Segmented Integrity Tables for Secure External Memory Loading
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing digital information processing devices face challenges in securely authenticating and encrypting data due to limited storage capacity and the need for unique keys, which is costly and inefficient in production.
Innovation Solution
A method involving segmenting digital information, generating integrity elements, and using both global and unique keys for encryption and authentication, with integrity tables stored in the processing device to ensure secure and efficient loading and processing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a unique key is used to authenticate digital information for each processing device, then security and authentication reliability are improved, but production cost and complexity increase due to the need to produce as many signatures as there are processing devices
Solution Approach 1:
The patent segments the authentication process into two parts: a global key that authenticates the digital information itself, and a unique key that only authenticates the processing device. The digital information is encrypted with the global key and authenticated with a digital signature using the global key. Each processing device has its own unique key for authenticating device-specific operations. This segmentation allows the same digital information to be distributed to multiple devices without requiring unique signatures for each device, thereby reducing production complexity while maintaining security.
Solution Approach 2:
The patent introduces a global key as an intermediary that mediates between the digital information provider and multiple processing devices. The global key serves as a common authentication mechanism that can be used by any number of devices without requiring individual signatures for each device. This intermediary approach resolves the contradiction by enabling universal authentication without the need to produce unique signatures for each processing device, thus reducing production complexity while maintaining authentication reliability.
2Quantity of substance
If digital information is stored in an external memory with large storage capacity, then storage capacity is improved, but the processing device cannot load all digital information at one time due to limited volatile memory
Solution Approach 1:
The patent divides the digital information into multiple segments that can be loaded into the processing device one at a time or in batches. Each segment contains a portion of the digital information along with its associated integrity elements. This segmentation allows the processing device to manage large storage capacity in external memory while loading only the necessary portions into volatile memory for processing, thereby resolving the contradiction between storage capacity and loading speed.
3Productivity
If integrity data is stored separately from encrypted segments, then memory requirements and processing efficiency are improved, but the complexity of loading and verifying increases
Solution Approach 1:
The patent combines the integrity data with the encrypted segments in a structured manner where each segment includes both the encrypted data and its corresponding integrity elements. This merging approach allows the processing device to load and process segments efficiently while maintaining the separation of integrity verification from the main data processing flow. The integrity elements are embedded within the segment structure, enabling parallel processing and reducing overall system complexity.
Data Source
AI summary
A method is provided in which digital information is stored in a plurality of segments in an external memory. The method is performed by a processing device and comprises the steps of loading a first integrity table containing a plurality of first integrity elements respectively authenticating the plurality of segments of digital information, and an associated digital signature of the plurality of first integrity elements, from the external memory; verifying the digital signature associated with the first integrity table, and loading segments of digital information in a protected form from the external memory to the processing device.


