Secure Computing Environment for Multi-Protocol Cryptographic Processing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional systems for secure storage and handling of cryptographic keys are limited in their ability to support multiple protocols, leading to usability issues and increased risk of errors or fraud due to complex user interfaces and limited interoperability with various cryptographic systems.

Innovation Solution

A device incorporating a secure computing environment (SCE) and a general computing environment (GCE) that allows for secure multi-protocol processing of cryptographic data, enabling the composition of messages compliant with a wide range of protocols through schema data and request data processing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional systems use dedicated hardware for each cryptographic protocol, then security is improved, but device complexity and cost increase significantly

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple cryptographic protocol processing capabilities into a single secure element, replacing the need for separate dedicated hardware for each protocol. The secure element contains a programmable processor that can execute different cryptographic protocols through software configuration, thereby reducing device complexity while maintaining security through centralized protection of cryptographic operations.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The secure element is designed with universal functionality to support multiple cryptographic protocols (e.g., ISO 7816-4, SMART Card, FeliCa, NFC) within a single device. This multi-functional approach allows one hardware component to perform the roles of multiple dedicated components, reducing overall system complexity while maintaining protocol-specific security requirements through software-based protocol adaptation layers.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If traditional systems support multiple protocols through separate interfaces, then interoperability is improved, but ease of operation deteriorates due to complex user interfaces

Engineering Contradiction:
ImproveinteroperabilityVSAvoidease of operation
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary protocol adaptation layer within the secure element that translates between different protocol formats and a unified internal processing interface. This intermediary layer handles protocol-specific formatting and communication rules, allowing the secure element to interact with multiple external protocols while presenting a simplified, consistent interface to the host system and end users.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system architecture segments cryptographic functionality into distinct protocol adaptation layers within the secure element, separating protocol-specific processing from core cryptographic operations. This segmentation allows each protocol to be handled by its dedicated software module while sharing common security infrastructure, thereby improving interoperability without exposing protocol complexity to users.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If cryptographic operations are performed externally without a secure element, then ease of operation is improved, but security deteriorates due to exposure of private keys

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts private key storage and sensitive cryptographic operations into a separate secure element, isolating these critical assets from the host system and external interfaces. This extraction ensures that private keys never leave the secure element in unprotected form, maintaining security while allowing external systems to perform cryptographic operations by sending authenticated requests to the secure element's protected interface.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The secure element provides self-service capabilities by autonomously performing cryptographic operations (signing, encryption, key generation) internally without requiring external access to private keys. The secure element receives authenticated requests from external systems, processes them using its protected cryptographic resources, and returns results through secure channels, thereby maintaining both security and operational convenience.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12236002B2System for secure multi-protocol processing of cryptographic data
Publication Date: 2025.02.25 GRIDPLUS INC
  • US12236002B2 patent drawing
  • US12236002B2 patent drawing
  • US12236002B2 patent drawing

AI summary

A general computing environment (GCE) determines request data comprising payload data and instruction data to use cryptographic functions in a secure computing environment (SCE). The SCE provides secure input and output devices, allowing secure presentation to a user and acquisition of user input. The SCE receives the request data and processes the payload data using the instructions in the instruction data to produce cryptographic output data. The request data may be determined using schemas that specify the formatting, grammar, and other attributes of data associated with a transaction that utilizes cryptographic functions. By using schemas and the request data, the SCE may support any protocol that uses the cryptographic functions supported by that SCE to compose cryptographic output. To enhance user comprehensibility and security, the SCE may securely replace some data with human readable text or images and present this as abstracted request data.