Data Processing System Dynamic Security Level Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current secure elements offer high security but low performance, making it complex and costly to achieve higher performance levels, and there is a need for flexible trade-offs between security and performance, especially in applications requiring dynamic adjustments.

Innovation Solution

A data processing system with multiple security levels, where key material is tagged with a minimum security level for storage and processing, allowing temporary movement to lower security levels for increased performance without compromising overall security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic operations are performed inside a secure element, then security level is high, but performance level is low

Engineering Contradiction:
Improvesecurity levelVSAvoidperformance level
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system dynamically adjusts the security level at runtime by temporarily moving key material between secure element and non-secure memory based on performance requirements. This allows the system to switch between high-security mode (operations inside secure element) and high-performance mode (operations using temporarily exported keys), resolving the static contradiction between security and performance.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces key material exportation as an intermediary mechanism that allows controlled transfer of cryptographic keys between secure and non-secure environments. This intermediary process enables performance-critical operations to occur outside the secure element while maintaining security through controlled access and runtime validation, thus bridging the gap between security and performance requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If multiple secure elements are used in parallel to achieve high performance, then performance level increases, but device complexity and cost increase

Engineering Contradiction:
Improveperformance levelVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system segments cryptographic operations into two types: security-critical operations that remain inside the secure element and performance-critical operations that can use temporarily exported keys in non-secure memory. This segmentation allows a single secure element to handle both security and performance requirements without needing multiple parallel secure elements, thereby reducing system complexity and cost.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the security parameter (security level) dynamically at runtime rather than maintaining constant high security. By allowing temporary reduction of security level (through controlled key export) when performance is critical, the system achieves high performance with a single secure element instead of requiring multiple parallel secure elements, thus reducing complexity.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If key material is stored at high security level, then security is maintained, but access speed and performance are limited

Engineering Contradiction:
Improvesecurity levelVSAvoidaccess time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary action by temporarily exporting key material from secure memory to non-secure memory before performance-critical operations. This advance preparation allows subsequent cryptographic operations to execute faster using the temporarily available keys, reducing access time while maintaining overall security through controlled exportation and runtime monitoring.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2819057B1Data processing system, method of initializing a data processing system, and computer program product
Publication Date: 2017.08.09 NXP BV
  • EP2819057B1 patent drawingFigure 1
  • EP2819057B1 patent drawingFigure 2
  • EP2819057B1 patent drawingFigure 3

AI summary

A data processing system is conceived, which comprises at least two security levels and key material stored at a specific one of said security levels, wherein the key material is tagged with a minimum security level at which the key material may be stored.