Data Security System Using Monotonic Counter Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data security systems face challenges in simultaneously protecting against data replay attacks and modifications caused by sudden service interruptions, as conventional methods for preventing replay and handling data alterations are often incompatible.

Innovation Solution

A data security system that incorporates a monotonic counter, a computing entity, and a physical data medium with secure data blocks and authentication codes to ensure data authenticity and integrity, including a first master block with the last monotonic counter value, an identifier, and authentication codes, along with a replica master block, to prevent unauthorized access and data corruption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data recovery is implemented using backup systems and RAID arrays to protect against sudden service interruptions, then data reliability is improved, but the ability to prevent replay attacks deteriorates because recovered data may use previous monotonic counter values

Engineering Contradiction:
Improvedata recovery capabilityVSAvoidreplay attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The master block is segmented into multiple components: monotonic counter value, authentication code, and data block identifier. This segmentation allows the system to verify each component independently, enabling recovery of data blocks while maintaining replay protection through the authenticated monotonic counter sequence.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An authentication code acts as an intermediary between the monotonic counter and the data blocks. This authentication code verifies the legitimacy of each data block in the sequence, allowing the system to accept recovered blocks only if they maintain the correct monotonic counter sequence, thus preventing replay attacks while enabling recovery.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If monotonic counters and authentication codes are used to prevent replay attacks, then security against unauthorized access is improved, but the ability to recover from service interruptions deteriorates because any data alteration is rejected

Engineering Contradiction:
Improvereplay attack protectionVSAvoiddata recovery difficulty
Core Design Contradiction:
Object-affected harmful factorsVSEase of repair

Solution Approach 1:

The system dynamically adjusts its response to data verification based on the context. When a data block is recovered and the monotonic counter sequence is valid, the system accepts the recovered data. When the sequence is invalid or authentication fails, the system rejects the data as a replay attack. This dynamic behavior enables both recovery and protection.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the verification parameters based on the operational state. During normal operation, strict authentication is applied to prevent replay. During recovery operations, the system allows reconstruction of data blocks as long as the monotonic counter sequence maintains its integrity, thus adapting the security parameters to the current needs.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If traditional backup systems are implemented to protect against data corruption, then data integrity is improved, but system complexity increases due to additional disks and RAID configuration

Engineering Contradiction:
Improvedata integrityVSAvoidbackup system structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the backup functionality with the existing data storage structure by integrating authentication codes and monotonic counters directly into the data blocks and master blocks. This eliminates the need for separate backup systems and RAID configurations, as the authentication mechanism itself enables recovery without requiring additional storage infrastructure.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP2100250B1System and method for securing data
Publication Date: 2019.08.21 TRUSTONIC SAS
  • EP2100250B1 patent drawingFigure 1A~1B
  • EP2100250B1 patent drawingFigure 2
  • EP2100250B1 patent drawingFigure 3

AI summary

The invention relates to a system and method for securing data. According to the invention, the system is characterised in that it consists of: a monotonic counter; a computing entity; a physical data medium including one or more data blocks (DBk1, DBk2, DBk3, DBk4), a first master block (MBk1) comprising the last value (Vlast) retrieved from the monotonic counter, an identifier (IDlast) of the last data block (DBk) written on the medium, a first authentication code (Auth_A) guaranteeing the authenticity of the written data block(s), a second authentication code (Auth_B) calculated from the last written data block, said data being fixed to a neutral value, and a third authentication code (Auth_C) guaranteeing the authenticity of the first master block (MBk1), and a second master block (MBk2) forming a replica of the first master block (MBk1); and an authentication key (15). The invention is particularly suitable for securing data against playback and sudden interruptions in service in embedded systems.