Electronic Signature Circuit for Connected Object Data Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Connected objects face security threats due to insecure control circuits, which can be compromised through attacks, compromising data authenticity and making it difficult to integrate a secure circuit without complexifying the architecture.
Innovation Solution
An electronic signature circuit connected to the communication bus detects and verifies data coherence, inhibits malicious requests, and generates dummy data to prevent attacks, ensuring data authenticity without significantly altering the object's architecture.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a secure circuit is added to the connected object to protect against attacks, then security is improved, but device complexity increases
Solution Approach 1:
The patent introduces an electronic signature circuit as an intermediary component between the control circuit and the communication interface. This secure circuit performs electronic signing of measurement data without requiring direct integration into the control circuit, thus improving security while maintaining a clear separation of functions and limiting architectural complexity
Solution Approach 2:
The patent divides the connected object into distinct functional segments: a control circuit for general operations, a separate electronic signature circuit for security functions, and a communication interface for data transmission. This segmentation allows the secure circuit to be added without redesigning the entire system architecture
2Reliability
If the control circuit is modified to be more secure, then security is improved, but ease of manufacture deteriorates
Solution Approach 1:
The patent extracts the security function from the control circuit and places it in a separate electronic signature circuit. This allows the control circuit to remain unchanged and easy to manufacture, while the secure circuit can be produced by specialized third-party manufacturers with security expertise
3Reliability
If the secure circuit is connected directly between the control circuit and sensor, then security is improved, but device complexity increases significantly
Solution Approach 1:
The patent makes the electronic signature circuit communicate with both the control circuit and the sensor through the existing communication bus, allowing it to perform security functions without requiring dedicated direct connections. This multi-functional approach uses the existing communication infrastructure for multiple purposes
4Device complexity
If the secure circuit is connected to the existing communication bus, then device complexity is reduced, but the secure circuit cannot ensure data authenticity
Solution Approach 1:
The patent implements preliminary electronic signing of measurement data by the secure circuit before the data is transmitted through the communication bus. By performing the security-critical signing operation in advance, the circuit ensures data authenticity without needing to control the entire communication path
Data Source
AI summary
The present invention concerns a method for securing data transmitted by a data source (2) of a connected object (1) against attacks affecting a control circuit (4) of the connected object (1), the connected object (1) also comprising an electronic signature circuit (6) and a communication bus (8) connected to the control circuit (4), connected to the electronic signature circuit (6) and connected to the source (2), wherein the method comprises the following steps implemented by the electronic signature circuit (6):detecting (602) a first datum (M) transmitted by the source (2) on the communication bus (8);detecting (606) a second datum (M′) to be signed, on the communication bus, the second datum having been transmitted (404) by the control circuit (4) on the communication bus (8) after detection of the first datum (M) by the control device (4);verifying (608) coherence between the detected data (M, M′),signalling (610) an error (E), if any, as a function of a result of the verification.


