Dual Trust Zone Data Handling with Symmetric Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security techniques for protecting sensitive data in gambling machines are inadequate, as they fail to prevent unauthorized access and manipulation of external memory data, which can be exploited by attackers to compromise the security of computations and alter bookkeeping data for personal gain.

Innovation Solution

A device comprising two integrated circuitries forming separate trust zones with a secure processing unit and a persistent memory area, using symmetrical crypto methods with a secure key for data transfer and initiating new key generation to ensure secure data handling, with one-time programmable power-on keys and tamper-resistant memory to prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If data is transferred off-chip to external memory, then storage capacity is increased, but security is compromised as data becomes vulnerable to attack

Engineering Contradiction:
Improvestorage capacityVSAvoidsecurity
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The system is divided into two separate trust zones: a first trust zone containing secure processing units and a second trust zone containing persistent memory areas. This segmentation isolates sensitive data operations within the secure processing unit while storing data in the external memory, maintaining security boundaries even when data is transferred off-chip.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A cryptographic method device acts as an intermediary between the secure processing unit and external memory. This intermediary encrypts data before transfer to external memory and decrypts it upon retrieval, ensuring that even if external memory is accessed unauthorized, the data remains protected through cryptographic transformation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cryptographic methods are used to protect data, then security is improved, but processing load and system complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The cryptographic method device combines multiple security functions including encryption/decryption, authentication, and key management into a single integrated component. This merging reduces overall system complexity compared to implementing separate security mechanisms while maintaining comprehensive cryptographic protection for data transfers.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If public key infrastructure is implemented for authentication, then security is improved, but processing load and setup complexity increase

Engineering Contradiction:
Improveauthentication securityVSAvoidprocessing load
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system implements different cryptographic approaches in different locations: symmetric encryption with shared keys is used for data encryption/decryption operations, while asymmetric encryption with public key infrastructure is used specifically for authentication of the cryptographic method device. This localized application of cryptographic methods optimizes both security and processing efficiency.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP2461265B1Device for and method of handling sensitive data
Publication Date: 2019.05.22 NOVOMATIC AG
  • EP2461265B1 patent drawingFigure 1
  • EP2461265B1 patent drawingFigure 2
  • EP2461265B1 patent drawingFigure 3

AI summary

The invention is related to a device for handling sensitive data comprising at least one first integrated circuitry for forming a first trust zone and at least one second integrated circuitry for forming a second trust zone wherein the first integrated circuitry comprises at least one secure processing unit adapted for processing sensitive data, the second integrated circuitry comprises at least one persistent memory area within its trust zone for storing the sensitive data wherein the second integrated circuitry is separated from the first integrated circuitry, the processing unit of the first integrated circuitry is adapted to transfer the sensitive data from the first trust zone to the second trust zone for securely storing said data in the persistent memory area of the second trust zone, the second integrated circuitry is adapted to transfer the sensitive data stored in its persistent memory area to the processing unit of the first trust zone, wherein the first and the second integrated circuitry comprise crypto means for securely transferring the sensitive data based on a symmetrical crypto method using a secure key, and wherein the second integrated circuitry comprises means for initiating a new key generation to replace the active secure key.