Security Device for Embedded Control Cyber Attack Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Embedded control devices face limitations in computer resources, such as CPU, ROM, and RAM, which hinder the implementation of high-security functions against cyber attacks without compromising their primary functions, often requiring resource-intensive enhancements that increase the device's cost and complexity.
Innovation Solution
A security device with an attack detection part, security risk state determination part, and execution environment controller that dynamically adjusts the execution environment to execute security functions based on detected risks, allowing for appropriate security measures without significantly impacting the main function's execution.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If high-security functions such as encryption processing are mounted on the embedded control device, then security protection capability is improved, but the main function execution is compromised due to limited computer resources
Solution Approach 1:
The patent segments the security function execution from the main control device by introducing a separate security device that handles authentication and encryption tasks. The embedded control device only performs simple authentication verification, while the security device manages resource-intensive cryptographic operations, thus protecting the main function execution from resource consumption.
Solution Approach 2:
The patent introduces a dedicated security device as an intermediary between the embedded control device and external systems. This security device acts as a mediator that handles all security-related computations and communications, allowing the embedded control device to maintain its primary functions without being burdened by security processing overhead.
2Reliability
If computer resources are enhanced to support high-security functions, then security protection capability is improved, but device cost increases
Solution Approach 1:
The patent extracts the resource-intensive security processing functions from the embedded control device and places them in a separate security device. This extraction allows the embedded control device to maintain low cost with minimal resources while still achieving high security through the dedicated security device that handles authentication and encryption operations.
Solution Approach 2:
The security device is designed as a universal security module that can be applied to multiple different embedded control devices and application scenarios. By creating a standalone security device with multi-functional capabilities (authentication, encryption, key management), the solution achieves high security without requiring each embedded control device to be customized with expensive high-performance resources.
3Reliability
If authentication processing is performed frequently to detect cyber attacks, then security detection capability is improved, but processing time and resource consumption increase
Solution Approach 1:
The patent implements preliminary authentication where authentication information is exchanged and verified in advance during normal operations. When a cyber attack is suspected, the system can quickly reference pre-established authentication states and credentials, enabling rapid detection without performing complete authentication cycles, thus reducing processing time while maintaining detection capability.
Data Source
AI summary
A security device includes an attack detection part, a security risk state determination part, and an execution environment controller. The attack detection part detects a cyber attack on an embedded device controlled by an embedded control device. The security risk state determination part determines a security risk state indicating at least one of a type and degree of risk of threat in a security caused by the cyber attack based on a result of the detection. The execution environment controller is included in the embedded control device, determines a security function against the cyber attack in accordance with the security risk state, and constitutes an execution environment of the security function in the embedded control device so that the embedded control device can execute the security function.


