Multi-Platform Cryptographic Provisioning via Segmented Architecture

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cryptographic management systems face challenges in offering technical flexibility to address different provisioning scenarios and implementing various computer resources for securely provisioning secure data assets to target devices, limiting their ability to adapt to diverse manufacturing processes and secure data management needs.

Innovation Solution

Implementing a multi-platform approach that separates sensitive data (Context) from logic (Module), allowing the use of multiple elements such as Applications, Contexts, and Modules to generate, process, and deliver secure data assets, with cryptographic binding ensuring security and flexibility, and leveraging hardware security modules (HSMs) for secure operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a traditional single-platform cryptographic management system is used, then the system structure is simple, but the system lacks flexibility to address diverse provisioning scenarios and cannot leverage various computer resources

Engineering Contradiction:
Improveflexibility to address diverse provisioning scenariosVSAvoidsystem structure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The cryptographic management system is segmented into multiple independent platforms, each with specific functionalities. The first platform handles application execution and resource coordination, while the second platform specializes in secure cryptographic operations. This segmentation allows each platform to be optimized for its specific purpose, improving overall system flexibility without requiring complete redesign of the entire system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements universal interfaces and protocols that allow different platform types to work together. The first platform can execute various applications and coordinate with different second platforms through standardized interfaces, enabling the system to address diverse provisioning scenarios while maintaining a consistent architectural framework.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If cryptographic operations are performed in a secured facility with factory programming, then security is maintained, but the system cannot adapt to different manufacturing processes and secure data management needs

Engineering Contradiction:
Improveability to adapt to diverse manufacturing processesVSAvoidsecurity of cryptographic operations
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The first platform acts as an intermediary between the application layer and the second secure platform. It handles application-specific logic and coordinates with the second platform through standardized interfaces, allowing different manufacturing processes to be supported while the second platform maintains consistent security standards for cryptographic operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system separates adaptive functionality (first platform) from security-critical functionality (second platform). This allows the first platform to adapt to different manufacturing processes and data management needs, while the second platform maintains reliable security through specialized hardware security modules that are not affected by process variations.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If multiple platforms are implemented for flexible provisioning, then the system can address diverse scenarios and leverage various resources, but the system complexity increases

Engineering Contradiction:
Improveflexibility for secure data asset managementVSAvoidmulti-platform system architecture
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system employs universal communication interfaces and standardized protocols between platforms. The first platform uses consistent interfaces to interact with different second platforms, and the second platforms respond through standardized secure operation interfaces. This universality reduces the complexity that would otherwise arise from platform-specific integration requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The first platform serves as a mediator that abstracts the complexity of multiple second platforms from applications. It handles the coordination, authentication, and interface management, presenting a simplified view to applications while managing the underlying multi-platform complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20230205919A1Multi-platform use case implementations to securely provision a secure data asset to a target device
Publication Date: 2023.06.29 CRYPTOGRAPHY RESEARCH INC
  • US20230205919A1 patent drawing
  • US20230205919A1 patent drawing
  • US20230205919A1 patent drawing

AI summary

An application executing at a first platform receives, from a tester device, a first request to generate a secure data asset to be securely provisioned to a target device. Responsive to receiving the first request, the application performs one or more operations related to the generation of the secure data asset. Subsequent to performing the one or more operations related to the generation of the secure data asset, the application sends, to a second secure platform, a second request to generate the secure data asset. The application receives, from the second secure platform, the generated secure data asset.