Dynamic Command Protection Using Time-Varying Salt Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for protecting physically linked devices from fake commands are inadequate, as they can be compromised if command data is recorded by hackers, leading to security risks such as data leakage or system crashes.

Innovation Solution

A dynamic command protection method that generates salt data bound to a physically linked device, which is transmitted to a computer terminal and used to protect commands. The salt data is updated over time, ensuring that even if recorded commands are intercepted, they remain protected by changing salt values.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional verification methods (application program, checksum mechanism, or packed encoded commands) are used, then command validity can be verified, but the system remains vulnerable to recorded fake commands

Engineering Contradiction:
Improvecommand verification capabilityVSAvoidvulnerability to recorded fake commands
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies dynamics by making the verification mechanism time-dependent. The salt data changes over time intervals, transforming a static verification system into a dynamic one where the verification parameters are continuously updated, thereby preventing reuse of recorded commands across different time periods.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of verification data by introducing time-varying salt data. Instead of using fixed checksums or encoding schemes, the system modifies the verification parameters periodically, ensuring that even if commands are recorded, they cannot be replayed when the salt data has changed.

Inventive Principle:
Principle #35Parameter changes

2Ease of manufacture

If static verification methods are used, then implementation is simple, but security protection is insufficient against replay attacks

Engineering Contradiction:
Improveimplementation simplicityVSAvoidsecurity protection level
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The system performs preliminary action by pre-establishing time intervals and generating salt data in advance for each interval. This allows the device to be prepared for future verification needs without complex real-time computation, maintaining ease of implementation while enhancing security.

Inventive Principle:
Principle #10Preliminary action

3Object-affected harmful factors

If time-varying salt data is implemented, then protection against recorded fake commands is enhanced, but system complexity increases

Engineering Contradiction:
Improveresistance to replay attacksVSAvoidverification system complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent segments the verification process into distinct time intervals, each with its own salt data. This segmentation simplifies the overall system design by breaking down the complex problem of continuous verification into manageable discrete intervals, reducing overall system complexity while maintaining strong security.

Inventive Principle:
Principle #1Segmentation

4Reliability

If frequent salt data updates are performed, then security is enhanced, but processing overhead increases

Engineering Contradiction:
Improvecommand protection strengthVSAvoidprocessing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system employs periodic action by updating salt data at fixed time intervals rather than continuously or with each command. This periodic approach maintains strong security protection while minimizing processing overhead, as the system only needs to perform verification operations at these scheduled intervals rather than continuously.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS12306926B2Dynamic command protection method and dynamic command protection system by using time-vary salt data
Publication Date: 2025.05.20 MEDIATEK INC
  • US12306926B2 patent drawing
  • US12306926B2 patent drawing
  • US12306926B2 patent drawing

AI summary

A dynamic command protection method includes generating salt data by a physically linked device after an authentication of the physically linked device is verified, transmitting the salt data from the physically linked device to a computer terminal, transmitting at least one command protected by the salt data during a first time interval from the computer terminal to the physically linked device, verifying the salt data if the at least one command is valid, executing at least one valid command after the salt data is successfully verified, and updating the salt data after the first time interval elapses. The salt data is bound to the physically linked device and is generated according to a time-varying value.