Anti-Tampering Device for Cryptographic Key Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in ensuring the physical security of cryptographic keys and data in weapon systems deployed in high-risk areas, requiring secure and remote management to prevent unauthorized access and ensure timely erasure of critical information in case of loss of control.

Innovation Solution

A client/server architecture-based anti-tampering device with Hardware Security Module (HSM) and Secure Elements for managing cryptographic keys, combined with anti-tampering sensors and a system policy management engine, allowing remote and centralized management of cryptographic keys and data erasure in both software and hardware modes, with optional external pin activation for hardware erasure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If anti-tampering sensors are activated to detect physical intrusion attempts, then security protection is improved, but the risk of involuntary data erasure during authorized maintenance operations increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidmaintenance operations
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

A server acts as an intermediary between maintenance operators and the anti-tampering sensors. The server receives sensor data, authenticates operator credentials, and decides whether to allow maintenance operations or trigger erasure. This mediator resolves the contradiction by enabling authorized maintenance while maintaining security protection through centralized authentication and control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If centralized server management is implemented for key erasure control, then remote management capability is improved, but system independence and operational autonomy are worsened

Engineering Contradiction:
Improveremote management capabilityVSAvoidsystem independence
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system is segmented into a centralized server for management functions and autonomous client devices for local operations. Each client contains local authentication credentials and can independently verify operator authorization without continuous server communication. This segmentation enables both remote management through the server and system independence at the client level.

Inventive Principle:
Principle #1Segmentation

3Reliability

If cryptographic keys are stored securely in hardware modules, then security protection is improved, but the ability to remotely erase keys is worsened

Engineering Contradiction:
Improvecryptographic key securityVSAvoidremote key erasure
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The hardware security module is designed to self-destruct or erase its cryptographic keys when it receives an authenticated erasure command. The module autonomously executes the key erasure operation without requiring external physical access or complex external erasure mechanisms. This self-service capability enables secure remote key erasure while maintaining the security protection of the hardware module.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP4198796A1An electronic system for the physical protection of a computer system and the protection of its cryptographic keys
Publication Date: 2023.06.21 MBDA ITAL
  • EP4198796A1 patent drawingFigure 1
  • EP4198796A1 patent drawingFigure 2
  • EP4198796A1 patent drawingFigure 3

AI summary

The present invention relates to an electronic system which mainly ensures the physical security of a complex computer system and the security of the cryptographic keys thereof. The device allows operating in operation environments with stringent environmental features, typical of military systems deployed in the operation scene. The device further allows implementing configurable policies which can best respond to the level of customization required for the operation context in which there is a computer system, whereby distinct reactions are possible (either invasive reactions, i.e., purge, physical erasing, or only informative reactions, i.e., logs and diagnostic visual alarms on screen and/or through LED lights) following the detection of an unauthorized attempted access (tamper detection) to the protected platform. The device according to the invention implements a client-server architecture, sharing the same electronic board which can be customized as a client or server, by means of a configuration at startup, ensuring a cost optimization of development, production and logistics management of spare parts.