USB Watchdog Device for Dynamic Peripheral Connection Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The flexibility of dynamic connection-making mechanisms in computer systems, such as USB hot-plug protocols, creates security vulnerabilities by allowing malicious devices to deceive the system into granting excessive permissions, enabling unauthorized access and potential breaches.

Innovation Solution

Implementing an automated watchdog device coupled to every USB socket and dynamic connection-making mechanism to enforce local permissions and rules, limiting access based on device type, location, time, and context, thereby restricting malicious device interactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If automated plug-and-play protocol is implemented for USB devices, then ease of operation is improved, but security vulnerability increases

Engineering Contradiction:
Improveease of operationVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary authorization system that sits between the USB device and the host system. This intermediary layer intercepts device connection events, verifies authorization tokens, and mediates permission granting. The intermediary prevents malicious devices from directly communicating with the host system, thereby maintaining ease of operation for legitimate devices while blocking security threats.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary authorization verification before granting full system access. When a USB device connects, the system first performs preliminary checks including device identification, token validation, and permission assessment before allowing the device to operate. This preliminary action prevents unauthorized devices from establishing harmful connections while maintaining smooth operation for authorized devices.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If device permissions are granted based on self-identification, then adaptability is improved, but reliability decreases

Engineering Contradiction:
ImproveadaptabilityVSAvoidreliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements a feedback mechanism where the system verifies device claims through multiple channels. When a device identifies itself as a specific type (e.g., keyboard, storage), the system provides feedback by requesting verification tokens or performing consistency checks. The device must prove its identity through cryptographic verification or behavioral validation, ensuring that self-identification is accurate and trustworthy while maintaining system adaptability.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent applies preliminary anti-action by preemptively validating device identities before granting permissions. Instead of trusting device self-identification, the system actively verifies claims through authorization tokens, digital signatures, or challenge-response protocols. This preliminary verification prevents deception by malicious devices while allowing legitimate devices to operate with appropriate permissions.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS10089261B2Discriminating dynamic connection of disconnectable peripherals
Publication Date: 2018.10.02 CA TECH INC
  • US10089261B2 patent drawing
  • US10089261B2 patent drawing
  • US10089261B2 patent drawing

AI summary

An enterprise wide data processing system includes at least one watchdog unit and/or software service that is configured to automatically detect an attempt to connect a dynamically connectable and disconnectable peripheral (DCP) such as a USB stick to a watchdog-watched Dynamic Connection-Making Mechanism (DCMM) of the system. The watchdog unit and/or software service is further configured to automatically determine if a type of the attempted connection is in accordance with at least one of a local list of connection permissions and connection rules, and if not to prevent an operatively effective connection to be actually made by way of the watchdog-watched DCMM. The system further includes a remotely modifiable storage storing the at least one of the local list of connection permissions and connection rules.