Selective USB Encryption via Policy Server
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Thin clients used in USB networks face challenges in protecting sensitive information such as user names and passwords, as they are transmitted over devices that also handle non-sensitive data, leading to potential security risks and inefficiencies in resource usage.
Innovation Solution
Implementing a system that uses a thin network protocol to tunnel driver-level messages, including a packet encoder and decoder, assistance engine, message analyzer, and security engine, which allows for selective encryption of sensitive USB transfers, reducing resource usage and enhancing security by parsing data locally and encrypting only necessary information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all USB data transfers are encrypted to protect sensitive information, then security is improved, but resource consumption and network latency increase
Solution Approach 1:
The patent segments USB data transfers into sensitive and non-sensitive categories, applying encryption only to sensitive data (e.g., credentials, personal information) while leaving non-sensitive data (e.g., printer commands, file transfers) unencrypted. This selective approach reduces computational overhead and resource consumption while maintaining security for critical information.
Solution Approach 2:
The patent implements different security policies for different USB devices and data types based on their sensitivity requirements. High-security devices (e.g., authentication tokens) receive full encryption, while low-security devices (e.g., printers) use minimal or no encryption, optimizing resource usage according to local security needs.
2Reliability
If all USB data transfers are encrypted to protect sensitive information, then security is improved, but network latency increases
Solution Approach 1:
The patent divides USB data transfers into sensitive and non-sensitive segments, applying encryption only where necessary. This reduces the total volume of encrypted data, thereby reducing processing time and network latency while maintaining security for sensitive information.
Solution Approach 2:
The patent applies encryption with varying intensity based on data sensitivity - full encryption for highly sensitive data, partial or no encryption for less sensitive data. This localized approach minimizes latency impact while preserving security where critical.
3Use of energy by moving object
If selective encryption is implemented to reduce resource consumption, then resource efficiency is improved, but system complexity increases
Solution Approach 1:
The patent introduces a USB policy server as an intermediary that centralizes the logic for determining which data requires encryption. The local USB host controller communicates with the policy server to obtain encryption decisions, simplifying the local device complexity while enabling sophisticated selective encryption through centralized policy management.
4Adaptability or versatility
If USB devices transmit all data over the network to a thin client, then device functionality is improved, but security risks increase due to transmission of sensitive information
Solution Approach 1:
The patent segments USB data transmissions into sensitive and non-sensitive categories, applying encryption to sensitive data while allowing unencrypted transmission of non-sensitive data. This maintains full device functionality while mitigating security risks by protecting only the information that requires protection.
Solution Approach 2:
The patent implements location-aware security policies where data sensitivity determines encryption requirements. Sensitive data transmitted to thin clients is encrypted, while non-sensitive data is transmitted without encryption, maintaining versatility while reducing security risks through localized security measures.
Data Source
AI summary
A method to interact with a remote USB device is disclosed. An identifying message is received from a remote client associated with the remote USB device. The remote USB device is identified based at least in part on the identifying message from the remote client. A security policy is determined for the remote USB device. A policy message is transmitted to the remote client for selectively implementing the security policy of the remote USB device. A method to interact with a local USB device is disclosed. An identifying message is determined by performing a host controller service for the local USB device. The identifying message is transmitted to a server. A policy message is received from the server for selectively implementing a security policy on the local USB device. The security policy is regarded and configuring the host controller service.


