Secure Payload Processing With External Security Appendix Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure computer systems face challenges in achieving high security with minimal computing effort, particularly in processing user data across secure and non-secure sections without overburdening the secure system with complex calculations.

Innovation Solution

A method where a secure computer system generates backup data and forms protected user data, which is then transferred to a non-secure system to create a security attachment. This attachment is verified in both systems before further processing, allowing for external checks and reducing the computational load on the secure system by leveraging the non-secure system's high computing performance for complex algorithms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the secure computer system section performs all security calculations including complex security appendix algorithms, then security verification capability is improved, but computing effort and hardware complexity of the secure system increases

Engineering Contradiction:
Improvesecurity verification capabilityVSAvoidhardware and software expenditure of secure system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the security verification function into two segments: the secure computer system section generates protected payload data with security data using a security function, while the non-secure computer system section generates the security appendix using complex algorithms. This segmentation allows each section to perform only the calculations appropriate to its security level, reducing the computational burden on the secure system while maintaining comprehensive security verification capability.

Inventive Principle:
Principle #1Segmentation

2Reliability

If the secure computer system section generates both security data and security appendix, then security integrity is improved, but computing effort of the secure system increases

Engineering Contradiction:
Improvesecurity integrityVSAvoidcomputing effort of secure system
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts the computationally intensive security appendix generation from the secure computer system section and assigns it to the non-secure computer system section. The secure section retains only the essential security function for generating security data, while the extracted security appendix function is implemented in the non-secure section, thereby reducing the computing effort and energy consumption of the secure system while preserving security integrity through the two-stage verification process.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If complex security algorithms are implemented in the secure computer system section, then security strength is improved, but hardware requirements and cost increase

Engineering Contradiction:
Improvesecurity strengthVSAvoidhardware requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The non-secure computer system section acts as an intermediary that handles the complex security appendix calculations. This intermediary performs the computationally intensive algorithms using standard hardware resources, then transfers the results to the secure system for final verification. This approach allows strong security algorithms to be implemented without requiring the secure hardware to be overloaded with complex computational capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If the secure system processes all security functions internally, then security control is improved, but processing speed and efficiency decrease

Engineering Contradiction:
Improvesecurity controlVSAvoidprocessing speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges the secure computer system section with a non-secure computer system section to form a hybrid processing architecture. The secure section maintains control over critical security functions while the non-secure section handles computationally intensive operations. This combination allows the system to leverage the high processing speed of the non-secure section for security appendix generation while the secure section maintains oversight and performs final verification, thereby improving overall processing efficiency without compromising security control.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP4362363A1Methods and systems for processing payload data
Publication Date: 2024.05.01 SIEMENS MOBILITY GMBH
  • EP4362363A1 patent drawingFigure 1
  • EP4362363A1 patent drawingFigure 2
  • EP4362363A1 patent drawingFigure 3

AI summary

The invention relates, among other things, to a method for processing user data (ND).According to the invention, a secure computing section (10) of a computing system (100, 110) generates backup data (CRC(ND)) using the user data (ND) and a predefined backup function (CRC) and forms protected user data (ND*) with the backup data (CRC(ND)) and the user data (ND). The secure computing section (10) transfers the user data (ND*) protected with the backup data (CRC(ND)) to a non-secure computing section (20) of the same or a different computing system (100, 120). The non-secure computing section (20) uses the data received there as source data (ND**) to form a backup appendage (SA). The non-secure computing section (20) transfers the backup appendage (SA) to the secure computing section (10), and the secure computing section (10) uses the previously formed protected user data (ND*) and the received backup data (ND**) to form a backup appendage (SA). Security Annex (SA) further processed.