Shared HMI Bridge for Secure Classified Data Processing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional personal digital assistant (PDA) devices lack sufficient security measures to handle classified data, being vulnerable to hacker attacks and lacking trusted processing and communication capabilities for secure data transport, which is inadequate for national security purposes.

Innovation Solution

A mobile PDA computer system comprising a non-secure user processor, a secure user processor, and a cryptographic engine, with a shared human/machine interface for bi-directional communication, enabling secure processing and communication of classified data while using non-secure processors for unclassified data, and employing trusted hardware and software for encryption and decryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional COTS operating systems and applications are used in PDA devices, then the devices can satisfy general processing and communication requirements with familiar interfaces and lower cost, but they lack sufficient security measures to handle classified data and are vulnerable to hacker attacks

Engineering Contradiction:
ImprovesecurityVSAvoiddata handling capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system is divided into two separate processing environments: a secure processor for handling classified data with trusted operating systems and applications, and a non-secure processor for handling unclassified data with COTS operating systems and applications. This segmentation allows each processor to be optimized for its specific security requirements while sharing common hardware resources through the cryptographic engine bridge.

Inventive Principle:
Principle #1Segmentation

2Reliability

If physical separation of classified and unclassified data processing is implemented, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidarchitecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the secure and non-secure processing environments by allowing them to share common hardware resources including display, keypad, battery, and communication interfaces. The cryptographic engine serves as a bridge that enables secure data transport between the two processors while maintaining physical separation of the processing environments, thus reducing overall device complexity compared to completely separate systems.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If trusted microprocessors and trusted operating systems are used, then security for classified data is improved, but the capability for wireless communications of classified data is lost

Engineering Contradiction:
ImprovesecurityVSAvoidwireless communication capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The cryptographic engine acts as an intermediary that enables wireless communication of classified data. The non-secure processor handles wireless communication protocols and radio frequency transmission, while the secure processor handles classified data. The cryptographic engine bridges these two processors, encrypting classified data before transmission and decrypting received data, thus enabling wireless communication capability while maintaining security through trusted processing.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7779252B2Computer architecture for a handheld electronic device with a shared human-machine interface
Publication Date: 2010.08.17 NERA INNOVATIONS LTD
  • US7779252B2 patent drawing
  • US7779252B2 patent drawing
  • US7779252B2 patent drawing

AI summary

Mobile PDA computer system (300) includes a secure user processor (302), a non-secure user processor (306), a cryptographic engine (304), and a shared human/machine interface (HMI) (308). The secure user processor (302) can be comprised of a first trusted microprocessor and a first trusted operating system executing on the first trusted microprocessor. The non-secure user processor (306) can be comprised of a second non-trusted microprocessor and a second non-trusted operating system executing on the second non-trusted microprocessor. A cryptographic engine (304) can be comprised of a third trusted cryptographic processor and a third trusted operating system executing on the third trusted cryptographic processor. The cryptographic engine can be configured for encrypting and decrypting data. A first data communication link (303) communicates data between the secure user processor and the cryptographic engine. A second data communication link (305) communicates data between the cryptographic engine and the non-secure user processor. In this way, the cryptographic engine forms a bridge between the secure user processor and the non-secure user processor. An HMI (308) comprised of trusted hardware for user input and output is time-multiplex-shared among the secure user processor (302), the non-secure user processor (304), and the cryptographic engine (306) in a secure fashion.