Self-securing Processor Unit for Metering Device Data Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Devices in metering networks are vulnerable to tampering and data theft due to lack of internal security, which can lead to unauthorized access and destabilization of the distribution grid, as existing security solutions primarily focus on network communication rather than device-level data protection.
Innovation Solution
Implementing a self-securing mechanism within devices using a processor unit and external non-volatile memory, where a unique secure key is generated and stored to encrypt and decrypt data, preventing unauthorized access by disabling external interfaces like JTAG and using it to secure data stored in non-volatile memory.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security measures are added to protect data stored in device memory, then data security is improved, but device complexity increases
Solution Approach 1:
The patent applies preliminary action by generating and storing a secure key in processor unit memory before any data is stored in external non-volatile memory. This pre-established security mechanism ensures that all subsequent data operations are automatically protected without requiring additional complexity during normal device operation.
Solution Approach 2:
The device performs self-securing by automatically generating its own secure key and using it to encrypt/decrypt data in external memory. The processor unit independently manages its own security without requiring external security modules or complex security infrastructure, thereby improving data security while minimizing added complexity.
2Reliability
If external interfaces like JTAG are disabled for security, then security against tampering is improved, but ease of repair and testing deteriorates
Solution Approach 1:
The secure key is generated and stored in processor unit memory before the device is deployed to the field. This preliminary security setup ensures that even if physical access is gained later, the data in external memory remains protected, maintaining security while allowing standard repair interfaces to remain functional for non-security-related maintenance.
3Reliability
If a secure key is generated and stored in processor unit memory, then data confidentiality is improved, but memory usage increases
Solution Approach 1:
The patent uses a single, small secure key stored in processor unit memory that serves as a disposable security credential. This minimal memory footprint approach provides strong confidentiality protection without consuming significant memory resources, as the key is small and can be regenerated if compromised.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Systems and methods are provided for securing a self-securing device and information that is stored in memory within the device. The self-securing device comprising a processor unit and memory external to the processor unit. The processor unit contains a processor and processor unit memory. Upon initialization of the self-securing device, the processor unit determines whether a secure key is stored in the processor unit memory. If no secure key is stored, then the processor unit generates a secure key and stores it in the processor unit memory. The processor unit uses the secure key to decrypt information read from the memory external to the processor unit and to encrypt information to be stored in memory external to the processor unit.