Secure Circuit Authentication via Peripheral Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Non-secure electronic devices are vulnerable to security breaches due to their high personalization and openness, allowing malware to intercept and modify user interactions, making it difficult for users to ensure a secure connection with secure electronic devices.

Innovation Solution

A method and circuit configuration that allows a secure electronic circuit to take control of input and output peripherals, establish a secure session, acquire and transform user information, and authenticate the secure electronic device, ensuring a trusted connection by receiving and verifying transformed user information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If interfaces of non-secure electronic device are opened up to enable third-party software development, then flexibility and functionality are improved, but security vulnerability increases

Engineering Contradiction:
ImproveflexibilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent divides the electronic device into two separate processing circuits: a non-secure processing circuit that handles user interface and applications, and a secure processing circuit that handles authentication and security functions. This segmentation allows the non-secure circuit to maintain flexibility while the secure circuit provides protective isolation against malware and unauthorized access.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The secure processing circuit acts as an intermediary between the non-secure processing circuit and the secure electronic device. It receives authentication data from the non-secure circuit, performs security verification, and only allows authenticated operations to proceed. This intermediary layer protects the system while maintaining functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If secure electronic circuit is installed in non-secure electronic device, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines the secure processing circuit with the existing non-secure processing circuit within the same electronic device. Both circuits share common hardware resources such as processors, memory, and peripheral interfaces, thereby providing enhanced security without proportionally increasing device complexity or hardware requirements.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If part of screen is reserved for secure electronic circuit, then authentication reliability is improved, but usability deteriorates

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidusability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The secure processing circuit serves as an intermediary that handles authentication functions without directly controlling the user interface. It communicates with the non-secure processing circuit through standardized interfaces, allowing authentication to occur transparently in the background without requiring dedicated screen real estate or affecting user interaction with applications.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Loss of information

If LED is integrated to indicate secure mode, then user awareness of secure connection is improved, but hardware cost increases

Engineering Contradiction:
Improveuser awarenessVSAvoidhardware cost
Core Design Contradiction:
Loss of informationVSEase of manufacture

Solution Approach 1:

The system uses existing display hardware and processing capabilities to provide user feedback about secure connection status. The non-secure processing circuit can utilize the same screen and processing resources already present in the device to display authentication status messages, eliminating the need for additional dedicated hardware indicators like LEDs.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9781093B2Authentication of a secure electronic device from a non-secure electronic device
Publication Date: 2017.10.03 IDEMIA PUBLIC SECURITY FRANCE
  • US9781093B2 patent drawing
  • US9781093B2 patent drawing
  • US9781093B2 patent drawing

AI summary

The application relates in particular to a method for authentication of a secure electronic device (BNK_SRV) from a non-secured electronic device (PC, SP) comprising an input peripheral (KBD, MS, TS, CAM), an output peripheral (SCR, SPK, PRN) and a secure electronic circuit (TPM).The application also relates to a secure electronic circuit (TPM), a computer program and a storage medium arranged to implement such a method.