Secure Controller Systems with Cryptographic Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional networked computer systems are vulnerable to unauthorized access and cyber-attacks, which can lead to significant consequences in critical infrastructure and data security breaches, as they rely on network traffic monitoring that often misses breaches until they occur.

Innovation Solution

The implementation of a secure computer system using hardware cryptographic processing, redundancy, and adaptive cryptographic key management to protect real-time control systems, including programmable logic controllers and autonomous vehicles, by employing unique cryptographic key sets for each system and dynamic reconfiguration to prevent unauthorized access and detect compromised devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network traffic monitoring is used to detect security breaches, then system complexity is reduced, but security reliability deteriorates as breaches are easily missed and detected only after occurrence

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary cryptographic verification of code integrity before execution. A cryptographic processor verifies cryptographic hashes of code segments prior to allowing their execution, preventing unauthorized or malicious code from running in the first place rather than detecting breaches after they occur through network monitoring

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a cryptographic processor as an intermediary component between the code storage and execution units. This dedicated hardware component performs cryptographic verification operations, separating security functions from general system operations and improving both security reliability and system organization

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If conventional security monitoring is implemented, then ease of operation is maintained, but loss of information increases as security breaches go undetected

Engineering Contradiction:
Improveinformation securityVSAvoidoperational simplicity
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The system performs self-verification through automatic cryptographic checking of code integrity. The cryptographic processor automatically verifies hashes of code segments before execution without requiring manual intervention, and the system autonomously responds to verification failures by preventing execution or triggering alerts, thereby protecting information security while maintaining ease of operation

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements feedback mechanisms where the cryptographic processor continuously monitors code integrity and provides feedback to the control system. When code segments fail cryptographic verification, the system receives feedback signals that trigger appropriate responses such as blocking execution or generating security alerts, ensuring information security without complicating operation

Inventive Principle:
Principle #23Feedback

3Reliability

If cryptographic verification of all code segments is performed, then security reliability improves, but processing speed deteriorates due to increased verification overhead

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidprocessing speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent applies cryptographic verification selectively rather than uniformly to all code. The system verifies cryptographic hashes of code segments loaded into memory, particularly focusing on critical segments, while using caching mechanisms to avoid repeated verification of the same code. This partial verification approach maintains high security reliability for critical operations while minimizing processing speed impact

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system performs cryptographic verification in advance during code loading and memory initialization phases, before code execution begins. By completing verification operations preliminarily, the system ensures security reliability is maintained while avoiding speed penalties during actual code execution, as verified code can be cached and executed without repeated verification overhead

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11200347B1Secure controller systems and associated methods thereof
Publication Date: 2021.12.14 DROPPS FR R
  • US11200347B1 patent drawing
  • US11200347B1 patent drawing
  • US11200347B1 patent drawing

AI summary

Systems and methods for encrypted processing are provided. For example, an apparatus for encrypted processing includes: an input interface adapted to receive input from a device; an encrypted processor connected to the input interface; a program store control connected to the encrypted processor, the program store control controlling use of and access to at least two program stores, where at least one program store acts as a primary program store and at least one program store acts as a back-up program store; and an output interface connected to the encrypted processor for outputting at least one of commands or data; where the encrypted processor is programmed to: receive and validate a request; determine whether a valid request is a program update request for a first program; and initiate a lock mechanism into a locked state.