Shared HMI Bridge for Secure Classified Data Processing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional personal digital assistant (PDA) devices lack sufficient security measures to handle classified data, being vulnerable to hacker attacks and lacking trusted processing and communication capabilities for secure data transport, which is inadequate for national security purposes.
Innovation Solution
A mobile PDA computer system comprising a non-secure user processor, a secure user processor, and a cryptographic engine, with a shared human/machine interface for bi-directional communication, enabling secure processing and communication of classified data while using non-secure processors for unclassified data, and employing trusted hardware and software for encryption and decryption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional COTS operating systems and applications are used in PDA devices, then the devices can satisfy general processing and communication requirements with familiar interfaces and lower cost, but they lack sufficient security measures to handle classified data and are vulnerable to hacker attacks
Solution Approach 1:
The system is divided into two separate processing environments: a secure processor for handling classified data with trusted operating systems and applications, and a non-secure processor for handling unclassified data with COTS operating systems and applications. This segmentation allows each processor to be optimized for its specific security requirements while sharing common hardware resources through the cryptographic engine bridge.
2Reliability
If physical separation of classified and unclassified data processing is implemented, then security is improved, but device complexity increases
Solution Approach 1:
The patent merges the secure and non-secure processing environments by allowing them to share common hardware resources including display, keypad, battery, and communication interfaces. The cryptographic engine serves as a bridge that enables secure data transport between the two processors while maintaining physical separation of the processing environments, thus reducing overall device complexity compared to completely separate systems.
3Reliability
If trusted microprocessors and trusted operating systems are used, then security for classified data is improved, but the capability for wireless communications of classified data is lost
Solution Approach 1:
The cryptographic engine acts as an intermediary that enables wireless communication of classified data. The non-secure processor handles wireless communication protocols and radio frequency transmission, while the secure processor handles classified data. The cryptographic engine bridges these two processors, encrypting classified data before transmission and decrypting received data, thus enabling wireless communication capability while maintaining security through trusted processing.
Data Source
AI summary
Mobile PDA computer system (300) includes a secure user processor (302), a non-secure user processor (306), a cryptographic engine (304), and a shared human/machine interface (HMI) (308). The secure user processor (302) can be comprised of a first trusted microprocessor and a first trusted operating system executing on the first trusted microprocessor. The non-secure user processor (306) can be comprised of a second non-trusted microprocessor and a second non-trusted operating system executing on the second non-trusted microprocessor. A cryptographic engine (304) can be comprised of a third trusted cryptographic processor and a third trusted operating system executing on the third trusted cryptographic processor. The cryptographic engine can be configured for encrypting and decrypting data. A first data communication link (303) communicates data between the secure user processor and the cryptographic engine. A second data communication link (305) communicates data between the cryptographic engine and the non-secure user processor. In this way, the cryptographic engine forms a bridge between the secure user processor and the non-secure user processor. An HMI (308) comprised of trusted hardware for user input and output is time-multiplex-shared among the secure user processor (302), the non-secure user processor (304), and the cryptographic engine (306) in a secure fashion.


