Dual System Management Device for Secure Information Interaction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security information interaction apparatuses face challenges in providing comprehensive and cost-effective solutions due to the emergence of new viruses, inherent bugs in system management devices, and high costs associated with frequent updates and modifications, limiting their safety and applicability.

Innovation Solution

An apparatus with dual system management devices, one for routine applications and another for secure mode operations, featuring a virtual security carrier manager, peer-to-peer communication, and a security information management module to enhance security and flexibility, allowing for isolated resource allocation and mutual authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single system management device is used for all applications, then device complexity is low, but security reliability is insufficient for security applications

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system is divided into two independent system management devices: a first system management device for routine applications and a second system management device for security applications. This segmentation allows each device to be optimized for its specific purpose, with the second device providing enhanced security functionality while the first device handles general operations, thereby resolving the contradiction between security reliability and device complexity.

Inventive Principle:
Principle #1Segmentation

2Reliability

If frequent updates and modifications are made to improve security, then security reliability improves, but manufacturing cost increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidmanufacturing cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The second system management device is pre-configured with dedicated security functionality and resources during manufacturing. Security applications are pre-authorized to access specific resources of the second device, eliminating the need for frequent updates and modifications to enhance security. This preliminary configuration reduces manufacturing costs while maintaining high security reliability.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If security applications share resources with routine applications, then device complexity is low, but security reliability deteriorates due to potential bugs and vulnerabilities

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidresource isolation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Security-critical resources and functions are extracted from the first system management device and assigned to the second system management device. The second device maintains independent resource management for security applications, preventing bugs and vulnerabilities in the first device from affecting security operations. This extraction ensures security reliability while managing resource isolation complexity through dedicated security resource allocation.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If a secure mode operational environment is provided for security applications, then security reliability improves, but device complexity increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system dynamically selects which system management device to use based on the application type. Routine applications operate under the first system management device, while security applications automatically switch to the second system management device. This dynamic switching mechanism provides a secure operational environment for security applications without requiring the entire system to operate in a complex secure mode, thereby balancing security reliability with manageable system architecture complexity.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP2966829B1Secure information interaction device
Publication Date: 2020.04.29 CHINA UNIONPAY
  • EP2966829B1 patent drawingFigure 1

AI summary

The invention provides an apparatus used for security information interaction comprising a first system management device for providing an operational environment for routine applications and a second system management device for providing an operational environment in a safe mode for security applications so as to perform a security information interaction process. The apparatus used for security information interaction disclosed by the invention has a high safety and a wide applicability and is low in cost.