Protocol-Free Encrypting Device for Secure Data Transmission

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

High assurance cryptography systems face challenges in maintaining secure data transmission over untrusted networks due to vulnerabilities in software-based implementations and the complexity of hardware-based solutions, particularly in mobile devices where radios host extensive software with unknown provenance, leading to increased risk and difficulty in achieving robust isolation.

Innovation Solution

The development of a protocol-free encrypting device (PFED) that uses low-cost commodity hardware running commodity software, providing a pair of encrypting devices for trusted elements to communicate securely over an untrusted network through a master encryption unit and a communications unit with a connectionless interconnect, ensuring logical and physical isolation without requiring specific protocols, and allowing for autonomous key management and recovery.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If software-based encryption implementations are used, then adaptability and ease of operation are improved, but reliability and security are worsened due to vulnerabilities and unknown provenance

Engineering Contradiction:
ImproveadaptabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system segments functionality into two distinct parts: a trusted hardware element (security processor) that performs cryptographic operations and a software-based host system that provides adaptability. This segmentation allows the software to be updated and adapted while the hardware ensures consistent security, resolving the contradiction between adaptability and reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A trusted hardware security processor acts as an intermediary between the untrusted software environment and the cryptographic operations. This intermediary isolates the security-critical functions from the vulnerable software layer, allowing software-based adaptability while maintaining hardware-level security guarantees.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If hardware-based encryption solutions are used, then reliability and security are improved, but device complexity and cost are worsened

Engineering Contradiction:
ImprovesecurityVSAvoidcomplexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The invention extracts only the essential security functions into hardware, rather than implementing a complete hardware encryption solution. The trusted hardware element performs only cryptographic operations, while all other functionality remains in software, reducing device complexity while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The trusted hardware security processor is designed as a universal component that can serve multiple applications and platforms. By creating a multi-functional security element that can be deployed across different devices and software environments, the solution reduces overall system complexity while maintaining high security standards.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If protocol-specific encryption is implemented, then reliability is improved through standardized processes, but adaptability is worsened due to protocol dependencies

Engineering Contradiction:
ImprovereliabilityVSAvoidadaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system implements dynamic protocol handling where the trusted hardware element can adapt to different communication protocols through software-based configuration. The hardware provides reliable cryptographic operations while the software layer dynamically adjusts to different protocols, combining reliability with adaptability.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12088569B1Protocol free encrypting device
Publication Date: 2024.09.10 NATIONAL SECURITY AGENCY
  • US12088569B1 patent drawing
  • US12088569B1 patent drawing
  • US12088569B1 patent drawing

AI summary

The present invention provides an encrypting device including an encryption unit and a communications unit. Paired encrypting devices allow for communication of trusted data between trusted devices over an untrusted network. Data received by the encryption unit is encrypted and provided with a connectionless header for delivery to the communications unit. Data received by the communications units is provided with a complex header for delivery to the paired encrypting device. The encrypting devices may be implemented in hardware or may be virtualized on a server or a plurality of severs. Arrangement of the encrypting devices in a hub-and-spoke topology allows for communication amongst a plurality of trusted devices. The encrypting devices can be used to covert commercially available equipment suitable for high assurance environments.