Data Processing System Dynamic Security Level Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current secure elements offer high security but low performance, making it complex and costly to achieve higher performance levels, and there is a need for flexible trade-offs between security and performance, especially in applications requiring dynamic adjustments.
Innovation Solution
A data processing system with multiple security levels, where key material is tagged with a minimum security level for storage and processing, allowing temporary movement to lower security levels for increased performance without compromising overall security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cryptographic operations are performed inside a secure element, then security level is high, but performance level is low
Solution Approach 1:
The system dynamically adjusts the security level at runtime by temporarily moving key material between secure element and non-secure memory based on performance requirements. This allows the system to switch between high-security mode (operations inside secure element) and high-performance mode (operations using temporarily exported keys), resolving the static contradiction between security and performance.
Solution Approach 2:
The patent introduces key material exportation as an intermediary mechanism that allows controlled transfer of cryptographic keys between secure and non-secure environments. This intermediary process enables performance-critical operations to occur outside the secure element while maintaining security through controlled access and runtime validation, thus bridging the gap between security and performance requirements.
2Productivity
If multiple secure elements are used in parallel to achieve high performance, then performance level increases, but device complexity and cost increase
Solution Approach 1:
The system segments cryptographic operations into two types: security-critical operations that remain inside the secure element and performance-critical operations that can use temporarily exported keys in non-secure memory. This segmentation allows a single secure element to handle both security and performance requirements without needing multiple parallel secure elements, thereby reducing system complexity and cost.
Solution Approach 2:
The patent changes the security parameter (security level) dynamically at runtime rather than maintaining constant high security. By allowing temporary reduction of security level (through controlled key export) when performance is critical, the system achieves high performance with a single secure element instead of requiring multiple parallel secure elements, thus reducing complexity.
3Reliability
If key material is stored at high security level, then security is maintained, but access speed and performance are limited
Solution Approach 1:
The system performs preliminary action by temporarily exporting key material from secure memory to non-secure memory before performance-critical operations. This advance preparation allows subsequent cryptographic operations to execute faster using the temporarily available keys, reducing access time while maintaining overall security through controlled exportation and runtime monitoring.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A data processing system is conceived, which comprises at least two security levels and key material stored at a specific one of said security levels, wherein the key material is tagged with a minimum security level at which the key material may be stored.