Secured Chip Cryptograph Conversion for Data Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for securing critical data during transmission from a secured input device to a remote server are impractical and insecure, as they require significant modifications to the input device and are vulnerable to attacks, especially when cryptograph conversion occurs on an open operating system.
Innovation Solution
A method utilizing a secured chip within a terminal that performs cryptograph conversion internally, parsing and re-encrypting critical data with preset keys to ensure it remains encrypted throughout the transmission process, preventing eavesdropping and theft by vicious software, and allowing for low-cost, easy customization of existing secured input devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the secured input device holds the key directly and encrypts critical data immediately, then the security of critical data is improved, but the device complexity and data processing capability requirements increase significantly
Solution Approach 1:
The system is divided into multiple components: the secured input device for initial encryption, the terminal for receiving cryptograph A, and the server for final verification. This segmentation allows each component to have specialized functions, reducing the complexity burden on any single device while maintaining overall security.
Solution Approach 2:
The terminal acts as an intermediary between the secured input device and the server. It receives the first cryptograph from the input device, converts it to a second cryptograph using a preset key, and forwards it to the server. This intermediary role eliminates the need for the input device to directly hold powerful processing capabilities while maintaining security.
2Ease of operation
If cryptograph conversion is performed on the PC platform using management and application software, then the ease of operation is improved, but the security of critical data deteriorates due to vulnerability to attacks from vicious software
Solution Approach 1:
The critical security function of cryptograph conversion is extracted from the vulnerable PC software environment and relocated to a secure terminal environment with a preset key. This extraction removes the security vulnerability from the operation chain while maintaining ease of use through automated terminal processing.
Solution Approach 2:
The terminal provides a secure, isolated environment for key-based cryptograph conversion, analogous to an inert atmosphere that protects sensitive reactions. This environment is resistant to attacks from vicious software, ensuring that critical data conversion occurs in a protected context while the PC platform remains easy to operate.
3Reliability
If the secured input device performs powerful data processing functions, then the security of critical data is improved, but the producibility and ease of manufacture deteriorate due to difficulty in rewriting or overwriting the device
Solution Approach 1:
The terminal is pre-configured with a preset key before operation. This preliminary setup enables the terminal to perform secure cryptograph conversion without requiring the secured input device to have complex pre-configured capabilities. The input device can be manufactured with simpler, more producible hardware while security is established in advance at the terminal level.
Data Source
AI summary
A method for guaranteeing the security of critical data, which is used in a terminal including a secured chip and includes the steps of: activating the secured chip by the terminal platform to receive cryptograph A of said critical data; parsing internally by the secured chip the cryptograph A with a preset key A to generate a plaintext, then encrypting said plaintext with a preset key B to generate cryptograph B, and returning the cryptograph B to the terminal platform. Since cryptograph conversion is performed inside the secured chip, and the process of converting the cryptograph A to the cryptograph B is completed inside the secured chip as a one-shot action, the secured chip cannot be eavesdropped upon or stolen by any vicious software, and thus the critical data is guaranteed to be always in a cryptograph status from the secured input device to the remote server, which ensures the security of the critical data. In addition, the present invention is low in cost, advantageous in spreading and application, and convenient in customization and upgrading. The present invention further provides a terminal and a secured chip.


