Confirmation Device Segments Integrity Data for Secure Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for computer-aided inspection and cryptographic confirmation of system integrity often disclose sensitive information, making it challenging to verify the trustworthiness of a system without revealing confidential details, especially in industrial data exchanges.
Innovation Solution
A method involving a confirmation device that records and processes integrity information, calculates an integrity value using measured values and measurement information, and provides summarized second integrity information, which is cryptographically confirmed, allowing for secure and partial disclosure of system state without revealing sensitive details.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If detailed integrity information including measurement information is provided for comprehensive system inspection, then the ability to verify system trustworthiness is improved, but confidential information is disclosed
Solution Approach 1:
The patent segments integrity information into two distinct types: integrity values (cryptographic hashes of measured values) and measurement information (descriptive data about system state). The confirmation device receives both but only processes and outputs the integrity values for verification purposes, leaving measurement information undisclosed. This segmentation allows comprehensive verification while protecting confidential details.
Solution Approach 2:
The patent extracts only the essential verification elements (integrity values calculated from measured values) from the complete integrity information set. The confirmation device processes these extracted integrity values to verify system state without requiring or disclosing the underlying measurement information, thus achieving verification while maintaining confidentiality.
2Measurement precision
If complete integrity information is transmitted and processed, then verification accuracy is improved, but computational time increases
Solution Approach 1:
The patent extracts only the critical integrity values from complete integrity information for processing. The confirmation device focuses computation exclusively on verifying these extracted integrity values against expected system states, rather than processing all measurement information. This extraction approach maintains verification accuracy while significantly reducing computational time and resources required.
3Loss of information
If all measured values and measurement information are disclosed, then system state transparency is improved, but data security deteriorates
Solution Approach 1:
The patent segments information into transparent integrity values (which can be verified) and confidential measurement information (which remains protected). The confirmation device operates on the segmented integrity values to provide verification transparency while the segmented measurement information remains securely undisclosed, thus achieving transparency in verification without compromising data security.
Solution Approach 2:
The integrity values serve as an intermediary between the complete system state and the verification process. Instead of directly disclosing measurement information, the system uses integrity values as a mediator that enables verification of system state without revealing the underlying confidential data, thus maintaining both transparency and security.
Data Source
AI summary
A method for computer-aided testing and confirmation of at least one system state of a first system by a confirmation device, is provided. After the testing of a first item of integrity information, which is provided by the first system, the confirmation device provides a second, combined item of integrity information and confirms the same cryptographically. The second item of integrity information includes at least part of the first item of integrity information and can be transmitted to a second system, in order to confirm the integrity of the first system to the latter. A confirmation device, to a first system, to a second system and to a computer program product in order to carry out the steps of the method is also provided.


