Mobile and Fixed Hardware Secure Unit Cooperation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current hardware secure solutions, such as USB Keys and smart cards, are inadequate in securing user identity and overall operating environment, as they rely on fixed secure chips that are difficult to move and use weak password-based authentication, making them vulnerable to hacking and loss-related security breaches.

Innovation Solution

A cooperation method and system combining fixed and mobile hardware secure units, where a mobile hardware secure unit provides user identification and a fixed hardware secure unit provides platform identification, establishing a bidirectional communication pipe through key negotiation or public key exchange, binding the units via unique identification information, and performing secondary encryption for secure data transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a fixed hardware secure unit is used in a computer or device, then platform security is guaranteed, but the system cannot be moved easily and is inconvenient for mobile use

Engineering Contradiction:
Improveplatform securityVSAvoidmobile usability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system divides the security functionality into two separate hardware secure units: a fixed hardware secure unit embedded in the computer/device and a mobile hardware secure unit that can be carried independently. This segmentation allows the fixed unit to provide reliable platform security while the mobile unit enables portable security operations, resolving the contradiction between fixed security and mobile usability.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If a USB Key or smart card is used for user identity, then user authentication is provided, but the solution cannot prevent password theft by hacker programs and is vulnerable to loss

Engineering Contradiction:
Improveuser authenticationVSAvoididentity security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system merges the fixed hardware secure unit (which secures the operating environment and platform) with the mobile hardware secure unit (which secures user identity). The fixed unit and mobile unit establish a bidirectional communication pipe and bind through interaction of unique identification information, creating a layered security architecture where neither unit alone can be compromised to steal credentials, thus resolving the contradiction between ease of authentication and reliability of identity security.

Inventive Principle:
Principle #5Merging (Combining)

3Ease of operation

If password-based authentication is used in USB Keys, then user verification is simple, but the security factor is weak and susceptible to violent attacks

Engineering Contradiction:
Improveverification simplicityVSAvoidsecurity strength
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The fixed hardware secure unit acts as an intermediary between the mobile hardware secure unit and external systems. It establishes a bidirectional communication pipe with the mobile unit and performs cryptographic operations, replacing weak password-based authentication with hardware-based mutual authentication and binding through unique identification information interaction, thus maintaining ease of operation while significantly improving security strength.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8806206B2Cooperation method and system of hardware secure units, and application device
Publication Date: 2014.08.12 LENOVO SOFTWARE
  • US8806206B2 patent drawing
  • US8806206B2 patent drawing
  • US8806206B2 patent drawing

AI summary

The present invention provides a cooperation method of a mobile hardware secure unit and a fixed hardware secure unit, comprising: providing user's identification information of a mobile hardware secure unit; providing platform's identification information of a computer-based or other-device-based fixed hardware secure unit; establishing a bidirectional communication pipe between the mobile and fixed hardware secure unit; and binding the mobile and fixed hardware secure units through interaction of the user's identification information and the platform's identification information. The present invention further provides a cooperation system of a mobile hardware secure unit and a fixed hardware secure unit as well as a computer device, with which the security solution based on a fixed hardware secure unit can be combined with a mobile hardware secure unit securing a user's identity.