensitivity - full encryption for highly sensitive data, partial or no encryption for less sensitive data. This localized approach minimizes latency impact while preserving security where critical.

Inventive Principle:
Principle #3Local quality

3Use of energy by moving object

If selective encryption is implemented to reduce resource consumption, then resource efficiency is improved, but system complexity increases

Engineering Contradiction:
Improveresource efficiencyVSAvoidsystem complexity
Core Design Contradiction:
Use of energy by moving objectVSDevice complexity

Solution Approach 1:

The patent introduces a USB policy server as an intermediary that centralizes the logic for determining which data requires encryption. The local USB host controller communicates with the policy server to obtain encryption decisions, simplifying the local device complexity while enabling sophisticated selective encryption through centralized policy management.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If USB devices transmit all data over the network to a thin client, then device functionality is improved, but security risks increase due to transmission of sensitive information

Engineering Contradiction:
Improvedevice functionalityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments USB data transmissions into sensitive and non-sensitive categories, applying encryption to sensitive data while allowing unencrypted transmission of non-sensitive data. This maintains full device functionality while mitigating security risks by protecting only the information that requires protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements location-aware security policies where data sensitivity determines encryption requirements. Sensitive data transmitted to thin clients is encrypted, while non-sensitive data is transmitted without encryption, maintaining versatility while reducing security risks through localized security measures.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS8984580B2Universal serial bus selective encryption
Publication Date: 2015.03.17 SAMSUNG ELECTRONICS CO LTD
  • US8984580B2 patent drawing
  • US8984580B2 patent drawing
  • US8984580B2 patent drawing

AI summary

A method to interact with a remote USB device is disclosed. An identifying message is received from a remote client associated with the remote USB device. The remote USB device is identified based at least in part on the identifying message from the remote client. A security policy is determined for the remote USB device. A policy message is transmitted to the remote client for selectively implementing the security policy of the remote USB device. A method to interact with a local USB device is disclosed. An identifying message is determined by performing a host controller service for the local USB device. The identifying message is transmitted to a server. A policy message is received from the server for selectively implementing a security policy on the local USB device. The security policy is regarded and configuring the host controller service.