ITP Data Transmission Stack for Open-to-Secure Module Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data processing devices face challenges in ensuring secure data transmission between open and secure modules while maintaining the open module's functionality and security, as standard communication protocols are vulnerable to fraudulent data or commands.
Innovation Solution
Implementing a specialized data transmission component that aggregates layers 3 and 4 of the OSI system, incorporating a hybridized network stack with an ITP component for secure data exchange between open and secure modules, including authorization and serialization steps, and a filtering component for secure verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If standard communication protocols (TCP/IP) are used for data transmission between open and secure modules, then ease of operation and compatibility are improved, but security is worsened due to vulnerability to fraudulent data
Solution Approach 1:
The patent introduces a specialized data transmission component as an intermediary layer between the open module and secure module. This component aggregates OSI layers 3 and 4 functionality and implements a hybridized network stack that filters and validates data packets before they reach the secure module, blocking fraudulent commands while allowing legitimate communication
Solution Approach 2:
The patent segments the network stack into traditional components (layers 7, 6, 5) and a specialized aggregated component (layers 3 and 4). This segmentation allows the specialized component to handle security-critical packet filtering and validation functions separately from application-layer protocols, enabling enhanced security without compromising overall system compatibility
2Adaptability or versatility
If the open module is made fully open and modular to enhance functionality, then adaptability is improved, but security is worsened due to potential malicious applications
Solution Approach 1:
The specialized data transmission component acts as a protective intermediary between the open application layer and the secure module. It validates all data packets passing through it, blocking malicious commands from reaching the secure module while allowing the open module to maintain its full functionality and adaptability
Solution Approach 2:
The patent implements preliminary security validation in the specialized data transmission component before data reaches the secure module. The component performs authorization checks and filters fraudulent data packets in advance, preventing malicious actions before they can affect the secure module
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
The invention relates to a method for transmitting data between a first electronic module comprising a general-purpose processor and a second electronic module comprising a secure processor, the two modules being combined in an electronic device, the first module executing a first operating system and the second module executing a second operating system, the modules each comprising a hybrid communication stack comprising, alongside components of layers 3 and 4 of the OSI model, a specialised data transmission component (ITP), connecting layers 3 and 4 of the OSI model.