Secure Module Data Transfer via Internal Session Key

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Electronic systems face security risks during data transfer, as security data can be leaked when the system is attacked, necessitating a secure method for data transfer between components.

Innovation Solution

A method involving a secure module with a processor and a secure element, performing cross-authentication, generating a session key, and encrypting data using this key to ensure secure data transfer, while switching between operation modes to facilitate secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is transferred through external buses between secure module and application processor, then data transfer functionality is achieved, but security is compromised when external buses are probed

Engineering Contradiction:
Improvedata transfer securityVSAvoidexternal bus probing attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary secure channel between the secure module and application processor that does not rely on external buses. This intermediary communication path allows data transfer while avoiding the vulnerability of external bus probing attacks, thus resolving the contradiction between achieving data transfer functionality and maintaining security against external bus probing.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cross-authentication and session key generation are performed, then data transfer security is enhanced, but communication overhead increases

Engineering Contradiction:
Improvedata transfer securityVSAvoidcommunication overhead
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent implements preliminary cross-authentication and session key generation before actual data transfer. By establishing secure credentials and encryption keys in advance, the system reduces the overhead during subsequent data transfer operations, as the authentication and encryption frameworks are already in place, thus resolving the contradiction between enhancing security and minimizing communication overhead.

Inventive Principle:
Principle #10Preliminary action

3Loss of energy

If secure module operates within single package, then communication overhead is reduced, but device complexity increases

Engineering Contradiction:
Improvecommunication overheadVSAvoidsecure module integration
Core Design Contradiction:
Loss of energyVSDevice complexity

Solution Approach 1:

The patent merges the secure module components (processor, secure element, memory) into a single integrated package. This consolidation reduces communication overhead by eliminating external bus transactions between separate components while the modular design maintains manageability, thus resolving the contradiction between reducing communication overhead and managing device complexity.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9858429B2Methods of data transfer in electronic devices
Publication Date: 2018.01.02 SAMSUNG ELECTRONICS CO LTD
  • US9858429B2 patent drawing
  • US9858429B2 patent drawing
  • US9858429B2 patent drawing

AI summary

A method of data transfer in an electronic device including a secure module, which includes a processor and a secure element, an application processor, and a sensor, may include: switching an operation mode of the processor to a bypass mode; performing a cross-authentication, by the application processor and the secure element; generating a session key, by the application processor and the secure element, when the cross-authentication is succeeded; switching the operation mode of the processor to a normal mode; encrypting, by the secure module, sensing data provided by the sensor using the session key; transferring the encrypted sensing data from the processor to the application processor; and/or acquiring, by the application processor, the sensing data by decrypting the encrypted sensing data using the session key.