Dual Secure Microprocessor Server for Encrypted Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for configuring secure microprocessors rely on non-secure devices, creating security vulnerabilities, especially when operating in field environments where traditional security measures are difficult to implement effectively.

Innovation Solution

A security server system utilizing two secure microprocessors to manage and encrypt configuration data, application information, and security settings for secure microprocessors, ensuring secure communication and verification of configuration data to prevent unauthorized access and tampering.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional personal computers are used to program secure microprocessors, then ease of operation is improved, but security deteriorates due to lack of secure processing environment

Engineering Contradiction:
Improveease of programmingVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a security server as an intermediary device between the conventional personal computer and the secure microprocessor. The security server performs all sensitive operations including configuration collection, encryption, and secure communication through dedicated secure interfaces. This mediator approach allows users to operate from conventional PCs while maintaining security through the specialized server hardware and encrypted communication channels.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If field security measures are implemented, then security is improved, but device complexity increases due to additional security infrastructure requirements

Engineering Contradiction:
ImprovesecurityVSAvoidsecurity infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security server performs all security-related operations in advance before the secure microprocessor is deployed to the field. Configuration data is collected, encrypted, and validated on the security server prior to programming. The secure microprocessor receives pre-processed configuration through secure interfaces, eliminating the need for complex security infrastructure in the field environment while maintaining high security standards.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If comprehensive security features are added to the microprocessor, then security is improved, but manufacturing precision requirements increase

Engineering Contradiction:
ImprovesecurityVSAvoidconfiguration accuracy
Core Design Contradiction:
ReliabilityVSManufacturing precision

Solution Approach 1:

The security server incorporates verification mechanisms that provide feedback during the configuration process. After configuration data is programmed into the secure microprocessor, the system verifies the programmed data against the original configuration to ensure accuracy and integrity. This feedback loop detects and corrects any manufacturing or programming errors, maintaining high precision without requiring overly complex manufacturing processes.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9195806B1Security server for configuring and programming secure microprocessors
Publication Date: 2015.11.24 THE BOEING CO
  • US9195806B1 patent drawing
  • US9195806B1 patent drawing
  • US9195806B1 patent drawing

AI summary

A security server for programming configuration settings and application images into a target device is disclosed. The security server includes two secure microprocessors. In the security server a first microprocessor is configured to be coupled to a user of the security server and a comparator to validate configuration data as it progresses through the security server. The first microprocessor receives configuration data and application data for use in configuring the target microprocessor. A second secure microprocessor is coupled to the first secure microprocessor through a high-speed communications link. This second microprocessor provides a security engine for encryption of data and a verifier for verifying that the configuration settings and application images are correctly stored in the target microprocessor.