Secure Payload Processing With External Security Appendix Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing secure computer systems face challenges in achieving high security with minimal computing effort, particularly in processing user data across secure and non-secure sections without overburdening the secure system with complex calculations.
Innovation Solution
A method where a secure computer system generates backup data and forms protected user data, which is then transferred to a non-secure system to create a security attachment. This attachment is verified in both systems before further processing, allowing for external checks and reducing the computational load on the secure system by leveraging the non-secure system's high computing performance for complex algorithms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the secure computer system section performs all security calculations including complex security appendix algorithms, then security verification capability is improved, but computing effort and hardware complexity of the secure system increases
Solution Approach 1:
The patent divides the security verification function into two segments: the secure computer system section generates protected payload data with security data using a security function, while the non-secure computer system section generates the security appendix using complex algorithms. This segmentation allows each section to perform only the calculations appropriate to its security level, reducing the computational burden on the secure system while maintaining comprehensive security verification capability.
2Reliability
If the secure computer system section generates both security data and security appendix, then security integrity is improved, but computing effort of the secure system increases
Solution Approach 1:
The patent extracts the computationally intensive security appendix generation from the secure computer system section and assigns it to the non-secure computer system section. The secure section retains only the essential security function for generating security data, while the extracted security appendix function is implemented in the non-secure section, thereby reducing the computing effort and energy consumption of the secure system while preserving security integrity through the two-stage verification process.
3Reliability
If complex security algorithms are implemented in the secure computer system section, then security strength is improved, but hardware requirements and cost increase
Solution Approach 1:
The non-secure computer system section acts as an intermediary that handles the complex security appendix calculations. This intermediary performs the computationally intensive algorithms using standard hardware resources, then transfers the results to the secure system for final verification. This approach allows strong security algorithms to be implemented without requiring the secure hardware to be overloaded with complex computational capabilities.
4Reliability
If the secure system processes all security functions internally, then security control is improved, but processing speed and efficiency decrease
Solution Approach 1:
The patent merges the secure computer system section with a non-secure computer system section to form a hybrid processing architecture. The secure section maintains control over critical security functions while the non-secure section handles computationally intensive operations. This combination allows the system to leverage the high processing speed of the non-secure section for security appendix generation while the secure section maintains oversight and performs final verification, thereby improving overall processing efficiency without compromising security control.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention relates, among other things, to a method for processing user data (ND).According to the invention, a secure computing section (10) of a computing system (100, 110) generates backup data (CRC(ND)) using the user data (ND) and a predefined backup function (CRC) and forms protected user data (ND*) with the backup data (CRC(ND)) and the user data (ND). The secure computing section (10) transfers the user data (ND*) protected with the backup data (CRC(ND)) to a non-secure computing section (20) of the same or a different computing system (100, 120). The non-secure computing section (20) uses the data received there as source data (ND**) to form a backup appendage (SA). The non-secure computing section (20) transfers the backup appendage (SA) to the secure computing section (10), and the secure computing section (10) uses the previously formed protected user data (ND*) and the received backup data (ND**) to form a backup appendage (SA). Security Annex (SA) further processed.