Trusted Computing Environment for Secured Sensor Data Processing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current automated and industrial control systems are vulnerable to cyber-attacks, which can cause irreparable damage, as seen in attacks like Stuxnet, highlighting the need for enhanced security measures to separate input/output operations from processing sections and ensure reliable authentication.

Innovation Solution

The integration of a trusted computing environment alongside a legacy computing environment in sensor and actuator systems, allowing for secure processing and communication of raw data, thereby enhancing data security, privacy, and safety through high-quality authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a legacy computing environment processes sensor data and transmits it over the network, then system functionality is maintained, but the system becomes vulnerable to malware contamination and cyber-attacks

Engineering Contradiction:
Improvesystem securityVSAvoidmalware contamination
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The computing environment is divided into two separate segments: a legacy computing environment for maintaining system functionality and a trusted computing environment for secure data processing and network communication. This segmentation isolates the system from malware contamination while preserving existing operations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The trusted computing environment acts as an intermediary between the legacy computing environment and the network. It receives raw sensor data from the legacy environment, processes it securely, and transmits it over the network, thereby mediating the interaction and preventing direct exposure to cyber-attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a trusted computing environment is added to process raw sensor data directly, then data security and authentication quality are improved, but device complexity increases

Engineering Contradiction:
Improvedata authenticationVSAvoidcomputing environment structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The computing environment is segmented into distinct functional components: legacy computing environment for data collection, trusted computing environment for secure processing, and network communication modules. This segmentation organizes complexity into manageable, dedicated sections with clear responsibilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The trusted computing environment performs multiple functions including raw data reception, security processing, authentication, and network transmission. By consolidating these functions into a single multi-functional component, the system manages complexity while improving data authentication capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Difficulty of detecting and measuring

If raw sensor output is transmitted to additional network nodes through a trusted computing environment, then system monitoring and detection capabilities are enhanced, but network infrastructure complexity increases

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidnetwork node structure
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The trusted computing environment serves as an intermediary that receives data from sensors, performs security processing and authentication, then transmits it to network nodes for monitoring and detection. This intermediary role enables enhanced detection capabilities without directly complicating the network infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system architecture segments monitoring and detection functions into separate network nodes that receive processed data from the trusted computing environment. This segmentation allows specialized monitoring components to operate independently, enhancing detection capabilities while maintaining manageable network structure.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12273360B2Secured automated or semi-automated systems
Publication Date: 2025.04.08 BARKAN MORDECAI
  • US12273360B2 patent drawing
  • US12273360B2 patent drawing
  • US12273360B2 patent drawing

AI summary

Secured automated or semi-automated systems are provided herein. In one embodiment, a sensor system includes a sensor, a legacy computing environment that is configured to communicate with the sensor and process sensor raw data output, and transmit the processed sensor output to a first network node over the network, and a trusted computing environment configured to receive raw sensor output directly from the sensor and transmit the raw sensor output to an additional network node or the first network node over the network.