Sensor Apparatus Secure Computing Segmentation for Temperature Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing sensor devices for motor vehicles, particularly those coupled to tachographs, face challenges in operating reliably across a wide temperature range (-40 to +150°C) while ensuring security against unauthorized access and manipulation.
Innovation Solution
A sensor device with a secure first computing device and a second computing device, where the first computing device is only operational within a low temperature range, and the session key is stored in the second memory for secure encryption and signing of data, ensuring protection against unauthorized access and manipulation across the broader temperature range.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a secure computing device is used for encryption and data protection, then security against unauthorized access is improved, but the device can only operate within a limited temperature range
Solution Approach 1:
The system is divided into two computing devices: a secure computing device for cryptographic operations and a second computing device for general control. This segmentation allows each device to be optimized for its specific function, with the secure device operating only within its temperature limitations while the overall system maintains broader temperature adaptability.
Solution Approach 2:
The second computing device acts as an intermediary that takes over control functions when the secure computing device is inactive due to temperature constraints. This mediator ensures continuous system operation across varying temperature conditions while maintaining security through the secure device when available.
2Reliability
If the secure computing device operates continuously, then security is maintained, but power consumption increases and cost-effectiveness decreases
Solution Approach 1:
The secure computing device operates periodically rather than continuously, activating only when temperature conditions permit and cryptographic operations are required. This periodic operation significantly reduces power consumption while maintaining security through intermittent but sufficient cryptographic verification and data protection.
Solution Approach 2:
The system automatically manages the activation and deactivation of the secure computing device based on temperature conditions and operational requirements, eliminating the need for continuous power supply and manual intervention while maintaining security protocols.
3Reliability
If the session key is stored in the second memory, then access to sensitive information is protected when power is removed, but the device must rely on temperature-dependent secure computing for key management
Solution Approach 1:
The session key is extracted from the secure computing device and stored in the second memory of the second computing device. This extraction allows the key to persist when power is removed while the secure computing device remains inactive during temperature excursions, simplifying the overall key management architecture.
Solution Approach 2:
The session key is generated and stored in advance in the second memory before power removal or temperature excursions occur. This preliminary action ensures that cryptographic credentials are ready and protected without requiring continuous operation of the secure computing device.
Data Source
Figure 1
Figure 2~3
Figure 4
AI summary
A sensor apparatus comprises a housing (G) with a security device (SE), a secure first computation device (SC), a second computation device (AC) and at least one sensor element (SENS). The sensor apparatus is designed to detect a temperature (T) in the housing (G), to activate the first computation device (SC) only when the detected temperature (T) is in a predefined temperature range, to determine a session key (SS) by means of the first computation device (SC) and to store the session key (SS) in a second memory (DMEM) of the second computation device (AC), to deactivate the first computation device (SC) after the session key (SS) has been stored, to determine data on the basis of a sensor signal (SIG) detected using the at least one sensor element (SENS) and to encrypt and/or sign the data by means the second computation device (AC) on the basis of the session key (SS).