Dual Secure Microprocessor Server for Encrypted Configuration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for configuring secure microprocessors rely on non-secure devices, creating security vulnerabilities, especially when operating in field environments where traditional security measures are difficult to implement effectively.
Innovation Solution
A security server system utilizing two secure microprocessors to manage and encrypt configuration data, application information, and security settings for secure microprocessors, ensuring secure communication and verification of configuration data to prevent unauthorized access and tampering.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If conventional personal computers are used to program secure microprocessors, then ease of operation is improved, but security deteriorates due to lack of secure processing environment
Solution Approach 1:
The patent introduces a security server as an intermediary device between the conventional personal computer and the secure microprocessor. The security server performs all sensitive operations including configuration collection, encryption, and secure communication through dedicated secure interfaces. This mediator approach allows users to operate from conventional PCs while maintaining security through the specialized server hardware and encrypted communication channels.
2Reliability
If field security measures are implemented, then security is improved, but device complexity increases due to additional security infrastructure requirements
Solution Approach 1:
The security server performs all security-related operations in advance before the secure microprocessor is deployed to the field. Configuration data is collected, encrypted, and validated on the security server prior to programming. The secure microprocessor receives pre-processed configuration through secure interfaces, eliminating the need for complex security infrastructure in the field environment while maintaining high security standards.
3Reliability
If comprehensive security features are added to the microprocessor, then security is improved, but manufacturing precision requirements increase
Solution Approach 1:
The security server incorporates verification mechanisms that provide feedback during the configuration process. After configuration data is programmed into the secure microprocessor, the system verifies the programmed data against the original configuration to ensure accuracy and integrity. This feedback loop detects and corrects any manufacturing or programming errors, maintaining high precision without requiring overly complex manufacturing processes.
Data Source
AI summary
A security server for programming configuration settings and application images into a target device is disclosed. The security server includes two secure microprocessors. In the security server a first microprocessor is configured to be coupled to a user of the security server and a comparator to validate configuration data as it progresses through the security server. The first microprocessor receives configuration data and application data for use in configuring the target microprocessor. A second secure microprocessor is coupled to the first secure microprocessor through a high-speed communications link. This second microprocessor provides a security engine for encryption of data and a verifier for verifying that the configuration settings and application images are correctly stored in the target microprocessor.


