ITP Data Transmission Stack for Open-to-Secure Module Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data processing devices face challenges in ensuring secure data transmission between open and secure modules while maintaining the open module's functionality and security, as standard communication protocols are vulnerable to fraudulent data or commands.

Innovation Solution

Implementing a specialized data transmission component that aggregates layers 3 and 4 of the OSI system, incorporating a hybridized network stack with an ITP component for secure data exchange between open and secure modules, including authorization and serialization steps, and a filtering component for secure verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If standard communication protocols (TCP/IP) are used for data transmission between open and secure modules, then ease of operation and compatibility are improved, but security is worsened due to vulnerability to fraudulent data

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a specialized data transmission component as an intermediary layer between the open module and secure module. This component aggregates OSI layers 3 and 4 functionality and implements a hybridized network stack that filters and validates data packets before they reach the secure module, blocking fraudulent commands while allowing legitimate communication

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the network stack into traditional components (layers 7, 6, 5) and a specialized aggregated component (layers 3 and 4). This segmentation allows the specialized component to handle security-critical packet filtering and validation functions separately from application-layer protocols, enabling enhanced security without compromising overall system compatibility

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If the open module is made fully open and modular to enhance functionality, then adaptability is improved, but security is worsened due to potential malicious applications

Engineering Contradiction:
ImproveadaptabilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The specialized data transmission component acts as a protective intermediary between the open application layer and the secure module. It validates all data packets passing through it, blocking malicious commands from reaching the secure module while allowing the open module to maintain its full functionality and adaptability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary security validation in the specialized data transmission component before data reaches the secure module. The component performs authorization checks and filters fraudulent data packets in advance, preventing malicious actions before they can affect the secure module

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentEP4256454B1Data transmission method, device and corresponding program
Publication Date: 2025.09.17 BANKS & ACQUIRERS INT HLDG SAS
  • EP4256454B1 patent drawingFigure 1~2
  • EP4256454B1 patent drawingFigure 3
  • EP4256454B1 patent drawingFigure 4

AI summary

The invention relates to a method for transmitting data between a first electronic module comprising a general-purpose processor and a second electronic module comprising a secure processor, the two modules being combined in an electronic device, the first module executing a first operating system and the second module executing a second operating system, the modules each comprising a hybrid communication stack comprising, alongside components of layers 3 and 4 of the OSI model, a specialised data transmission component (ITP), connecting layers 3 and 4 of the OSI model.