Secure Processor Hardware Access Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computing networks face significant security challenges due to insecure connections and lack of protection for hardware resources, with existing solutions being either non-scalable or not addressing access to non-computing hardware devices effectively.

Innovation Solution

A computer-implemented method and system that uses a secure processor to encrypt and decrypt requests for access to hardware devices, requiring an encrypted private key for operating system access, providing additional layers of security through a secure application and legacy sensor access system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption keys are embedded in hardware, then security is improved, but scalability deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidscalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent extracts the encryption functionality from individual hardware devices and centralizes it in dedicated security computers. Each hardware device removes its embedded encryption keys and instead communicates encrypted requests to security computers that perform the decryption and key management centrally, enabling scalability while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces security computers as intermediary components between requesting computers and hardware devices. These intermediaries handle the encryption/decryption operations and key management, allowing hardware devices to remain simple while providing scalable security through the intermediary layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If traditional security mechanisms are used, then ease of operation is maintained, but security against attacks deteriorates

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces traditional software-based security mechanisms with a hardware-centric approach using secure processors and encrypted communication protocols. This substitution provides stronger security guarantees while maintaining ease of operation through automated encryption/decryption processes that require no user intervention.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent implements preliminary security measures by establishing encrypted communication channels and authentication mechanisms before any hardware device access occurs. Security computers pre-validate requests and establish secure sessions, preventing attacks before they can compromise the system.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If access control is restricted to known devices, then security is improved, but adaptability to new devices deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidadaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic access control where the security computer can adapt to new requesting computers and hardware devices in real-time. Instead of static whitelists, the system dynamically establishes encrypted sessions and validates credentials on-demand, allowing both security and adaptability to new devices.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9832199B2Protecting access to hardware devices through use of a secure processor
Publication Date: 2017.11.28 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US9832199B2 patent drawing
  • US9832199B2 patent drawing
  • US9832199B2 patent drawing

AI summary

A computer-implemented method, system, and/or computer program product protects access to hardware devices through use of a secure processor. A security computer receives a request from a requesting computer for access to a hardware device on a network. A secure processor within the security computer encrypts the request to generate an encrypted request, which is generated within a core of the secure processor. The secure processor protects a secure application that is used to process the request from other software on the secure processor. The security computer transmits the encrypted request to the hardware device, and then receives an encrypted acknowledgement of the encrypted request from a processor associated with the hardware device. The security computer then creates a communication session between the requesting computer and the hardware device.