Sensor Data Authentication Using Compressed Hash References
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The transition to digital storage media has made it easier to manipulate and suppress sensor data without leaving physical traces, complicating the detection of unauthorized alterations.
Innovation Solution
An authentication module that integrates with sensors and cameras to create compressed products of sensor data, which serve as authentications, ensuring data integrity by allowing detection of modifications and suppressions through distributed storage and cryptographic methods.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If sensor data is stored in digital form, then storage capacity and cost efficiency are improved, but susceptibility to manipulation and suppression increases
Solution Approach 1:
The patent applies preliminary action by computing cryptographic hash values of sensor data immediately upon generation, before the data leaves the sensor device. This pre-computed hash serves as a digital fingerprint that travels with the data, enabling future verification of data integrity without requiring the original data to be present. The hash is generated in advance using cryptographic functions, ensuring that any subsequent manipulation of the sensor data can be detected.
Solution Approach 2:
The patent introduces cryptographic hash values as an intermediary element between the sensor data and the verification process. This hash acts as a mediator that represents the original data in a condensed, immutable form. When data integrity needs to be verified, the intermediary hash is compared against a newly computed hash of the received data, providing a reliable mechanism to detect manipulation without directly examining the original sensor data.
2Adaptability or versatility
If sensor data can be deleted and rewritten, then storage flexibility is improved, but detection of unauthorized alterations becomes more difficult
Solution Approach 1:
The patent applies the color changes principle by using cryptographic hash functions that transform the original sensor data into a completely different representation - a fixed-length hash value that appears unrelated to the original data. This transformation is analogous to a color change, where the original data 'color' is transformed into a hash 'color' that provides verification capabilities. Any modification to the original data produces a completely different hash, making manipulation detectable despite the flexibility to delete and rewrite stored data.
3Reliability
If cryptographic hash functions are used for authentication, then data integrity verification is improved, but computational complexity increases
Solution Approach 1:
The patent reduces computational complexity at verification points by performing the computationally intensive cryptographic hash computation in advance, when the sensor data is first generated. The pre-computed hash is then stored and transmitted alongside or instead of the original data. At verification points, only a simple hash comparison is needed, which is computationally trivial compared to generating new hashes. This preliminary computation shifts the computational burden to the data generation stage.
Solution Approach 2:
The patent extracts the essential verification information from the complex sensor data by computing a condensed cryptographic hash. This extraction process separates the verification function from the original data, creating a simplified representation that can be easily stored, transmitted, and compared. The complex original data is replaced or supplemented by this extracted hash, reducing the computational burden of subsequent verification operations.
Data Source
AI summary
An authentication module for a time series of sensor data is provided that comprises at least one data interface which can be connected to at least one sensor. An authentication interface and an authentication logic are provided which is coupled to the data interface and the authentication interface. The authentication logic is configured toreceive at least one data set (21a-24a) via the at least one data interface from at least one sensor,form one or more compressed products (21b-24b) from one or more received data sets,create an authentication which contains the compressed products and respectively contains a reference to the associated data set, or at least a part of the associated data set, andoutput the authentication via the authentication interface.


