Cryptographic Agility via Multi-Mode Switching in Computing Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cryptographic techniques in computer systems degrade over time due to factors like software update mistakes, advanced attacks, and cryptographic counter-measures, leading to security vulnerabilities, especially in devices that cannot be updated.
Innovation Solution
Implementing a system with multiple cryptographic operating modes allows devices to switch to more secure modes when security vulnerabilities arise, either by design or through updates, thereby maintaining security over time.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If a single cryptographic operating mode is used in a computing device, then the device structure is simple and ease of manufacture is improved, but the device cannot adapt to changing security conditions and cryptographic agility deteriorates
Solution Approach 1:
The computing device is designed to support multiple cryptographic operating modes (first, second, and third modes with different security profiles) within a single device architecture. The processor can execute different sets of cryptographic instructions corresponding to different security requirements, enabling the device to universally handle various cryptographic protocols and security levels without requiring separate hardware for each mode.
Solution Approach 2:
The cryptographic operating mode of the device is made dynamic rather than static. The processor can switch between different cryptographic operating modes based on security requirements, threat levels, or operational context. This dynamic capability allows the device to adapt its cryptographic behavior in real-time, transitioning from a first cryptographic operating mode to a second cryptographic operating mode when needed.
2Reliability
If cryptographic tools are updated frequently to counter new attacks, then security is improved, but the frequency of updates increases system maintenance complexity and loss of time
Solution Approach 1:
The device is pre-configured with multiple cryptographic operating modes and the necessary cryptographic instructions for each mode before deployment. By having multiple cryptographic toolsets already available in the device, there is no need to perform updates or installations when new security threats emerge. The system can immediately switch to an appropriate pre-prepared cryptographic mode, eliminating update downtime and maintenance interruptions.
3Adaptability or versatility
If multiple cryptographic operating modes are implemented, then cryptographic agility and adaptability are improved, but device complexity and manufacturing difficulty increase
Solution Approach 1:
The cryptographic functionality is segmented into distinct, modular sets of cryptographic instructions, each corresponding to a specific cryptographic operating mode. The processor can selectively execute different segments (first set, second set, or third set of cryptographic instructions) based on the required security profile. This segmentation allows complex cryptographic capabilities to be organized in manageable, independent modules that can be executed without interfering with each other.
4Stability of the object's composition
If cryptographic tools are not updated, then device stability and manufacturing simplicity are maintained, but security vulnerabilities accumulate over time
Solution Approach 1:
The system changes the cryptographic parameters (specifically, the cryptographic operating mode and associated cryptographic instructions) in response to security conditions, while maintaining the overall device architecture and stability. By transitioning between different cryptographic operating modes with different security profiles, the system adapts its security parameters without requiring physical device changes or structural modifications, thus maintaining stability while improving security.
Data Source
AI summary
Provided are computer systems which demonstrate improved cryptographic agility via inclusion of multiple cryptographic operating modes. In one example, one or more devices included within a computing system are designed to include multiple cryptographic operating modes from the outset (e.g., prior to deployment of the system, “by design”). Additionally or alternatively, one or more devices included within the computing system (e.g., a gateway computing device) can be updated to include the multiple cryptographic operating modes after deployment of the system (e.g., in an “ad hoc” fashion). A system can also include both device(s) that have multiple operating modes by design and device(s) that have multiple operating modes introduced in an ad hoc fashion. Inclusion of the multiple cryptographic operating modes can serve to enhance the security of at least the communications of the computing system that are performed by or follow the updated device(s).


