Tamper-Resistant Controller for Dynamic Data Integrity Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data processing systems in vehicle telematics and smart metering face challenges in ensuring the integrity of processes against tampering attacks, with current solutions like TPMs offering static protection and smart cards providing dynamic protection but being inconvenient and limited in processing power.
Innovation Solution
A data processing apparatus with a secure tamper-resistant controller that randomly selects operations to verify, ensuring dynamic protection without requiring hardware modifications, combining the advantages of TPMs and smart cards in a cost-effective and flexible manner.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a Trusted Platform Module (TPM) is used to protect the host process, then security against tampering is improved, but the protection is static and does not cover attacks occurring after certification
Solution Approach 1:
The patent implements dynamic protection by having the secure controller randomly select and verify different operations at different times, rather than providing static certification. This allows the system to adapt to evolving threats by changing which operations are protected in each execution cycle.
Solution Approach 2:
The secure controller verifies only a randomly selected subset of operations rather than all operations, providing partial protection that is sufficient to deter tampering while maintaining system performance. This partial verification approach balances security with computational efficiency.
2Adaptability or versatility
If a smart card is used to provide dynamic protection, then protection against evolving threats is improved, but the device requires specific design and manufacturing processes
Solution Approach 1:
The secure controller is designed as a universal component that can be integrated with any generic host controller without requiring application-specific hardware design. It provides dynamic protection through software-based random operation selection, making it adaptable to different applications while maintaining ease of manufacture.
Solution Approach 2:
The patent replaces hardware-based dynamic protection (smart cards with specific manufacturing) with a software-based approach in a generic secure controller, achieving the same dynamic protection effect without the need for specialized hardware design and manufacturing processes.
3Reliability
If all operations are verified by a secure controller, then security is improved, but processing performance and speed are reduced
Solution Approach 1:
The secure controller verifies only a randomly selected subset of operations rather than all operations, providing sufficient security protection while maintaining high processing speed. This partial verification approach ensures that tampering is detected with high probability without the performance penalty of complete verification.
Solution Approach 2:
The verification process occurs periodically at randomly selected intervals rather than continuously, allowing the host controller to execute operations at full speed while the secure controller intermittently verifies a subset of operations to detect potential tampering.
4Reliability
If a TPM is used, then proven certification state is achieved, but deep support from operating system and host controller is required
Solution Approach 1:
The secure controller independently selects which operations to verify and performs verification autonomously without requiring deep integration with the operating system or host controller. This self-service approach reduces system complexity while maintaining reliable security certification.
Data Source
AI summary
A data processing apparatus (30) comprising: a local source of data (4); a first controller (31); and a tamper-resistant second controller (32) configured to communicate with the first controller, the first controller being configured to control and receive data from the local source of data and from a sensing unit connected to the first controller via a communication interface and to perform a series of calculation operations on the data, wherein the second controller is configured to verify the integrity of a selected subset of the operations performed by the first controller.


