Hierarchical Bus Encryption for Mobile Payment Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing hierarchical bus systems in mobile payment technologies fail to physically isolate security module data transmission from common module data transmission, leading to insecure data exposure and inefficient bus utilization due to lack of encryption.
Innovation Solution
A hierarchical bus encryption system with multiple buses and corresponding encryption and decryption units, each using distinct security levels and algorithms, along with a bus converter to adapt and secure data transmission between buses.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data transmission is not encrypted on the bus, then product performance is maintained, but security is compromised and confidential data can be obtained by attackers
Solution Approach 1:
The bus system is segmented into multiple independent buses (first bus for security modules, second bus for common modules) with different encryption requirements. This allows security-critical data to be encrypted on the first bus while non-critical data on the second bus remains unencrypted, resolving the contradiction between security and performance by applying encryption selectively rather than system-wide
Solution Approach 2:
Different encryption algorithms and security levels are applied to different buses based on their specific security requirements. The first bus uses a first encryption algorithm with a first security level, while the second bus uses a second encryption algorithm with a second security level. This local differentiation allows each bus to have the appropriate security-performance balance for its specific function
2Reliability
If all modules are attached to the same high-performance bus, then bus utilization is simplified, but security modules are not physically isolated from common modules leading to security risks
Solution Approach 1:
The system is divided into separate bus domains: a first bus connecting security modules and a second bus connecting common modules. This physical segmentation ensures that security modules are isolated from common modules, preventing attackers from accessing security data through common module transmissions while maintaining manageable complexity through clear functional separation
3Reliability
If data transmission rate requirements are the only classification criterion, then bus allocation is simplified, but security requirements are not differentiated leading to inadequate protection
Solution Approach 1:
The bus allocation strategy applies different quality standards to different buses: the first bus is configured with high security characteristics (first encryption algorithm, first security level) for security modules, while the second bus uses different characteristics (second encryption algorithm, second security level) for common modules. This allows the system to adapt to varying security requirements of different modules while maintaining a structured allocation framework
Data Source
AI summary
A system includes at least two buses including a first bus and a second bus, an encryption and decryption system corresponding to each bus, at least one signal processing module corresponding to each bus, and a bus converter coupled between the first bus and the second bus. According to the system provided in embodiments of the present invention, because data transmitted on a bus is encrypted data, even though an attacker obtains bus data by means of a probe attack, it is quite difficult to break a key, and an anti-attack capability of the system can be improved.


