Reconfigurable Digital Module Identifier Provisioning for Data Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data processing technologies in digital modules, such as FPGAs, lack robust security measures to prevent manipulation of hardware applications by software or operating systems, which is critical for real-time and safety-relevant functions.

Innovation Solution

A computer-implemented device with a digital module that uses a provision unit to generate and provide specific identifiers for configuration descriptions, allowing cryptographic functions to be performed on data, thereby enhancing security by ensuring only the specific configuration description has access to the identifier, preventing manipulation by software or operating systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware applications are loaded into reconfigurable parts of digital components, then real-time critical and safety-relevant functions can be implemented, but security against manipulation by software or operating systems is insufficient

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the identifier provision process into two distinct parts: (1) a provisioning unit that provides identifiers to configuration descriptions before loading, and (2) the reconfigurable part that executes cryptographic functions using these identifiers. This segmentation isolates the security-critical identifier management from the software layer, preventing manipulation while maintaining system functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The provisioning unit performs preliminary action by providing specific identifiers to configuration descriptions before they are loaded into the reconfigurable part. This pre-provisioning ensures that security-relevant hardware applications have exclusive access to their identifiers from the outset, preventing any subsequent manipulation by operating systems or software applications.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If identifiers are made accessible to configuration descriptions, then cryptographic functions can be executed, but manipulation by software applications becomes possible

Engineering Contradiction:
Improveease of operationVSAvoidmanipulation risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The provisioning unit acts as an intermediary between the configuration descriptions and the identifiers. It selectively provides specific identifiers to specific configuration descriptions based on derivation parameters, ensuring that only authorized hardware applications access their identifiers. This intermediary mechanism prevents direct access that would enable manipulation while maintaining necessary functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Each configuration description receives a unique specific identifier tailored to its security requirements. The provisioning unit derives identifiers locally for each configuration description using derivation parameters, ensuring that security-critical functions have exclusive access to their specific identifiers without exposing them to other software components or potential manipulators.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If reconfiguration is allowed during operation, then flexibility is improved, but security of existing hardware applications may be compromised

Engineering Contradiction:
Improvereconfiguration capabilityVSAvoidsecurity integrity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

Before any reconfiguration occurs, the provisioning unit provides specific identifiers to the new configuration descriptions. This preliminary provisioning ensures that even as the system dynamically reconfigures, each new hardware application has exclusive access to its identifiers from the moment of configuration, preventing security compromises during the reconfiguration process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements a feedback mechanism where the provisioning unit continuously monitors and provides identifiers to configuration descriptions as they are loaded or reconfigured. This ensures that the security state is maintained and updated in real-time, allowing the system to adapt to reconfiguration while preserving security integrity through continuous identifier management.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3686763B1Computer-implemented device and method for processing data
Publication Date: 2021.03.24 SIEMENS AG
  • EP3686763B1 patent drawingFigure 1
  • EP3686763B1 patent drawingFigure 2~3

AI summary

A computer-implemented device (100) for processing data is proposed, comprising a digital component (10) with at least one part (11) reconfigurable by a number N of configuration descriptions (KB), with N ≥ 1, a specific configuration description (KB) from the number N for reconfiguring the reconfigurable part (11), and a provisioning unit (12) for providing an identifier (ID) specific to the specific configuration description (KB) using a number A of derivation parameters comprising the specific configuration description (KB), with A ≥ 1, wherein the part (11) reconfigured with the specific configuration description (KB) is configured to perform a cryptographic function on specific data using the provided specific identifier (ID) to generate cryptographically processed data (KVD).This makes it possible to implement security-relevant functions as configuration descriptions. This has the advantage of increasing security when processing data in digital modules.