Security Sensor Cryptography for Decentralized Tamper Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for detecting manipulation of devices in IT security lack a decentralized approach, relying on central units for evaluation and potentially leading to inefficiencies and increased complexity.

Innovation Solution

A method and device for decentralized manipulation detection using security sensors to record unevaluated measured values, which are then cryptographically protected and transmitted to an evaluation device for analysis, allowing for flexible manipulation detection and response without requiring complex logic on the device itself.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized evaluation units are used for manipulation detection, then security monitoring can be implemented, but device complexity and system overhead increase

Engineering Contradiction:
Improvemanipulation detection capabilityVSAvoidsystem structure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides manipulation detection functionality into two segments: (1) decentralized security sensors and crypto modules embedded in individual devices that autonomously generate and protect security data sets, and (2) centralized evaluation units that receive and assess these data sets. This segmentation allows devices to perform basic security functions independently while the central unit handles complex evaluation, reducing overall system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Security data sets act as an intermediary between the decentralized device level and the centralized evaluation unit. These data sets contain cryptographically protected measured values that can be independently generated by devices and then evaluated centrally, serving as a mediator that decouples the complexity of manipulation detection algorithms from individual devices while maintaining centralized security monitoring.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If complex manipulation detection logic is implemented on devices, then detection accuracy improves, but device resource requirements and complexity increase

Engineering Contradiction:
Improvemanipulation detection accuracyVSAvoiddevice processing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts complex manipulation detection logic from individual devices and relocates it to centralized evaluation units. Devices only need to perform simple functions: acquiring measured values via security sensors, cryptographically protecting these values using crypto modules, and transmitting the protected data sets. The complex evaluation of whether manipulation occurred is performed externally, reducing device complexity while maintaining detection accuracy.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Devices perform preliminary actions by acquiring measured values and cryptographically protecting them before transmission. The crypto modules generate security data sets with digital signatures or encryption in advance, so that when data reaches the evaluation unit, the complex manipulation detection can be performed efficiently without burdening the device with heavy processing requirements.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If cryptographic protection is applied to measured values, then security is improved, but processing time and computational overhead increase

Engineering Contradiction:
Improvedata securityVSAvoiddata processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system applies cryptographic protection selectively rather than to all data processing operations. Crypto modules protect only the essential measured values that indicate manipulation status, using efficient cryptographic algorithms appropriate for the security level required. This partial application of cryptographic protection maintains security for critical data while minimizing overall processing time overhead.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP3399457B1Method and devices for detecting a manipulation of a device
Publication Date: 2020.04.15 SIEMENS AG
  • EP3399457B1 patent drawingFigure 1~2
  • EP3399457B1 patent drawingFigure 3~4
  • EP3399457B1 patent drawingFigure 5~6

AI summary

The invention relates to methods and devices for transmitting measured values ​​from security sensors of a device to an evaluation unit in order to detect tampering. To achieve the highest possible level of security, the security sensors are configured to cryptographically protect the measured values ​​after acquisition before transmission to the evaluation unit. The evaluation unit can assess this cryptographic protection (e.g., cryptographic verification – in particular a digital signature – or decryption of the measured values) and additionally evaluate the measured values ​​to determine whether a corresponding device has been tampered with.