Legacy Analog Sensor Circuits With Cryptographic Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Intrusion Detection Systems (IDS) and Physical Access Control Systems (PACS) are vulnerable to replay attacks, lack authentication, and have unsecured command and control systems, making them susceptible to manipulation and unauthorized control.
Innovation Solution
Implementing asymmetric public key cryptography for encryption and digital signature authentication, using a microcontroller to authenticate and encrypt sensor and control output signals, and incorporating a programmable watchdog timer for communication monitoring.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If legacy analog sensor circuits and 1940s supervised line techniques are used, then system compatibility and ease of installation are maintained, but security is compromised and systems are easily defeated
Solution Approach 1:
The system segments the security function by introducing discrete security modules (cryptoprocessors, authentication units) that can be independently integrated with legacy sensor circuits. This allows security enhancements to be added without replacing the entire legacy infrastructure, maintaining ease of installation while improving security through modular integration of cryptographic functions with existing analog sensor circuits.
Solution Approach 2:
The patent introduces intermediary security modules between the legacy analog sensor circuits and the main processing system. These intermediaries (such as authentication units and cryptoprocessors) act as mediators that secure the communication and data transmission without requiring direct modification of the legacy circuits, thus maintaining compatibility while enabling encrypted communication and authentication.
2Reliability
If digital encrypted security interfaces are implemented, then authentication and encryption are achieved, but device complexity increases
Solution Approach 1:
The authentication and encryption functions are segmented into separate dedicated modules (cryptoprocessors, authentication units) rather than being integrated into the main processor. This modular approach distributes the complexity across independent security components, making the overall system more manageable while achieving robust authentication and encryption capabilities.
Solution Approach 2:
The patent uses hardware security modules that contain copied and pre-configured cryptographic algorithms and authentication logic. By embedding these security functions in dedicated hardware copies rather than software implementations, the system achieves efficient authentication while reducing the complexity burden on the main processing units.
3Reliability
If asymmetric public key cryptography is implemented, then digital signature authentication and encryption are provided, but processing requirements and power consumption increase
Solution Approach 1:
The cryptographic processing is segmented into dedicated hardware modules (cryptoprocessors) that are optimized for security functions. By separating the computationally intensive asymmetric cryptography from the main processing system, the patent achieves efficient power management where only the security modules consume significant power during authentication operations, while the main system remains low-power.
Solution Approach 2:
The security modules are designed with self-contained cryptographic accelerators that handle authentication and encryption autonomously without requiring continuous involvement from the main processor. This self-service capability allows the security functions to operate efficiently with minimal power consumption from external systems, as the dedicated modules perform their cryptographic operations independently.
Data Source
AI summary
Embodiments are directed to an apparatus, comprising: a microcontroller configured as a Universal Field Panel. The microcontroller provides channels that (i) couple to a digital encrypted security interface (DESI) via a digital communications interface and/or couple to a sensor comprising an analog signal, and wherein the analog sensor comprises one or more resistors coupled with one or more switches to monitor Boolean status from sensors (ii) wherein the digital encrypted security interface (DESI) couples to a sensor input and/or couples to a control output where signals to command a relay are authenticated prior to execution, (iii) authenticate and encrypt the sensor or control output. The control output is a programmable relay or solid-state device that features a Form-C control interface for providing authentication from command-and-control platforms to the devices and/or signals they are controlling.


