Secure Message Transmission Apparatus with Domain Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for secure message transmission are vulnerable to man-in-the-middle attacks, which can lead to message content changes or extortion, and exposure of encryption/decryption keys, compromising security.
Innovation Solution
Implementing a secure message transmission apparatus with physically separated secure and non-secure domains, using a secure operating system for encryption and decryption, and a non-secure operating system for message processing, to block unauthorized access and prevent key leakage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If message verification is performed after receipt using conventional methods, then message authenticity can be checked, but the system becomes vulnerable to man-in-the-middle attacks during transmission
Solution Approach 1:
The patent applies preliminary action by encrypting the message content before transmission occurs. The encryption is performed in advance during the message creation phase, so that when the message travels through the network, it is already protected. This resolves the contradiction by ensuring authenticity verification capability is established before transmission, eliminating the window of vulnerability to man-in-the-middle attacks.
Solution Approach 2:
The patent applies preliminary anti-action by pre-encrypting the message content to counteract potential man-in-the-middle attacks. The encryption operation is performed beforehand to neutralize the threat of interception and modification during transmission. This creates a defensive measure that acts against the harmful factor before the transmission process begins.
2Reliability
If encryption/decryption keys are used for secure message transmission, then message confidentiality is improved, but keys may be exposed during decryption processes
Solution Approach 1:
The patent applies the taking out principle by extracting the encryption/decryption key from the message processing flow. The key is stored separately in a secure key storage unit, isolated from the message encryption and decryption operations. This separation prevents the key from being exposed during message processing, as the key never resides in the same system components that handle the message content.
Solution Approach 2:
The patent applies segmentation by dividing the message transmission system into distinct functional components: a message processing unit that handles encryption/decryption operations and a separate secure key storage unit that holds the cryptographic keys. This segmentation ensures that even if the message processing unit is compromised, the keys remain protected in the isolated storage unit, preventing key exposure.
3Ease of operation
If screen capture methods are used to display decrypted messages, then message readability is improved, but security is compromised through potential leakage
Solution Approach 1:
The patent applies the taking out principle by extracting the decrypted message content from the general system memory and presenting it through a dedicated secure output interface. The message is taken out of the vulnerable system environment and delivered through a controlled path that prevents unauthorized capture or leakage, while still providing readable output to the user.
Data Source
Figure 1
Figure 2
Figure 3~4
AI summary
The present document relates to a security message transmission apparatus and a processing method therefor. A security message processing method according to an embodiment of the present document comprises the steps of: receiving a message transmitted from an originating terminal and determining whether the message is an encrypted message, by a non-security message service unit; when the message is an encrypted message, transmitting the encrypted message to a security message service unit, by the non-security message service unit; and decoding the encrypted message, encrypting the decrypted message again, and then transmitting the message to a receiving terminal, by the security message service unit.