Encrypted GNSS Signal Simulation via Smart Card Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Standard computers used as GNSS simulators are vulnerable to security flaws, such as data copying and algorithm de-compilation, which compromise the security of protected cryptographic algorithms and secrets required for generating encrypted GNSS codes.

Innovation Solution

A method involving a simulator computing device that transmits cryptographic variable input to a detachably coupled smart card, where protected cryptographic algorithms are executed to generate cryptographic products, which are then used to produce an encrypted signal simulation, thereby physically isolating sensitive data from the simulator device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If standard computers are used to run simulation programs, then simulation functionality is achieved, but security vulnerabilities arise allowing data copying and algorithm de-compilation

Engineering Contradiction:
Improvesimulation functionalityVSAvoidsecurity protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system divides the simulation functionality into two separate components: a standard computer running the simulation program and a secure smart card storing cryptographic secrets. This segmentation allows the simulation to run on easy-to-operate standard hardware while security-critical operations are isolated in the protected smart card environment, preventing both data copying and algorithm de-compilation

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A cryptographic interface card (CIC) acts as an intermediary between the standard computer and the secure smart card. The CIC manages cryptographic operations by receiving requests from the simulation program, executing protected algorithms on the smart card, and returning results. This intermediary enables standard computers to perform secure simulations without directly accessing sensitive cryptographic materials

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If cryptographic algorithms and secrets are stored on the simulator computer, then simulation execution is simplified, but security flaws enable unauthorized access and data extraction

Engineering Contradiction:
Improvesystem configurationVSAvoidunauthorized access
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The system extracts cryptographic secrets (private keys, cryptographic constants) and protected algorithms from the simulator computer and stores them exclusively on the secure smart card. This extraction eliminates the security vulnerability of having sensitive data on the standard computer, while the simulation program can still execute by receiving cryptographic products from the smart card through the CIC interface

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The smart card functions as a disposable or replaceable security token that can be inserted and removed as needed. If compromised or expired, the card can be replaced without affecting the simulation software or hardware infrastructure, providing a cost-effective security solution compared to securing the entire computer system

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS11757646B2Methods for generating an encrypted signal simulation with a cryptographic interface card (GCIC) and devices thereof
Publication Date: 2023.09.12 OROLIA DEFENSE & SECURITY LLC
  • US11757646B2 patent drawing
  • US11757646B2 patent drawing
  • US11757646B2 patent drawing

AI summary

A method, non-transitory computer readable medium, and device that transmits a cryptographic variable input to a detachably coupled smart card. Execution of at least one of protected cryptographic algorithm operation by the smart card which requires the cryptographic variable input and a cryptographic constant input stored on the smart card to generate one or more cryptographic products is requested. The one or more generated cryptographic products from the smart card are received. An encrypted signal simulation based on execution of a simulator using the received one or more generated cryptographic products is generated and is output.