IP Library › Granted Patent US 12,651,081
Granted Patent B2
US 12,651,081 · App. 18/721,239 · Granted Jun 9, 2026

System and method for secure copy-and-paste operations between hosts through a peripheral sharing device

Inventors: Aviv Soffer (Caesarea, IL); David Hirshberg (Caesarea, IL)
Assignee: HIGH SEC LABS LTD.
G06F21/606G06F9/543G06F21/55
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,651,081
App. No.
18/721,239
Granted
Jun 9, 2026
Kind
B2
Abstract

A peripheral sharing device for supporting secure copy-paste operations between hosts comprising: a plurality of copy-emulators and a plurality of paste emulators, configured cach to be connected to a copy-paste driver, wherein cach copy-paste driver is running on one of a plurality of hosts that are connected to the peripheral sharing device, and the copy-paste driver is configured to fetch or store clipboard objects from the clipboard of the corresponding host, a security bridge that is configured to securely pass clipboard objects between pairs of copy emulator and paste emulator. The security bridge performs security operations, such as, enforce unidirectional data transfer of the clipboard object, monitor the clipboard object and enable or disable the copy-paste operation according to a set of security rules; enable or disable the copy-paste operation according to security policy, analyze clipboard object traffic to detect cybersecurity events, locking suspicious peripheral sharing devices, and preventing clipboard object transfer between pairs of copy-paste controllers according to security rules. The copy emulator receives the clipboard object from the copy-paste driver of a first host, transfer the clipboard object to the security bridge and conditioned upon passing the security conditions the security bridge transfer the clipboard object to the paste emulator that further pass the clipboard object to a second computer's copy-paste driver.

Claims (93)

1 . A peripheral sharing device for supporting secure copy-paste operations between hosts, comprising:

a plurality of copy emulators and a plurality of paste emulators, each one of the copy emulators and each one of the paste emulators is configured to be connected to a single copy-paste driver of one of the hosts, wherein each one of the copy-paste drivers is running on one of the plurality of hosts, each one of the hosts is connected to the peripheral sharing device, and each one of the copy-paste drivers is configured to fetch or store clipboard objects from a clipboard of the corresponding host; and

a security bridge that is configured to securely pass the clipboard objects between pairs of one of the copy emulators and one of the paste emulators,

wherein the security bridge performs one or more of

(1) enforcing unidirectional data transfer of the clipboard objects,

(2) monitoring the clipboard objects and enabling or disabling any one of the copy-paste operations according to a security policy,

(3) enabling or disabling only one of the copy-paste operations according to the security policy comprising from at least the identity of source host, the identity of the target host, the type of the clipboard object, time delays and time of day of the copy-paste operation,

(4) modifying the clipboard object to prevent sensitive data leakage,

(5) building a profile of copy-paste operation patterns of users,

(6) analyzing clipboard object traffic to detect cyber-security events,

(7) logging, auditing and archiving copy-paste operations or clipboard object traffic history,

(8) scanning virus existence in the clipboard objects,

(9) sanitizing or removing some information from the clipboard objects,

(10) encrypting and decrypting of the clipboard objects,

(11) locking suspicious peripheral sharing devices, and

(12) preventing clipboard object transfer between pairs of copy-paste controllers according to security rules,

wherein the copy emulator that receives the clipboard object from a source host's copy-paste driver transfers the clipboard object to the security bridge, and conditioned upon passing security conditions, the security bridge transfers the clipboard object to one of the paste emulators that further passes the clipboard object to a target host's copy-paste driver, and

wherein the peripheral sharing device couples the hosts to one or more user's consoles, wherein the user's consoles comprise one or more peripheral devices, wherein the peripheral sharing device enables each one of the users to operate the hosts using a single console, and wherein the peripheral sharing device is a secure peripheral sharing device that isolates communication and data between pairs of one console and one host from all other hosts and all other consoles while preventing any data transfer or communication between hosts and permitting only limited copy-paste operations allowed by the security policy.

2 . The peripheral sharing device of claim 1 , wherein the security bridge further comprises one or more copy controllers and one or more paste controllers, each one of the copy controllers is configured to be connected to one or more copy emulators, and each one of the paste controllers is configured to be connected to one or more paste emulators, wherein the copy controllers are coupled to the paste controller through a security agent to provide one or more pairs of copy-and-paste controllers, and the security bridge is further configured to perform security functions from at least one of or any combination of

(1) enforcing unidirectional communication between the pairs of copy-and-paste controllers,

(2) authenticating the pairs of copy-and-paste controllers,

(3) blocking or filtering out undesired data transmission between the pairs of copy-and-paste controllers,

(4) blocking, locking, neutralizing or stopping the communication between the pairs of copy-and-paste controllers,

(5) encrypting and decrypting the communication between the pairs of copy-and-paste controllers,

(6) logging, auditing or alerting clipboard transfer events,

(7) auditing the clipboard context of clipboard transfer events,

(8) analyzing the context of clipboard transfer events,

(9) preventing data transfer between the pairs of copy-and-paste controllers according to security rules,

(10) preventing signal leakage between different pairs of copy-and-paste controllers,

(11) allowing passage of only specific types of clipboard object types,

(12) scanning for viruses and malicious codes in files/objects clipboards,

(13) isolating the communication between the pairs of copy-and-paste controllers,

(14) allowing only specific copy-and-paste usage, and

(15) using Artificial Intelligence (AI) processing to detect suspicious pattern of copy-paste operations.

3 . The peripheral sharing device of claim 1 , wherein the clipboard object received by the target host is modified version of the clipboard object transferred by the source host.

4 . The peripheral sharing device of claim 1 , wherein the security bridge further comprises an external/remote security agent attached to the peripheral sharing device and the external/remote security agent is a local external device connected to the peripheral sharing device or a remote device or server connected to the peripheral sharing device using a data network comprising from at least an intranet or the Internet.

5 . The peripheral sharing device of claim 1 , wherein the peripheral sharing device is configured to communicate with an external/remote security agent via one or more Ethernet ports.

6 . The peripheral sharing device of claim 4 , wherein communication with the external/remote security agent is performed using Virtual Private Network (VPN) or Internet Protocol Security (IPSEC) tunneling protocols.

7 . The peripheral sharing device of claim 1 , wherein the security bridge comprises a copy controller communicating with the one or more copy emulators and a paste controller communicating with the one or more paste emulators.

8 . The peripheral sharing device of claim 1 , wherein the peripheral sharing device comprises at least one unidirectional enforcing device that enables only copy operations and blocks all paste operations from a particular host.

9 . The peripheral sharing device of claim 1 , wherein the peripheral sharing device comprises at least one unidirectional enforcing device that enables only paste operations and blocks all copy operations from a particular subset of all the hosts.

10 . The peripheral sharing device of claim 1 , wherein the peripheral sharing device comprises one or more memories to store the clipboard objects, and the memories are at least any one of or any combination of: internal memories, add-on memories, external storage devices, volatile memories, non-volatile memories.

11 . The peripheral sharing device of claim 1 , wherein the peripheral sharing device comprises user interface means to trigger and control the copy-paste operations.

12 . The peripheral sharing device of claim 1 , wherein the peripheral sharing device is a secure peripheral sharing device.

13 . The peripheral sharing device of claim 1 , wherein communication between at least one of the copy-paste drivers and at least one of the copy emulators is performed over Universal Serial Bus (USB).

14 . The peripheral sharing device of claim 1 , wherein communication between at least one of the copy-paste drivers and at least one of the paste emulators is performed over Universal Serial Bus (USB).

15 . The peripheral sharing device of claim 1 , wherein a keyboard and mouse device emulator, one of the copy emulators, and one of the paste emulators, share the same Universal Serial Bus (USB) port and enumerate as a plurality of composite Universal Serial Bus (USB) devices.

16 . The peripheral sharing device of claim 1 , wherein the peripheral sharing device further comprises network switches to share data communication of the hosts and the security bridge over one or more external network ports.

17 . The peripheral sharing device of claim 1 , wherein the clipboard objects comprise at least one of the following types: text string, picture, file, and Object Linking and Embedding (OLE) objects.

18 . The peripheral sharing device of claim 1 , wherein the peripheral sharing device adds metadata information to the clipboard objects and wherein the metadata information comprises at least one of or any combination of: Time Of Day (TOD) of the copy operation, copy operation host identification (host ID), Time Of Day (TOD) of the paste operation, and paste operation host identification (host ID).

19 . The peripheral sharing device of claim 1 , wherein the peripheral sharing device comprises a copy-paste User Interface (UI), the copy-paste user interface comprises at least one of or any combination of (1) pushbuttons to trigger the copy-paste operations or steps of the copy-paste operations, and (2) one or more indicators to provide progress and status information to the user regarding the copy-paste operation.

20 . The peripheral sharing device of claim 1 , wherein the peripheral sharing device captures copy-paste triggering commands from a keyboard data stream.

21 . The peripheral sharing device of claim 1 , wherein the peripheral sharing device receives copy-paste triggering commands from the host's copy-paste driver.

22 . The peripheral sharing device of claim 1 , wherein only text string clipboard objects, with length that is less than a predefined maximum length, are allowed to be transferred in the copy-paste operations.

23 . A system for secure copy-paste operations between hosts comprising:

a plurality of hosts; and

a secure copy-paste peripheral sharing device for supporting secure copy-paste operations between hosts,

wherein each host is connected to the secure copy-paste peripheral sharing device and comprises copy-paste driver configured to fetch or store clipboard objects from the clipboard of the host,

wherein the secure copy-paste peripheral sharing device includes

a plurality of copy emulators and a plurality of paste emulators, each one of the copy emulators and each one of the paste emulators is configured to be connected to one of the host's copy-paste drivers, and

a security bridge that is configured to securely pass the clipboard objects between pairs of one of the copy emulators and one of the paste emulators,

wherein the security bridge performs at least one of or any combination of

(1) enforce unidirectional data transfer of the clipboard objects,

(2) monitor the clipboard objects and enable or disable the any one of the copy-paste operations according to a security policy,

(3) enable or disable any one of the copy-paste operations according to the security policy comprising from at least the identity of source host, the identity of the target host, the type of the clipboard object, time delays and time of day of the copy-paste operation,

(4) modify the clipboard object to prevent sensitive data leakage,

(5) build a profile of copy-paste operation patterns of users,

(6) analyze clipboard object traffic to detect cybersecurity events,

(7) log, audit and archive copy-paste operations or clipboard object traffic history,

(8) scan virus existence in the clipboard objects,

(9) sanitize or remove some information from the clipboard objects,

(10) encrypt and decrypt of the clipboard objects,

(11) lock suspicious peripheral sharing devices, and

(12) prevent clipboard object transfer between pairs of copy-paste controllers according to security rules, and

wherein the copy emulator that receives the clipboard object from a source host's copy-paste driver transfer the clipboard object to the security bridge and conditioned upon passing security conditions, the security bridge transfers the clipboard object to one of the paste emulators that further passes the clipboard object to a target host's copy-paste driver, and wherein the secure copy-paste peripheral sharing device couples the hosts to one or more user's consoles, wherein the user's consoles comprise one or more peripheral devices, wherein the peripheral sharing device enables each one of the users to operate the hosts using a single console, and wherein the secure peripheral sharing device isolates communication and data between pairs of one console and one host from all other hosts and all other consoles while preventing any data transfer or communication between hosts and permitting only limited copy-paste operations allowed by the security policy.

24 . A method for performing secure copy-paste operations between hosts through a peripheral sharing device, wherein the peripheral sharing device couples the hosts to one or more user's consoles, wherein the user's consoles comprise one or more peripheral devices, wherein the peripheral sharing device enables each one of the users to operate the hosts using a single console, and wherein the peripheral sharing device is a secure peripheral sharing device that isolates the communication and data between pairs of one console and one host from all other hosts and all other consoles while preventing any data transfer or communication between hosts and permitting only limited copy-paste operations allowed by a security policy, the method comprising the steps of:

receiving a clipboard object from a source host;

transferring the clipboard to a security bridge;

receiving the clipboard from the security bridge; and

sending the clipboard to the target host,

wherein the security bridge performs at least one of or any combination of

(1) enforcing unidirectional data transfer of the clipboard object,

(2) monitoring the clipboard object and enabling or disabling the copy-paste operation according to the security policy or a set of security rules,

(3) enabling or disabling the copy-paste operation according to the security policy comprising from at least the identity of source host, the identity of the target host, the type of the clipboard object, time delays and time of day of the copy-paste operation,

(4) modifying the clipboard object to prevent sensitive data leakage,

(5) building a profile of copy-paste operation patterns of users,

(6) analyzing clipboard object traffic to detect cyber-security events,

(7) logging, auditing and archiving copy-paste operation or clipboard object traffic history,

(8) scanning virus existence in clipboard object,

(9) sanitizing or removing some information from clipboard objects,

(10) encrypting and decrypting of clipboard objects,

(11) locking suspicious peripheral sharing devices, and

(12) preventing clipboard object transfer between pairs of hosts according to security rules.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 18, 2024
From: HIRSCHBERG, DAVID; SOFFER, AVIV
To: HIGH SEC LABS LTD.
Reel/Frame 067752/0308 →
Continuity (2)
Provisional Application 63299031 · Jan 13, 2022
Related Publication 20250053669A1 · Feb 13, 2025
References Cited (4)
US 20140113550A1 · Li · 2014 [cited by examiner]
US 20140267339A1 · Dowd · 2014 [cited by examiner]
US 20150326575A1 · Ramirez Flores · 2015 [cited by examiner]
US 20180039385A1 · Worley · 2018 [cited by examiner]