Source Data Integrity Signatures Using Multi-EDAC Remainders

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional error detection and correction techniques are inadequate in protecting against malicious attacks and cyber threats in mission- and safety-critical systems, particularly in outsourced system development and data delivery, as they fail to detect and counter deliberate corruption of systems and data.

Innovation Solution

A method involving transforming source data, distorting it with a specific function, and passing it through multiple Error Detection and Correction (EDAC) algorithms to produce remainders that are attached to the data, enhancing the ability to detect intentional alterations and providing a fortified digital signature resistant to tampering.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional EDAC techniques are used, then random errors can be detected and corrected, but malicious attacks and deliberate corruption cannot be detected

Engineering Contradiction:
Improveerror detection capabilityVSAvoidvulnerability to cyber attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent divides the protection mechanism into multiple independent EDAC algorithms working in parallel. Each algorithm processes the data independently and produces its own remainder, creating segmented protection layers that collectively detect both random errors and malicious attacks that single algorithms would miss

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent combines multiple EDAC algorithms (different coding schemes) to create a composite protection system. This composite approach leverages the strengths of different algorithms to provide defense against diverse threats including both random errors and intelligent cyber attacks

Inventive Principle:
Principle #40Composite materials

2Measurement precision

If digital signatures are used to verify firmware, then source identification is improved, but the known value can be easily modified to provide a match

Engineering Contradiction:
Improvesource identification accuracyVSAvoidtamper resistance
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The verification process is segmented into multiple independent EDAC algorithm checks. Instead of relying on a single digital signature that can be forged, the system uses multiple remainder calculations from different algorithms, making it computationally infeasible for attackers to create matching remainders across all algorithms simultaneously

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces remainders from multiple EDAC algorithms as intermediary verification elements. These remainders act as mediators between the firmware and the verification process, providing an additional layer of authentication that is much harder to compromise than traditional digital signatures

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If additional security algorithms are added to address malicious attacks, then protection is improved, but timing requirements may not be met

Engineering Contradiction:
Improveprotection against cyber attacksVSAvoidprocessing speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent performs all EDAC remainder calculations during the firmware build process rather than at runtime. This preliminary action ensures that security verification is completed before deployment, eliminating any impact on real-time system performance and boot timing requirements

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8769373B2Method of identifying and protecting the integrity of a set of source data
Publication Date: 2014.07.01 LRDC SYST
  • US8769373B2 patent drawing
  • US8769373B2 patent drawing
  • US8769373B2 patent drawing

AI summary

A method of identifying and protecting the integrity of a set of source data which produces and combines an identification signature with a detection and correction remainder and extends the existing capability of some information assurance methods.