Intelligent Cryptographic Module Online Reconfiguration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for an intelligent electronic cryptographic module that can selectively encrypt, decrypt, and securely transmit messages between an enterprise server and intelligent electronic devices, while allowing for online reconfiguration without interrupting normal functions or services, and supporting mixed-mode transmission to optimize security and efficiency.

Innovation Solution

The module includes a cryptography chip and a processor that enables online reconfiguration and mixed-mode transmission, using authentication means like digital certificates and keys, and can function as both a cryptographic module and a remote terminal unit, allowing for secure communication and efficient data transmission without interrupting services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If selective encryption and mixed-mode transmission are implemented, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The cryptographic module segments encryption operations into different modes (encrypt/decrypt/pass-through) that can be selectively applied to different messages based on source, destination, or message type, allowing complex security requirements to be managed through modular configuration rather than monolithic processing logic

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The module dynamically switches between encryption and pass-through modes based on real-time configuration parameters, enabling adaptive security where the level of encryption is adjusted according to the specific communication needs without requiring separate hardware for each mode

Inventive Principle:
Principle #15Dynamics

2Adaptability or versatility

If online reconfiguration is enabled, then adaptability is improved, but system stability worsens

Engineering Contradiction:
ImproveadaptabilityVSAvoidsystem stability
Core Design Contradiction:
Adaptability or versatilityVSStability of the object's composition

Solution Approach 1:

Configuration changes are prepared and validated before being applied to the running cryptographic module, allowing reconfiguration without service interruption while maintaining system stability through pre-validation of configuration parameters

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A configuration interface acts as an intermediary between the control system and the cryptographic module, buffering configuration changes and managing the transition state to ensure stable operation during reconfiguration events

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If mixed-mode transmission is implemented, then bandwidth efficiency is improved, but encryption reliability worsens

Engineering Contradiction:
Improvebandwidth efficiencyVSAvoidencryption reliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

Different encryption treatments are applied locally to different messages or data streams based on their specific requirements, allowing critical data to receive full encryption while non-critical data uses pass-through mode, optimizing both security and bandwidth efficiency

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS7673338B1Intelligent electronic cryptographic module
Publication Date: 2010.03.02 DJ OSBURN MANAGEMENT LLC
  • US7673338B1 patent drawing
  • US7673338B1 patent drawing
  • US7673338B1 patent drawing

AI summary

An intelligent electronic cryptographic module comprising a processor in communication with data storage, a cryptography chip for encrypting and decrypting messages and responses, at least one server-side port for receiving and transmitting encrypted and non-encrypted messages and responses between the intelligent electronic cryptographic module and an enterprise server, and at least one non-encrypted port for receiving and transmitting decrypted and non-encrypted messages and responses between the intelligent electronic cryptographic module and at least one intelligent electronic device. The data storage comprises computer instructions for instructing the processor to select a protocol module and telemetry method, authenticate the enterprise server and intelligent electronic cryptographic module, encrypt and decrypt messages and responses using the cryptography chip, and transmit and receive messages and responses.