SHIELD Dielet RFID Probe for Quantum-Resistant Hardware Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current RFID probes are not designed for permanent installation on host systems and lack the capability to provide security services, such as authentication and encryption, while existing software distribution channels are vulnerable to attacks, and asymmetric key encryption is at risk due to quantum computing. Additionally, there is a lack of reliable hardware-enforced methods for device identification and tamper protection.

Innovation Solution

A multi-function SHIELD security system that includes an RFID probe system coupled with a SHIELD dielet containing an immutable shared-secret cipher key, which communicates with a secure server system to provide hardware identity and security services, including assured software distribution, encryption key management, device authentication, and anti-tamper protection, using cryptographic primitives and blockchain for secure data integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If RFID probes are made permanently installable on host systems, then continuous authentication capability is improved, but device complexity increases

Engineering Contradiction:
Improvecontinuous authentication capabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the RFID probe functionality with a permanent installation component (such as a PCB card or module) that can be permanently affixed to host systems. This combination enables continuous authentication capability while managing device complexity through integrated design.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The RFID probe system is designed to perform multiple functions including authentication, encryption, and communication with various host systems. This multi-functionality allows a single permanent installation to serve multiple security purposes, improving reliability without proportionally increasing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If asymmetric key encryption is used for software distribution, then security is improved, but vulnerability to quantum attacks increases

Engineering Contradiction:
Improvesoftware distribution securityVSAvoidvulnerability to quantum attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent transitions from asymmetric key encryption to symmetric key encryption for software distribution security. This parameter change in the encryption approach maintains security while eliminating vulnerability to quantum attacks, as symmetric encryption algorithms are not susceptible to quantum factorization.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If multiple vendors provide software distribution channels, then software availability is improved, but attack surface increases

Engineering Contradiction:
Improvesoftware availabilityVSAvoidattack surface
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a centralized authentication server as an intermediary between software vendors and clients. This intermediary verifies the authenticity of software distributions and manages authentication keys, allowing multiple vendors to operate while reducing the overall attack surface through centralized security control.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If hardware-enforced security methods are implemented, then device authentication reliability is improved, but manufacturing complexity increases

Engineering Contradiction:
Improvedevice authentication reliabilityVSAvoidmanufacturing complexity
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent segments the security functionality into separate modules: an authentication server, RFID probe components, and host system interfaces. This segmentation allows hardware-enforced security methods to be implemented in a modular manner, improving authentication reliability while managing manufacturing complexity through standardized components.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11556675B2System and method for providing security services with multi-function supply chain hardware integrity for electronics defense (SHIELD)
Publication Date: 2023.01.17 NORTHROP GRUMMAN SYSTEMS CORP
  • US11556675B2 patent drawing
  • US11556675B2 patent drawing
  • US11556675B2 patent drawing

AI summary

A system and a method for a supply-chain hardware integrity for electronics defense (SHIELD) dielet embedded over a component of a device, a radio frequency identification (RFID) probe system coupled to the SHIELD dielet, and a secure server system communicating with the RFID probe system that can enable security services is provided. Embodiments include a multi-function SHIELD software defined, hardware enabled security system that provides hardware identity, anti-tamper, encryption key generation and management, trusted platform module services, and cryptographic software security services for a device.