Cryptographic Equipment Red Black Mode Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The implementation of a 'clear' mode in cryptographic equipment poses a significant security risk due to the potential untimely activation, leading to the disclosure of sensitive information and unavailability of security services, particularly in critical fields like aeronautical and tactical operations where high availability is required.
Innovation Solution
The cryptographic equipment features a cryptographic block and a management device that are physically and logically separate, with autonomous hardware resources, allowing for secure routing of information between interfaces without non-sensitive information passing through the red module, and employing a switching device to control the connection based on chosen modes of operation, ensuring the integrity and security of sensitive information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a clear transmission channel is established between red and black host domains, then the availability of clear mode is improved, but the security of sensitive information deteriorates
Solution Approach 1:
The cryptographic module is segmented into a cryptographic block for sensitive information processing and a separate management device for clear mode control. This physical and logical separation ensures that clear mode operations do not compromise the security of the cryptographic block, resolving the contradiction between availability and security.
Solution Approach 2:
A management device acts as an intermediary between the input interface and the red/black host domains. It routes clear information directly to the black domain without passing through the red domain, preventing unauthorized access to sensitive information while maintaining clear mode availability.
2Ease of operation
If the clear mode is activated, then the ease of operation is improved, but the reliability of security services deteriorates
Solution Approach 1:
The system is divided into independent cryptographic and management functions. The management device can be activated independently without affecting the cryptographic block, allowing clear mode operation while maintaining security services availability through the separate cryptographic pathway.
Solution Approach 2:
The system dynamically changes operational parameters by switching between encrypted and clear modes through the management device. This allows easy activation of clear mode while the cryptographic block remains ready to provide security services when needed, maintaining both ease of operation and reliability.
3Device complexity
If the red module processes non-sensitive information, then the device complexity is reduced, but the security of sensitive information deteriorates
Solution Approach 1:
The management device is segregated from the red module, with dedicated routing paths for clear and sensitive information. This segmentation maintains simple device architecture while preventing sensitive information exposure through the clear mode pathway.
Solution Approach 2:
The management device serves as an intermediary that directs non-sensitive information away from the red module to the black domain. This intermediary function simplifies routing complexity while ensuring sensitive information remains protected within the cryptographic block.
Data Source
Figure 1~2
Figure 3~4
AI summary
The invention relates to cryptographic equipment which includes an input interface, a red module, a cryptographic module, a black module, and an output module. The cryptographic module comprises a cryptographic unit, which interacts with the red module and with the black module, and a management device, which interacts with the input interface and with either the red module or the black module but not with both simultaneously. The cryptographic unit and the management device are physically and logically separate from one another and independent, and have identical protection means capable of protecting the integrity of the management device so as to detect any attempt at tampering.