Hierarchical Bus Encryption for Mobile Payment Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing hierarchical bus systems in mobile payment technologies fail to physically isolate security module data transmission from common module data transmission, leading to insecure data exposure and inefficient bus utilization due to lack of encryption.

Innovation Solution

A hierarchical bus encryption system with multiple buses and corresponding encryption and decryption units, each using distinct security levels and algorithms, along with a bus converter to adapt and secure data transmission between buses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data transmission is not encrypted on the bus, then product performance is maintained, but security is compromised and confidential data can be obtained by attackers

Engineering Contradiction:
Improvedata securityVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The bus system is segmented into multiple independent buses (first bus for security modules, second bus for common modules) with different encryption requirements. This allows security-critical data to be encrypted on the first bus while non-critical data on the second bus remains unencrypted, resolving the contradiction between security and performance by applying encryption selectively rather than system-wide

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different encryption algorithms and security levels are applied to different buses based on their specific security requirements. The first bus uses a first encryption algorithm with a first security level, while the second bus uses a second encryption algorithm with a second security level. This local differentiation allows each bus to have the appropriate security-performance balance for its specific function

Inventive Principle:
Principle #3Local quality

2Reliability

If all modules are attached to the same high-performance bus, then bus utilization is simplified, but security modules are not physically isolated from common modules leading to security risks

Engineering Contradiction:
Improvephysical isolationVSAvoidbus system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system is divided into separate bus domains: a first bus connecting security modules and a second bus connecting common modules. This physical segmentation ensures that security modules are isolated from common modules, preventing attackers from accessing security data through common module transmissions while maintaining manageable complexity through clear functional separation

Inventive Principle:
Principle #1Segmentation

3Reliability

If data transmission rate requirements are the only classification criterion, then bus allocation is simplified, but security requirements are not differentiated leading to inadequate protection

Engineering Contradiction:
Improvesecurity level differentiationVSAvoidbus allocation flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The bus allocation strategy applies different quality standards to different buses: the first bus is configured with high security characteristics (first encryption algorithm, first security level) for security modules, while the second bus uses different characteristics (second encryption algorithm, second security level) for common modules. This allows the system to adapt to varying security requirements of different modules while maintaining a structured allocation framework

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10943020B2Data communication system with hierarchical bus encryption system
Publication Date: 2021.03.09 HUAWEI TECH CO LTD
  • US10943020B2 patent drawing
  • US10943020B2 patent drawing
  • US10943020B2 patent drawing

AI summary

A system includes at least two buses including a first bus and a second bus, an encryption and decryption system corresponding to each bus, at least one signal processing module corresponding to each bus, and a bus converter coupled between the first bus and the second bus. According to the system provided in embodiments of the present invention, because data transmitted on a bus is encrypted data, even though an attacker obtains bus data by means of a probe attack, it is quite difficult to break a key, and an anti-attack capability of the system can be improved.