Electronic Signature Circuit for Connected Object Data Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Connected objects face security threats due to insecure control circuits, which can be compromised through attacks, compromising data authenticity and making it difficult to integrate a secure circuit without complexifying the architecture.

Innovation Solution

An electronic signature circuit connected to the communication bus detects and verifies data coherence, inhibits malicious requests, and generates dummy data to prevent attacks, ensuring data authenticity without significantly altering the object's architecture.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a secure circuit is added to the connected object to protect against attacks, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an electronic signature circuit as an intermediary component between the control circuit and the communication interface. This secure circuit performs electronic signing of measurement data without requiring direct integration into the control circuit, thus improving security while maintaining a clear separation of functions and limiting architectural complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent divides the connected object into distinct functional segments: a control circuit for general operations, a separate electronic signature circuit for security functions, and a communication interface for data transmission. This segmentation allows the secure circuit to be added without redesigning the entire system architecture

Inventive Principle:
Principle #1Segmentation

2Reliability

If the control circuit is modified to be more secure, then security is improved, but ease of manufacture deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidease of manufacture
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent extracts the security function from the control circuit and places it in a separate electronic signature circuit. This allows the control circuit to remain unchanged and easy to manufacture, while the secure circuit can be produced by specialized third-party manufacturers with security expertise

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If the secure circuit is connected directly between the control circuit and sensor, then security is improved, but device complexity increases significantly

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the electronic signature circuit communicate with both the control circuit and the sensor through the existing communication bus, allowing it to perform security functions without requiring dedicated direct connections. This multi-functional approach uses the existing communication infrastructure for multiple purposes

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Device complexity

If the secure circuit is connected to the existing communication bus, then device complexity is reduced, but the secure circuit cannot ensure data authenticity

Engineering Contradiction:
Improvedevice complexityVSAvoiddata authenticity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent implements preliminary electronic signing of measurement data by the secure circuit before the data is transmitted through the communication bus. By performing the security-critical signing operation in advance, the circuit ensures data authenticity without needing to control the entire communication path

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11165633B2Method and system for securing data transmitted by a connected object against attacks affecting a control circuit of said object
Publication Date: 2021.11.02 IDEMIA FRANCE SAS
  • US11165633B2 patent drawing
  • US11165633B2 patent drawing
  • US11165633B2 patent drawing

AI summary

The present invention concerns a method for securing data transmitted by a data source (2) of a connected object (1) against attacks affecting a control circuit (4) of the connected object (1), the connected object (1) also comprising an electronic signature circuit (6) and a communication bus (8) connected to the control circuit (4), connected to the electronic signature circuit (6) and connected to the source (2), wherein the method comprises the following steps implemented by the electronic signature circuit (6):detecting (602) a first datum (M) transmitted by the source (2) on the communication bus (8);detecting (606) a second datum (M′) to be signed, on the communication bus, the second datum having been transmitted (404) by the control circuit (4) on the communication bus (8) after detection of the first datum (M) by the control device (4);verifying (608) coherence between the detected data (M, M′),signalling (610) an error (E), if any, as a function of a result of the verification.