Hardware Security Device for Data Integrity and Confidentiality

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for protecting data and executable codes in computer systems primarily focus on securing transmitted data or authenticating transmitters, but they fail to adequately address the security of the computer system itself and the integrity and confidentiality of data and codes stored within the system.

Innovation Solution

A security device is positioned between the computer system and the memory medium to protect data and codes, implementing authentication, integrity, and confidentiality functions independently of the system's processor, using cryptographic components and operating modes to manage access and ensure the integrity and confidentiality of data and codes, with no interaction required with the system's processor.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a security device is physically positioned between the computer system and the memory medium to protect data and codes, then the integrity and confidentiality of data and codes are improved, but the device complexity increases

Engineering Contradiction:
Improveintegrity and confidentiality of data and codesVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A security device is physically positioned between the computer system and the memory medium to act as an intermediary. This device contains cryptographic components that independently perform authentication, integrity verification, and confidentiality protection without requiring interaction with the system processor, thereby resolving the contradiction by introducing a dedicated security layer that enhances reliability while maintaining operational simplicity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security functionality is segmented into a separate physical device distinct from both the computer system and the memory medium. This segmentation allows the security device to operate independently with its own cryptographic components, protecting data and codes without complicating the existing system architecture, as the security functions are isolated in a dedicated module

Inventive Principle:
Principle #1Segmentation

2Reliability

If the security device operates independently of the system processor using cryptographic components, then the security protection is improved, but the ease of operation deteriorates

Engineering Contradiction:
Improvesecurity protectionVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The security device is designed to autonomously perform all security functions including authentication, integrity verification, and confidentiality protection using its internal cryptographic components. The device operates independently without requiring processor interaction or external intervention, thereby maintaining high security protection while simplifying operation through self-contained functionality that requires no additional user actions

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The security device serves as an automatic intermediary that handles all security operations between the computer system and memory medium without human intervention. It independently manages cryptographic operations, authentication processes, and data protection, resolving the contradiction by making the security device self-sufficient and transparent to users while maintaining robust security

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If authentication and integrity verification are performed independently of the machine code executed by the protected computer system, then the reliability of protection is improved, but the productivity of the system decreases

Engineering Contradiction:
Improvereliability of protectionVSAvoidproductivity of the system
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The security device acts as an independent intermediary that performs authentication and integrity verification in parallel with the computer system operations. By physically positioning the security device between the system and memory medium, it verifies data and code integrity without blocking or slowing down the execution of machine code, thereby maintaining high reliability while preserving system productivity through concurrent operation

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Security verification functions are segmented into a separate device that operates independently from the main computer system. This allows authentication and integrity checks to be performed on data and codes without interfering with the execution flow of machine code, resolving the contradiction by enabling simultaneous security verification and system productivity through architectural separation

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8627406B2Device for protection of the data and executable codes of a computer system
Publication Date: 2014.01.07 BULL SA
  • US8627406B2 patent drawing
  • US8627406B2 patent drawing
  • US8627406B2 patent drawing

AI summary

A security and protection device (1) for protection of the data and executable codes of any fixed or portable computer system and that has a memory medium to be protected. The security and protection device (1) is located physically between the computer system (2) and the memory medium (MP) to be protected, in order to allow the computer system (2) access to the data and codes to be protected after execution of the protection functions independently of the machine code executed by the computer system (2) and requires no interaction with the processor of the system for the execution of these functions.