Security Chip with I/O Encryption for Data Leakage Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security chips do not guarantee the safety of information input and output processes, as they only monitor data within the processing apparatus and fail to verify data entering or leaving the system, leaving it vulnerable to unauthorized access and data leakage.

Innovation Solution

The introduction of a security chip with a security I/O module that encrypts and decrypts data both incoming from input devices, such as keyboards and mice, and outgoing to output devices, like audio and video cards, ensuring secure data transmission through the use of a processor module, encryption/decryption module, storage module, and power detecting module connected via an internal bus.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a security chip only monitors data inside the processing apparatus, then the internal data integrity can be verified, but the safety of input and output data processes cannot be guaranteed

Engineering Contradiction:
Improvedata securityVSAvoiddata monitoring coverage
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The security chip is divided into functionally independent modules: a first security module for monitoring internal data, a second security module for encrypting input data, and a third security module for decrypting output data. This segmentation allows each module to specialize in specific security functions, enabling comprehensive data protection both inside and outside the processing apparatus without compromising any single module's performance.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security chip is designed with multi-functionality to handle multiple security tasks simultaneously: internal data monitoring, input data encryption, and output data decryption. This universal design enables the single security chip to provide comprehensive security coverage across all data flows (input, internal, and output) rather than requiring separate dedicated chips for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If a security chip encrypts and decrypts all input and output data, then data transmission security is improved, but the processing complexity increases

Engineering Contradiction:
Improvedata transmission securityVSAvoidprocessing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The encryption and decryption functions are segmented into dedicated second and third security modules, separate from the first security module that handles internal data monitoring. This modular segmentation allows the encryption/decryption operations to be optimized independently and reduces the processing burden on any single module, making the overall system more manageable despite the enhanced security functionality.

Inventive Principle:
Principle #1Segmentation

3Reliability

If a security chip monitors all data entering or leaving the system, then information leakage is prevented, but the processing time increases

Engineering Contradiction:
Improveinformation protectionVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The security chip segments monitoring functions into a dedicated first security module that operates independently from the encryption and decryption modules. This allows parallel processing where internal data monitoring occurs simultaneously with input encryption and output decryption operations, reducing the total processing time while maintaining comprehensive monitoring coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security chip implements continuous security monitoring and encryption/decryption operations without interruption to the data flow. The dedicated security modules operate continuously in the background, ensuring that all data entering or leaving the system is protected without requiring pauses or additional processing steps that would increase overall processing time.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS7987374B2Security chip
Publication Date: 2011.07.26 LENOVO SOFTWARE
  • US7987374B2 patent drawing
  • US7987374B2 patent drawing
  • US7987374B2 patent drawing

AI summary

Two kinds of security chips having a security interface are provided. One kind of security chip comprises a processor module, an encrypt/decrypt module, a memory module, a power detecting module and a security I/O module, and all of the modules are connected with each other by an internal bus in the security chip; the other kind of security chip comprises a processor module, an encrypt/decrypt module, a memory module, a power detecting module and an I/O interface module, all of the modules being connected with each other by the internal bus in the security chip, wherein, the security chip also comprises a security input module, a security output module and a south bridge interface module, and all of the modules are connected with each other by the internal bus in the security chip. With the security chip provided by the present invention, it is possible to encrypt/decrypt the I/O information of an information processing device, ensure the safety of the I/O information, and thus prevent the information from being listened to or otherwise revealed.