Systems and Methods With Cryptography and Tamper Resistance Software Security
Abstract
Provided is an arbitrary automation system for secure communications. The system includes a utility device configured for processing critical data associated with the arbitrary automation system, the critical data being structured in accordance with utility device access levels. Also included is a key management module for (i) providing a data protection key (DPK) for protecting the critical data in accordance with each of the utility device access levels and (ii) generating a user key encryption key (UKEK) for encrypting the DPK based upon the device access levels. The system additionally includes a software module configured for masking an execution state of software within the utility device and the key management module via principles of evasion and resistance.
Claims
exact text as granted — not AI-modifiedWe claim:
1 . An arbitrary automation system for providing secure communications, comprising:
a utility device configured for processing critical data associated with the arbitrary automation system, the critical data being structured in accordance with utility device user access levels; a key management module for (i) providing a data protection key (DPK) for protecting the critical data in accordance with each of the utility device access levels and (ii) generating a user key encryption key (UKEK) for encrypting the DPK based upon the device access levels; and a software module configured for masking an execution state of software within the utility device and the key management module via principles of evasion and resistance.
2 . The arbitrary automation system of claim 1 , further comprising a password management module configured for setting a new password for subsequent access to the utility device after the user initially accesses the utility device.
3 . The arbitrary automation system of claim 1 , wherein the system is an industrial control network.
4 . The arbitrary automation system of claim 1 , wherein the utility device includes at least one from the group including a smart electricity meter, a gas meter, and a water meter.
5 . The arbitrary automation system of claim 1 , wherein the key management module is decentralized.
6 . The arbitrary automation system of claim 1 , wherein the DPK is dynamically and randomly generated.
7 . The arbitrary automation system of claim 1 , wherein the system is configured for providing simultaneous access to one or more users, each user having a user role associated with one of the utility device access levels, and wherein the UKEK grants access to the user in accordance with the respective user role.
8 . The arbitrary automation system of claim 7 , wherein the UKEK is generated when the user initially accesses the utility device; and
wherein the UKEK is destroyed after the initial access.
9 . The arbitrary automation system of claim 1 , wherein the principles of evasion include entropy and anti-debugger techniques; and
wherein the principles of resistance include self-monitoring software integrity and redundancy checks.
10 . The arbitrary automation system of claim 9 , wherein the integrity and redundancy checks are directed to random threads of execution.
11 . A computer readable media storing instructions wherein the instructions when executed are configured to execute processes within a computer system for an arbitrary automation system for providing secure communication in an industrial control network, with a method comprising:
processing critical data associated with the arbitrary automation system, the critical data being structured in accordance with utility device user access levels; providing a data protection key (DPK) for protecting the critical data in accordance with each of the utility device access levels; generating a user key encryption key (UKEK) for encrypting the DPK based upon the device access levels; and masking an execution state of software associated with the processing, providing, and generating via principles of evasion and resistance.
12 . The computer readable media of claim 11 , further comprising setting a new password for subsequent access to the utility device after the user initially accesses the utility device.
13 . The computer readable media of claim 12 , wherein the system is configured for providing simultaneous access to one or more users, each user having a user role associated with one of the utility device access levels; and
wherein the UKEK grants access to the user in accordance with the respective user role.
14 . The computer readable media of claim 11 , wherein the UKEK is generated when the user initially accesses the utility device; and
wherein the UKEK is destroyed after the initial access.
15 . The computer readable media of claim 11 , wherein the principles of evasion include entropy and anti-debugger techniques; and
wherein the principles of resistance include self-monitoring software integrity and redundancy checks.
16 . A method for providing secure communications in an industrial control network, comprising:
processing critical data associated with the arbitrary automation system, the critical data being structured in accordance with utility device user access levels; providing a data protection key (DPK) for protecting the critical data in accordance with each of the utility device access levels; generating a user key encryption key (UKEK) for encrypting the DPK based upon the device access levels; and masking an execution state of software associated with the processing, providing, and generating via principles of evasion and resistance.
17 . The method for providing secure communications of claim 16 , further comprising setting a new password for subsequent access to the utility device after the user initially accesses the utility device.
18 . The method for providing secure communications of claim 16 , wherein the system is configured for providing simultaneous access to one or more users, each user having a user role associated with one of the utility device access levels; and
wherein the UKEK grants access to the user in accordance with the respective user role.
19 . The method for providing secure communications of claim 16 , wherein the UKEK is generated when the user initially accesses the utility device; and
wherein the UKEK is destroyed after the initial access.
20 . The method for providing secure communications of claim 16 , wherein the principles of evasion include entropy and anti-debugger techniques and the principles of resistance include self-monitoring software integrity and redundancy checks.
21 . The method for providing secure communications of claim 16 , further comprising facilitating exporting and importing of security file via a user specified password.Join the waitlist — get patent alerts
Track US2015199530A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.