Hardware-Software Message Authentication System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security schemes for embedded computing systems are vulnerable due to software bugs and the inability to update hardware configurations, while communication protocols can be compromised using weak protocols, making it difficult to ensure secure message transmission.

Innovation Solution

A system that authenticates and secures message transmission by using a hardware processing unit and a software processing unit to test messages with specific firmware and software code, respectively, and compares the results using a logic comparison hardware module, ensuring authentication through a logic gate array, with security elements initialized and activated at different stages to prevent unauthorized modifications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If software is used for security schemes, then flexibility and updatability are improved, but vulnerability to bugs and hacking increases

Engineering Contradiction:
Improvesoftware updatabilityVSAvoidsecurity reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The security system is divided into two independent segments: a hardware security processing unit that executes immutable security-critical code, and a software component that handles non-critical functions. This segmentation isolates the security-critical operations from software vulnerabilities while maintaining flexibility in non-critical areas.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A hardware security processing unit acts as an intermediary between the software system and security requirements. This intermediary executes security-sensitive operations in isolated hardware, preventing software bugs from compromising security while allowing software to remain flexible and updatable.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If hardware configuration is predetermined, then security against software attacks is improved, but ability to update and adapt decreases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidconfiguration flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The hardware security processing unit incorporates dynamic elements that allow configuration changes through secure cryptographic operations. While the hardware structure remains fixed for security, it can dynamically adapt security parameters, keys, and algorithms through cryptographic processing, balancing immutability with adaptability.

Inventive Principle:
Principle #15Dynamics

3Reliability

If strong security mechanism is built on end-nodes, then security protection is improved, but performance overhead increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidmessage transmission speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Security processing is performed in advance through pre-computed cryptographic operations and pre-established security contexts. The hardware security processing unit prepares security parameters and performs authentication operations before critical message transmission, reducing real-time overhead while maintaining strong security protection.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3987418B1A system and method for securing electronic devices
Publication Date: 2024.10.16 RATINER MICHAEL
  • EP3987418B1 patent drawingFigure 1
  • EP3987418B1 patent drawingFigure 2
  • EP3987418B1 patent drawingFigure 3

AI summary

The present invention discloses a system for authenticating and securing message/instruction transmission, system comprising: a hardware processing unit for testing the validity of a nonrandom original message or derivative of said original message by running specific firmware code resulting first test results; a software processing unit, for testing the validity of the nonrandom original message or derivative of said original message by running specific software code; for resulting a second test result; a logic comparison module, for comparing between the first and the second test results, wherein said comparison authenticate said message. Wherein the testing is performed simultaneously at the hardware processing unit and the software processing unit; According to some embodiments of the present invention said logic comparison module is implemented as a hardware module comprising a gates array including at least one logic gate