Recently shared in our organization. Comments raised serious concerns about the information security of hardware solutions for USB over IP, which also worries us.
So, let's first clarify the initial conditions.
- A large number of electronic protection keys.
- Access to them is required from various geographical locations.
- We are only considering USB over IP hardware solutions and are trying to secure this solution by implementing additional organizational and technical measures (alternative options are not being considered for now).
- In this article, I will not detail the threats models we are considering (much can be seen in ), but I will briefly highlight two points. We exclude social engineering from the model and illegal actions by the users themselves. We consider the possibilities of unauthorized access to USB devices from any network without having standard credentials.

To ensure the security of access to USB devices, organizational and technical measures have been taken:
1. Organizational security measures.
The managed USB over IP hub is installed in a server cabinet that locks securely. Physical access to it is controlled (access control systems in the room, video surveillance, keys and access rights are held by a strictly limited group of individuals).
All USB devices used in the organization are conditionally divided into 3 groups:
- Critical. Financial digital signatures – used according to banking recommendations (not through USB over IP)
- Important. Digital signatures for marketplaces, services, electronic document management, reporting, etc., several keys for software – used with the managed USB over IP hub.
- Non-critical. Several keys for software, cameras, a number of flash drives and disks containing non-critical information, USB modems – used with the managed USB over IP hub.
2. Technical security measures.
Network access to the managed USB over IP hub is only provided within an isolated subnet. Access to this isolated subnet is granted:
- from the terminal server farm,
- via VPN (certificate and password) to a limited number of computers and laptops, permanent addresses are granted through VPN.
- via VPN tunnels connecting regional offices.
On the fully managed USB over IP hub DistKontrolUSB, the following functions are configured using its native tools:
- Access to USB devices of the USB over IP hub employs encryption (encryption with SSL is enabled on the hub), although this may already be unnecessary.
- Configured 'IP address access restriction for USB devices.' Depending on the IP address, users are granted or denied access to designated USB devices.
- Configured 'USB port access restriction by username and password.' Accordingly, users are assigned rights to access USB devices.
- 'Access restriction to USB devices by username and password' has not been implemented, as all USB keys are permanently connected to the USB over IP hub and are not rearranged from port to port. It makes more sense for us to give users access to the USB port with a device connected to it for an extended period.
- The physical turning on and off of USB ports is done:
- For software and EDS keys — using the task scheduler and assigned tasks of the hub (a number of keys are programmed to turn on at 9:00 and off at 18:00, while others are from 13:00 to 16:00);
- For marketplace keys and certain software – by users with permissions through the WEB interface;
- Cameras, a number of flash drives and disks with non-critical information – are always turned on.
We believe that this organization of access to USB devices ensures their secure use:
- from regional offices (conditionally NET No. 1 …… NET No. N),
- for a limited number of computers and laptops connecting USB devices through the global network,
- for users published on application terminal servers.
In the comments, I would like to hear concrete practical measures that enhance the information security of providing global access to USB devices.
Source: habr.com
