Moving Target Defense Serial Bus Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional serial communications systems lack robust security measures, particularly in addressing the risk of unauthorized access and malicious commands due to limited address availability and lack of authentication or encryption, which can lead to security breaches and require extensive reconfiguration for anomaly detection.
Innovation Solution
Implementing a moving target defense (MTD) scheme that generates randomized addresses for remote terminals using a shared secret and nonce, preventing unauthorized actors from generating coherent messages by dynamically changing addresses based on a pseudo-random number generator and cryptographic functions, without broadcasting the shared secret.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional security approaches focusing on anomaly detection are used, then security monitoring is provided, but extensive reconfiguration of the serial communications system is required
Solution Approach 1:
The patent implements dynamic address assignment where remote terminals periodically switch between multiple possible addresses according to a pseudorandom sequence derived from a shared secret. This dynamic behavior prevents unauthorized access without requiring system reconfiguration, as the address changes are automatic and predetermined by the cryptographic key
Solution Approach 2:
The system changes the address parameter of remote terminals over time based on a pseudorandom sequence generated from a shared secret key. This parameter change enables security enhancement while maintaining system operation without reconfiguration, as the address transitions follow a predetermined cryptographic pattern
2Reliability
If authentication or encryption is implemented in serial communications systems, then security against malicious commands is improved, but the limited address availability and system constraints are exacerbated
Solution Approach 1:
The patent introduces a shared secret key as an intermediary that enables security without requiring traditional authentication protocols. The shared secret serves as a mediator that allows remote terminals to independently generate matching pseudorandom address sequences, providing security while working within the constraints of limited address availability
Solution Approach 2:
The system uses cryptographic copying where the shared secret is replicated across all authorized remote terminals and the bus controller. Each device independently generates the same pseudorandom address sequence through cryptographic functions applied to the shared secret, enabling coordinated address changes without centralized control or extensive reconfiguration
Data Source
AI summary
A moving target defense scheme for a serial communications system is disclosed herein. A bus controller generates and broadcasts a nonce to remote terminals over a bus. The bus controller and the remote terminals generate a randomized sequence based upon the nonce and a shared secret that is shared between the bus controller and the remote terminals. The bus controller broadcasts first messages over the bus on first addresses that are derived from first portions of the randomized sequence. The remote terminals listen for the first messages that are broadcast over the bus on the first addresses. The bus controller broadcasts a shift message that causes the remote terminals to listen for second messages that are broadcast over the bus on second addresses that are derived from second portions of the randomized sequence.


