Key management and protection in secure execution environment
By performing multiple randomization and masking of secure information assets at the randomization engine, the problem of vulnerability of secure information assets is solved and the security of computing devices is improved.
Patent Information
- Application Number
- CN202380090720.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-01-12
- Filing Date
- 2023-12-21
- Publication Date
- 2025-08-08
AI Technical Summary
In the prior art, secure information assets (such as encryption keys) are vulnerable to side channel attacks and fault injection attacks on computing devices, resulting in impaired security of computing devices.
By performing repeated randomization, masking and remasing processing of the security information assets at the randomization engine, including obtaining the security information assets at the randomization engine, performing the first randomization, providing it to the secure storage device, further performing the second randomization on the secure storage device, and ultimately providing it to the security component for use.
Improves the security of computing devices and prevents attackers from obtaining security information assets through side channel attacks or failure injection attacks, enhancing the security of computing devices.
Smart Images

Figure CN120457431A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure generally relates to techniques for protecting secure information assets (e.g., cryptographic keys) using a secure execution environment. For example, aspects of the present disclosure relate to systems and techniques for randomizing, masking, and re-masking secure information assets as they are obtained and used at a computing device. Background Art
[0002] Computing devices often employ various techniques to protect data. For example, encryption and decryption techniques may be applied to data in various scenarios, such as writing data to or reading data from storage devices, writing data to or reading data from memory devices, encrypting and decrypting data blocks and / or volumes, encrypting and decrypting digital content, and performing inline cryptographic operations. These encryption and decryption operations are often performed, at least in part, using security information assets (such as encryption keys, derived encryption keys, and the like). Certain scenarios exist in which attacks are conducted to attempt to obtain such security information assets. Therefore, it would be generally advantageous to implement systems and techniques for protecting such security information assets. Summary of the Invention
[0003] Systems and techniques for protecting secure information assets on a computing device are described herein. According to some aspects of the present disclosure, when a secure information asset (e.g., an encryption key) is transmitted or otherwise used on a computing device, the secure asset can be protected, at least in part, using repeated randomization, masking, and / or re-masking techniques.
[0004] According to at least one example, a process for information protection is provided. The process includes: obtaining a security information asset at a randomization engine; performing a first randomization on the security information asset to obtain a randomized security information asset; providing the randomized security information asset to a secure storage device; obtaining the randomized security information asset from the secure storage device; performing a second randomization on the security information asset to obtain an updated randomized security information asset; and providing the updated randomized security information asset to a security component, wherein the updated randomized security information asset is used to perform a security operation.
[0005] In another illustrative example, an apparatus for information protection is provided. The apparatus may include: at least one memory; and at least one processor, the at least one processor being coupled to the at least one memory and configured to: obtain a security information asset at a randomization engine; perform a first randomization on the security information asset to obtain a randomized security information asset; provide the randomized security information asset to a secure storage device; obtain the randomized security information asset from the secure storage device; perform a second randomization on the security information asset to obtain an updated randomized security information asset; and provide the updated randomized security information asset to a security component, wherein the updated randomized security information asset is used to perform a security operation.
[0006] In another illustrative example, a non-transitory computer-readable medium having instructions stored thereon is provided, which instructions, when executed by at least one processor, cause the at least one processor to: obtain a security information asset at a randomization engine; perform a first randomization on the security information asset to obtain a randomized security information asset; provide the randomized security information asset to a secure storage device; obtain the randomized security information asset from the secure storage device; perform a second randomization on the security information asset to obtain an updated randomized security information asset; and provide the updated randomized security information asset to a security component, wherein the updated randomized security information asset is used to perform a security operation.
[0007] According to at least one example, an apparatus for information protection is provided. The apparatus includes: means for obtaining a security information asset at a randomization engine; means for performing a first randomization on the security information asset to obtain a randomized security information asset; means for providing the randomized security information asset to a secure storage device; means for obtaining the randomized security information asset from the secure storage device; means for performing a second randomization on the security information asset to obtain an updated randomized security information asset; and means for providing the updated randomized security information asset to a security component, wherein the updated randomized security information asset is used to perform a security operation.
[0008] In some aspects, one or more of the apparatuses described herein is, is part of, and / or includes a mobile or wireless communication device (e.g., a mobile phone or other mobile device), an extended reality (XR) device or system (e.g., a virtual reality (VR) device, an augmented reality (AR) device, or a mixed reality (MR) device), a wearable device (e.g., a web-connected watch or other wearable device), a vehicle or a computing device or component of a vehicle, a camera, a personal computer, a laptop computer, a server computer or server device (e.g., an edge or cloud-based server, a personal computer acting as a server device, a mobile device such as a mobile phone acting as a server device, an XR device acting as a server device, a vehicle acting as a server device, a network router, or other device acting as a server device), a system-on-chip (SoC), any combination thereof, and / or other types of devices. In some aspects, the apparatus includes a display for displaying one or more images, notifications, and / or other displayable data. In some aspects, the apparatus includes one or more sensors (e.g., one or more RF sensors), such as one or more gyroscopes, one or more gyrometers, one or more accelerometers, any combination thereof, and / or other sensors.
[0009] This summary is not intended to identify key or essential features of the claimed subject matter, nor is it intended to be used in isolation to determine the scope of the claimed subject matter. This subject matter should be understood by reference to appropriate portions of the entire specification of this patent, any or all of the drawings, and each claim.
[0010] The foregoing and other features and examples will become more apparent after reference to the following description, claims, and accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] Illustrative examples of the present application are described in detail below with reference to the following drawings:
[0012] Figure 1 is a block diagram illustrating certain components of a computing device according to some examples;
[0013] Figure 2 is a diagram illustrating a process for protecting secure information assets according to some examples;
[0014] Figure 3 is a flow chart illustrating an example process for protecting secure information assets according to some examples;
[0015] Figure 4 is a diagram illustrating an example of a computing system for implementing certain aspects described herein. DETAILED DESCRIPTION
[0016] Provided below are certain aspects and examples of the present disclosure. As will be apparent to those skilled in the art, some of these aspects and examples can be applied independently, and some of them can be applied in combination. In the following description, specific details are set forth for explanation purposes to provide a thorough understanding of the examples of the present application. However, it will be apparent that each example can be implemented without these specific details. Each drawing and description is not intended to be restrictive. Additionally, certain details known to those of ordinary skill in the art may be omitted to avoid obscuring the description.
[0017] In the following description of the drawings, in the various examples described herein, any component described with reference to a drawing may be equivalent to one or more similarly named (or numbered) components described with reference to any other drawing. For the sake of brevity, the description of these components may not be repeated in full with reference to each drawing. Therefore, each example of a component of each drawing is incorporated by reference and is assumed to be optionally present in each other drawing having one or more similarly named components. Additionally, according to the various examples described herein, any description of a component of a drawing is to be interpreted as an optional example that can be implemented in addition to, in conjunction with, or in place of an example described with reference to a corresponding similarly named component in any other drawing.
[0018] The following description provides only illustrative examples and is not intended to limit the scope, applicability or configuration of the present disclosure. On the contrary, the following description of the illustrative examples will provide an enabling description for implementing the illustrative examples to those skilled in the art. It should be understood that various changes may be made to the function and arrangement of elements without departing from the spirit and scope of the present application as set forth in the appended claims.
[0019] As used herein, the phrases operatively connected or operatively connected (or any variations thereof) mean that there is a direct or indirect connection between elements / components / devices, etc., that allows the elements to interact with each other in some manner. For example, the phrase "operatively connected" can refer to any direct connection (e.g., a wired connection directly between two devices or components) or indirect connection (e.g., a wired and / or wireless connection between any number of devices or components that connect operatively connected devices). Thus, any path through which information can travel can be considered an operative connection. Additionally, operatively connected devices and / or components can exchange things and / or can unintentionally share things other than information, such as, for example, electrical current, radio frequency signals, power supply interference, interference due to proximity, interference due to reusing the same wires and / or physical media, interference due to reusing the same registers and / or other logical media, etc.
[0020] This document describes systems, apparatuses, processes (also referred to as methods), and computer-readable media (collectively, "systems and techniques") for protecting secure information assets (e.g., cryptographic keys) during various scenarios while they are transferred, stored, and / or otherwise used on a computing device. The secure information assets can be used to perform security operations on data on the computing device. By way of example, the secure information assets can be cryptographic keys used to encrypt and / or decrypt data used by the computing device. Such secure information assets can be stored in a secure information asset storage device (e.g., a one-time programmable (OTP) storage device, a non-volatile memory device, a flash memory storage device, etc.). The secure information assets can be retrieved from the secure information asset storage device during execution of the computing device (e.g., at startup and / or reboot), stored in a separate storage device, and provided as needed to security components (e.g., cryptographic engines, key tables, key derivation functions, etc.) for use in performing security operations (e.g., encryption and / or decryption of data). The security information assets thus obtained can be used directly by any number of security components and / or can be used to derive additional security information assets (e.g., derived keys used by a cryptographic engine to encrypt and / or decrypt data), which is an example of a security operation. Other examples of security operations include steps, transformations, etc., as further discussed herein.
[0021] However, repeated reuse of security information assets may allow attackers to use various techniques to obtain all or any portion of the security information assets, potentially compromising the security of the computing device. For example, an attacker could perform a side-channel attack by using a measurement device (e.g., an oscilloscope) to measure any number of characteristics of the computing device during operation (e.g., voltage, power, electromagnetic output, timing information, sound, temperature, etc.). As another example, an attacker could employ fault injection techniques. Such attacks may be of limited use when performed once or relatively infrequently, but may be more effective when performed more frequently. Therefore, when such techniques are used, security information assets become more vulnerable to attack when reused. For example, when performing an operation to transfer security information assets or when using security information assets to perform operations, measuring one or more characteristics of the computing device's operation may allow an attacker to obtain all or any portion of the security information assets, potentially compromising the security of the computing device. As an example, when a cryptographic key is being sent and / or received (e.g., when obtained from a secure information asset storage device at boot time, when obtained from a different storage device, when provided to a secure component for use in performing cryptographic operations, etc.), used to derive other cryptographic keys, etc., an attacker using a side-channel attack or a fault injection attack may be able to infer the cryptographic key and, therefore, be able to use the key to decrypt data on the computing device and / or encrypt potentially malicious data using the correct key, which may then be used by the computing device.
[0022] In some examples, secure information assets are obtained from a secure information asset storage device. For example, secure information assets may be obtained from the secure information asset storage device when the computing device is booted and / or restarted for various security operations (e.g., encryption and / or decryption operations, key derivation operations, other steps or transformations performed using secure information assets, etc.). In some examples, secure information assets are obtained from a randomization engine. In some examples, the randomization engine is any hardware, software, firmware, or any combination thereof residing within a secure execution environment of the computing device. In some examples, the secure execution environment is any portion of the computing device that is a secure enclave of the computing device. Examples of secure execution environments include, but are not limited to, a trusted management environment, a trusted execution environment, a trusted enclave, a trusted platform module, a secure element, etc. In some examples, the secure information asset storage device is a read-only storage device, such as a read-only memory device or a one-time programmable storage device. In some examples, the secure information asset storage device is a reprogrammable storage device, such as a non-volatile memory device or a flash memory device. In some examples, secure information assets may be obtained from the secure information asset storage device each time the computing device is booted or restarted.
[0023] Security information assets (e.g., encryption keys) can be stored on a security information asset storage device in either masked or unmasked form. In some examples, data masking refers to the process of obfuscating the contents of a data item by performing a masking process. Any suitable form of data masking may be used without departing from the scope of the examples described herein. In some examples, data masking refers to altering data represented in binary form so that if read by any entity not configured to understand the applied mask, the data does not represent the original data (e.g., the security information asset), but an entity configured to understand the mask (e.g., an encryption engine) can demask and subsequently use the original data (e.g., the encryption key). Examples of data masking processes include, but are not limited to, techniques such as substitution, data shuffling, appending data to the original data, altering data using various parameters (e.g., date, time, etc.), splitting and randomizing the order in which data is sent, splitting data into separate parts and appending additional data to each part (e.g., a random number), combinations of all or any of the foregoing techniques, and the like.
[0024] In some aspects, the secure information assets are stored on the secure information asset storage device in masked form. In some examples, if the secure information assets obtained by the randomization engine have already been masked, the data may be subjected to a re-masking process performed by the randomization engine. In some examples, the re-masking process includes performing an additional masking process on the secure information assets. In some examples, the secure information assets stored on the secure information asset storage device are not in masked form. In such examples, the randomization engine may perform an initial masking process on the secure information assets after obtaining the secure information assets from the secure information asset storage device. In some examples, the masking and / or re-masking is performed using random bits or another quantity derived from the internal state of the device, which random bits or another quantity can then be securely stored or transmitted and protected in the same manner as the original asset, or the random bits or another quantity is protected by physical boundaries, restrictions on use and access, and limited privileges or capabilities of different internal components.
[0025] In some cases, the security information assets obtained by the randomization engine, whether masked and / or re-masked, may be randomized during transmission to a secure storage device. The secure storage device can be any form of data storage device residing within a secure execution environment. The secure storage device can reside within the same secure execution environment of the computing device as the randomization engine, or within a different secure execution environment of the computing device. In some examples, randomizing the security information assets during transmission includes randomizing the order in which portions (e.g., bytes) of the security information assets are transmitted within the computing device. In some examples, the randomization of transmission can be performed at randomized intervals to prevent attackers from decoding the assets. In some examples, dummy operations or dummy data packets can be added to the transmission process. These dummy operations or dummy data packets will be rejected due to invalid format, range, or data content, but will confuse an eavesdropping attacker. In some examples, the dummy operations can be performed by another functional unit of the same type in parallel with the actual operations. As an example, rather than sending the portions (e.g., bytes) of a security information asset to a secure storage device in the order in which they are present, the portions may be subjected to a randomization process such that the order in which the portions are sent is different each time the security information asset is sent. In some examples, a security information asset that has undergone a randomization process performed by a randomization engine may be referred to as a randomized security information asset.
[0026] In some examples, as discussed above, randomized security information assets, which may or may not be masked or re-masked by the randomization engine, may be stored in a secure storage device within the secure execution environment of the computing device. In some examples, the secure storage device includes a key table for storing cryptographic keys to be used as needed by the computing device's secure components to perform cryptographic operations (e.g., encryption and / or decryption of data). In some examples, while stored in the secure storage device, the randomized security information assets may be subjected to a mandatory re-masking process. In some examples, the mandatory re-masking is based on one or more thresholds related to the number of times all or any portion of the security information asset has been read and / or written. As an example, one or more counters may be included in the computing device, which are updated each time a portion of the security information asset is read and / or written. Such counters may track individual portions (e.g., bytes) of the security information asset and / or may track the total number of reads and / or writes of individual portions of the security information asset. In some examples, if the total number of reads and / or writes of all or any portion of the security information asset exceeds a threshold (e.g., a usage threshold), a re-masking of the security information asset may be initiated, or use of the security information asset may be discontinued. In some examples, the computing device may be configured with a usage difference threshold, which is a threshold associated with any difference between reads and / or writes of one or more portions (e.g., bytes) of the security information asset relative to one or more other portions of the security information asset. As an example, if the first byte of a cryptographic key has experienced a significantly higher number of reads (e.g., above the usage difference threshold) than other bytes of the security information asset, a potential attack on the security information asset may be detected, at which point use of the cryptographic asset may be interrupted and / or a re-masking may be initiated.
[0027] In some aspects, as discussed above, a security component of a computing device may require a security information asset (e.g., a cryptographic key) to perform one or more security operations (e.g., encrypting and / or decrypting data, generating a derived cryptographic key, any other steps and / or transformations performed using the security information asset, etc.). In such examples, a randomization engine obtains the security information asset from a secure storage device, which may have been randomized, masked by the randomization engine, re-masked by the randomization engine, and / or re-masked any number of times while stored in the secure storage device. In some examples, after obtaining the security information asset, the randomization engine may or may not perform a re-masking process to re-mask the security information asset. Additionally or alternatively, when providing the security information asset to one or more security components, the randomization engine may perform an additional randomization process such that the order of portions (e.g., bytes) of the security information asset are randomized again during transmission to the one or more security components. Such randomization may cause the locations of the security information assets to be sent in a randomized order, but stored and / or otherwise understood, unmasked, by the security component in a non-randomized order, and subsequently used to perform any number of security operations on the data on the computing device (e.g., encryption and / or decryption, derived key generation, any other steps and / or transformations performed using the security information assets, etc.).
[0028] In some cases, all or any portion of any number of security information assets (e.g., master encryption keys, derived encryption keys, etc.) may be subjected to initial masking or re-masking of the security information assets, randomization of the security information assets upon transmission, and periodic re-masking during all transfers of the security information assets. In this way, the randomization engine can act as a firewall through which security information assets pass when they are transferred (e.g., from an initial storage location to a key table, from a key table to a secure component, etc.). Such transfers may occur for a variety of reasons, including, but not limited to, reading, writing, shadowing, copying, parallel reuse, deterministic recalculation, and the like. In some examples, while the randomization engine may perform randomization, masking, and / or re-masking on security information assets, these security information assets are not stored at the randomization engine. In some cases, the randomization engine may be a hardware component comprising circuitry configured to perform the randomization and / or masking processes.
[0029] Examples described herein address the need for providing improved security for secure information assets. In some examples, masking and / or re-masking of secure information assets obtained from a secure information asset storage device (e.g., during startup and / or restart of a computing device), randomizing the order in which portions of secure information assets are sent to a secure storage device, enforcing periodic re-masking of secure information assets (e.g., based on one or more counters associated with a usage threshold and / or a usage difference threshold), re-masking of secure information assets when obtained by a randomization engine for provision to one or more security components, and / or randomizing the sending of secure information assets to the one or more security components can improve the security of a computing device. Such improvements may involve randomizing, masking, and / or re-masking data content during all or any portion of the use of a secure information asset as it traverses a path from the secure information asset storage device to the randomization engine, then to the secure storage device, then back to the randomization engine, and ultimately to one or more security components used to perform any number of security operations. Such a series of randomization, masking, re-masking, etc. along the data path may obfuscate the security information asset such that an attacker (e.g., performing a side-channel attack, fault injection attack, etc.) may be less likely to discern all or any portion of the security information asset and, therefore, less likely to compromise the security of the computing device.
[0030] Various aspects of the techniques described herein are discussed below with respect to the accompanying figures. Figure 1 is a block diagram illustrating an example of a computing device 100. As shown, computing device 100 includes a processor 102, a universal flash storage (UFS) device 104, a secure information asset storage device 106, a memory device 108, an attached storage device 110, and a secure execution environment 112. In some examples, secure execution environment 112 includes a randomization engine 114, a secure storage device 116, and any number of secure components (e.g., secure component A 118, secure component N 120). Each of these components is described below.
[0031] The computing device 100 is any device, portion of a device, or any collection of devices capable of processing instructions electronically, and may include, but is not limited to, any of the following: one or more processors (e.g., components including integrated circuits, memory, input and output devices (not shown)), non-volatile storage hardware, one or more physical interfaces, any number of other hardware components (not shown), and / or any combination thereof. Examples of computing devices include, but are not limited to, mobile devices (e.g., laptops, smartphones, personal digital assistants, tablet computers, automotive computing systems, and / or any other mobile computing devices), Internet of Things (IoT) devices, servers (e.g., blade servers in blade server chassis, rack-mount servers in racks, etc.), desktop computers, storage devices (e.g., disk drive arrays, Fibre Channel storage devices, Internet Small Computer System Interface (iSCSI) storage devices, tape storage devices, flash arrays, network attached storage devices, etc.), network devices (e.g., switches, routers, multilayer switches, etc.), wearable devices (e.g., connected watches or smartwatches or other wearable devices), robotic devices, smart televisions, smart appliances, extended reality (XR) devices (e.g., augmented reality, virtual reality, etc.), any device including one or more SoCs, and / or any other type of computing device having the aforementioned requirements. In one or more examples, any or all of the aforementioned examples may be combined to create a system of such devices, which may be collectively referred to as a computing device. Other types of computing devices may be used without departing from the scope of the examples described herein.
[0032] In some examples, processor 102 is any component that includes circuitry for executing instructions (e.g., of a computer program). For example, such circuitry may be an integrated circuit implemented at least in part using transistors, which implement such components as arithmetic logic units, control units, logic gates, registers, first-in-first-out (FIFO) buffers, data and control buffers, and the like. In some examples, the processor may include additional components, such as cache memory. In some examples, the processor retrieves and decodes instructions, which are then executed. Execution of instructions may include operations on data, which may include reading and / or writing data. In some examples, the instructions and data used by the processor are stored in memory (e.g., memory device 108) of computing device 100. The processor may perform various operations for executing software (such as an operating system, applications, and the like). Processor 102 may write data from the memory of computing device 100 to the computing device's storage device and / or read data from the storage device via the memory. Examples of processors include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), a neural processing unit, a tensor processing unit, a display processing unit, a digital signal processor (DSP), a finite state machine, etc. The processor 102 may be operatively connected to the memory device 108, any storage device of the computing device 100 (e.g., the UFS device 104, the additional storage device 110), and / or the secure execution environment 112. Although Figure 1 Computing device 100 is shown with a single processor 102 , but the computing device may include any number of processors without departing from the scope of the examples described herein.
[0033] In some examples, the computing device 100 includes a UFS device 104. In some examples, the UFS device 104 is a flash memory storage device that complies with the UFS specification. The UFS device 104 can be used to store any type of data. Data can be written to and / or read from the UFS device 104. As an example, the UFS device can store operating system images, software images, application data, etc. Without departing from the scope of the examples described herein, the UFS device 104 can store any other type of data. In some examples, the UFS device 104 includes a NAND flash memory storage device. Without departing from the scope of the examples described herein, the UFS device 104 can use any other type of storage technology. In some examples, the UFS device 104 is capable of achieving a relatively faster data rate than other storage devices of the computing device 100 (e.g., the additional storage device 110). The UFS device 104 is operably connected to the processor 102, the memory device 108, and / or the additional storage device 110. Although Figure 1The computing device 100 is shown with a single UFS device 104, but the computing device may include any number of UFS devices without departing from the scope of the examples described herein. Figure 1 A UFS device 104 is shown, but the computing device 100 may include any other type of flash storage device without departing from the scope of the examples described herein.
[0034] In some examples, computing device 100 includes additional storage device 110. In some examples, the additional storage device is a non-volatile storage device. Additional storage device 110 can be, for example, a persistent memory device. In some examples, additional storage device 110 can be any type of computer storage device. Examples of types of computer storage devices include, but are not limited to, hard drives, solid-state drives, flash memory storage devices, tape drives, removable disk drives, universal serial bus (USB) storage devices, secure digital (SD) cards, optical storage devices, read-only memory devices, and the like. Although Figure 1 An additional storage device 110 is shown as part of the computing device 100, but the additional storage device can be separate from the computing device 100 and operatively connected to the computing device (e.g., an external drive array, cloud storage, etc.). In some examples, the additional storage device 110 operates at a relatively slower data rate than the UFS device 104. In some examples, the additional storage device 110 is also a UFS storage device. In some examples, the additional storage device 110 is operatively connected to the processor 102, the UFS device 104, the secure execution environment 112, and / or the memory device 108. Although Figure 1 Computing device 100 is shown with a single additional storage device 110 , but computing device 100 may have any number of additional storage devices without departing from the scope of the examples described herein.
[0035] In some examples, computing device 100 includes a memory device 108. The memory device can be any type of computer memory. In some examples, memory device 108 is a volatile memory device. As an example, memory device 108 can be a random access memory (RAM). In one or more examples, data stored in memory device 108 is located at a memory address and is therefore accessible by processor 102 and / or secure execution environment 112 using the memory address. Similarly, processor 102 and / or secure execution environment (or components therein) can write data to and / or read data from memory device 108 using the memory address. Memory device 108 can be used to store any type of data, such as, for example, computer programs, results of operations, etc. In some examples, memory device 108 is operatively connected to processor 102, UFS device 104, additional storage device 110, and secure execution environment 112. Although Figure 1 The computing device 100 is shown with a single memory device 108 , but the computing device 100 may have any number of memory devices without departing from the scope of the examples described herein.
[0036] In some examples, the computing device 100 includes a secure information asset storage device 106. In some examples, the secure information asset storage device 106 is any storage device configured to store secure information assets (e.g., cryptographic keys). In some examples, the secure information asset storage device 106 is a device from which secure information assets are stored and from which they are initially obtained when needed for use on the computing device (e.g., at startup and / or reboot). Examples of secure information asset storage devices include, but are not limited to, various types of read-only memory, one-time programmable memory devices (e.g., one-time programmable fuses or other types of one-time programmable memory devices), non-volatile memory, and the like. The secure information asset storage device 106 is operatively connected to the secure execution environment 112. Although Figure 1 The computing device 100 is shown as including a single secure information asset storage device 106 , but the computing device 100 may include any number of secure information asset storage devices without departing from the scope of the embodiments described herein.
[0037] In some examples, computing device 100 includes any number of security components (e.g., security component 118, security component 120). Security components 118 and 120 can be any components capable of performing various cryptographic services and, therefore, can be any hardware (e.g., circuitry), software, firmware, or any combination thereof. In some examples, the security components are sub-chip hardware components of a system-on-chip (SoC), which can include Figure 1, such as, for example, processor 102. Any other components of computing device 100 may also be included as part of the SoC without departing from the scope of the examples described herein. In some examples, the security component is present in the data path between the storage device (e.g., UFS storage device 104, additional storage device 110) and memory device 108 and / or the data path between processor 102 and memory device 108 or any of the storage devices (e.g., 104, 110). In some examples, all or any portion of the security component can be considered an "inline" encryption engine. In some examples, the security component (e.g., 118, 120) is configured to perform any number of cryptographic service types on data being read from or written to the storage device (e.g., UFS device 104, additional storage device 110) and / or memory device 108 of computing device 100. In some examples, all or any portion of data passed from memory to storage, from storage to memory, or to or from processor 102 of computing device 100 passes through a security component (eg, 118 , 120 ).
[0038] Examples of the types of cryptographic services that can be performed include, but are not limited to, encrypting data, decrypting data, key derivation, performing data integrity verification, and performing authenticated encryption and decryption. In some examples, security components 118 and 120 are configured to perform various types of cryptographic services by being configured to execute one or more cryptographic algorithms. As an example, to perform encryption and decryption, one or more security components (e.g., 118, 120) can be configured to execute one or more of the Advanced Encryption Standard XOR-encryption-XOR Tunable Block Ciphertext Stealing (AES-XTS) algorithm, the AES-Cipher Block Chaining (AES-CBC) algorithm, the AES-Electronic Codebook (AES-EBC) algorithm, the Encryption Salt-Sector Initialization Vector-AES-CBC (ESSIV-AES-CBC) algorithm, and the like, including any variants of such algorithms (e.g., 128-bit, 192-bit, 256-bit, etc.). As another example, to perform integrity verification, security components (e.g., 118, 120) can be configured to execute a hash algorithm, such as, for example, one or more members of the SHA family of hash algorithms. As another example, to perform authenticated encryption, the security components (e.g., 118, 120) may be configured to execute the AES-Galois / Counter Mode (GCM) algorithm. Without departing from the scope of the examples described herein, the security components (e.g., 118, 120) may be configured to execute any other cryptographic algorithm. In some examples, to perform at least a portion of the aforementioned cryptographic service types, the security components may require one or more security information assets (e.g., cryptographic keys), which may be provided as needed by the randomization engine 114 (described below) after being obtained from the security information asset storage device 106 and, in some cases, after additional transformations. Additional transformations may include, but are not limited to, masking, re-masking, removing or adjusting the masking scheme for recipient encoding, key derivation, reordering, adding dummy data elements, adding security policy bits specifying actions that are not allowed, entities, channels, or IDs that are allowed to read or manipulate the asset, adding status bits related to the past history of the asset's manipulation, timestamps, counters, and authentication tokens, or any combination thereof.
[0039] In some examples, the computing device 100 includes a secure execution environment 112. In some examples, the secure execution environment 112 is a hardware component (e.g., including circuitry) that can execute software and / or firmware and is configured to perform various services to protect the computing device 100 (e.g., by verifying the confidentiality and / or integrity of data being used by the computing device 100). Such services may include, but are not limited to, performing various operations for performing the aforementioned types of cryptographic services, configuring protection units, configuring and / or otherwise interacting with cryptographic hardware units, and the like. Examples of secure execution environments include, but are not limited to, a trusted management environment, a trusted execution environment, a trusted zone, a trusted platform module, a secure element, and the like. The secure execution environment 112 is operably connected to the processor 102, the UFS device 104, the secure information asset storage device 106, the additional storage device 110, and / or the memory device 108. Although Figure 1 The computing device 100 is shown as having a single secure execution environment 112, but the computing device 100 may include any number of secure execution environments without departing from the scope of the examples described herein. Figure 1 Various components (described below) are shown as being included in a single secure execution environment 112, but all or any portion of the components shown within secure execution environment 112 may be in a different secure execution environment (not shown) of computing device 100 and / or may not be in a secure execution environment (e.g., as part of a rich execution environment).
[0040] In some examples, the secure execution environment 112 includes a randomization engine 114. In some examples, the randomization engine 114 is any hardware (e.g., circuitry), software, firmware, or any combination thereof configured to perform a randomization and / or masking or re-masking process on a secure information asset as it is transmitted between locations within the computing device 100. As an example, the randomization engine 114 can be circuitry configured to randomize, mask, and / or re-mask an encryption key as it is transmitted within the computing device 100. The randomization engine 114 can be operatively connected to the secure information asset storage device 106, the secure storage device 116, and any number of security components (e.g., 118, 210). As discussed above, the randomization process can include randomizing the order of portions (e.g., bytes) of the secure information asset as it is transmitted within the computing device 100. Such randomization may be performed by the randomization engine 114 after initially obtaining the secure information assets from the secure information asset storage 106 and subsequently sending the randomized secure information assets to the secure storage 116. Such randomization may also be performed again after obtaining the secure information assets from the secure storage 116 and subsequently sending the updated randomized secure information assets to one or more security components (e.g., 118, 120).
[0041] Additionally or alternatively, as discussed above, the randomization engine 114 may perform a masking and / or re-masking process on the security information asset. In some examples, a masking and / or re-masking process refers to a process of obfuscating the content of a data item by performing a masking process. Any suitable form of data masking may be used without departing from the scope of the examples described herein. In some examples, masking of data refers to altering data represented in binary form so that if read by any entity not configured to understand the applied mask, the data does not represent the original data (e.g., the security information asset), but an entity configured to understand the mask (e.g., a security component) is able to demask and subsequently use the original data (e.g., an encryption key). Examples of data masking processes include, but are not limited to, techniques such as substitution, shuffling data, appending data to the original data, altering data using various parameters (e.g., date, time, etc.), splitting and randomizing the order in which data is sent, splitting data into separate parts and appending additional data to each part (e.g., a random number), combinations of all or any of the foregoing techniques, and the like.
[0042] In some examples, if the secure information assets stored in the secure information asset storage device 106 have already been masked when obtained by the randomization engine 114, the randomization may not perform a re-masking process. In some examples, the randomization engine 114 may be configured to perform a re-masking operation even if the secure information assets obtained from the secure information asset storage device 106 have already been masked. In some examples, if the secure information assets obtained from the secure information asset storage device 106 have not been masked, the randomization engine 114 performs a masking process, which may occur before or after the aforementioned randomization for transmission to the secure storage device.
[0043] In some examples, the randomization engine 114 is also the entity that obtains or is otherwise provided with security information assets from the secure storage device because these security information assets are needed by one or more security components (e.g., 118, 120) during operation of the computing device 100. Similar to the randomization and re-masking described above, when the randomization engine 114 obtains a security information asset from the secure information asset storage device 106, the randomization engine can perform a randomization and / or re-masking process on the security information asset after receiving the security information asset from the secure storage device, and then send the randomized and / or re-masked security information asset to the one or more security components (e.g., 118, 120). Thus, as a particular security information asset traverses from the secure information asset storage device 106 to the secure storage device 116 via the randomization engine 114, and again as the security information asset traverses from the secure storage device 116 to one or more secure components (e.g., 118, 120) via the randomization engine 114, the security information asset may be repeatedly masked, re-masked, and / or randomized any number of times during the transmission process. In some examples, repeatedly randomizing and / or re-masking the security information asset as it is transmitted within the computing device 100 helps protect the security information asset from attacks (e.g., side channel attacks, fault injection attacks, etc.) because the portions of the security information asset being transmitted are in different orders and may also have been repeatedly re-masked.
[0044] Additionally, although Figure 1 The computing device 100 is shown as having a single randomization engine 114, but without departing from the scope of the examples described herein, the computing device 100 may include any number of randomization engines that are grouped into groups of one or more randomization engines in any number of secure execution environments of the computing device 100.
[0045] In some examples, secure execution environment 112 also includes secure storage 116. In some examples, secure storage 116 is any type of storage device that exists within the secure execution environment of computing device 100. Figure 1 The secure storage device is shown as residing within the same secure execution environment 112 as the randomization engine 114 and one or more security components (e.g., 118, 120), but the secure storage device may be located in a separate secure execution environment (not shown) that is operatively connected to the secure execution environment 112. In some examples, a secure storage device 116 is operatively connected to the randomization engine 114. In some examples, the secure storage device 116 is configured to store any number of secure information assets. As an example, the secure storage device 116 may include a key table for storing any number of cryptographic keys. In some examples, a key table is any type of data structure capable of storing any number of cryptographic keys.
[0046] In some examples, secure storage device 116 may include and / or be operatively connected to any number of counters (not shown). In some examples, a counter is any hardware (e.g., circuitry), software, firmware, or any combination thereof configured to store the number of times a particular event or process has occurred. In some examples, one or more counters included in and / or operatively connected to the secure storage device are configured to track operations (e.g., reads, writes, etc.) performed using secure information assets. Such counters may track the number of times all or any portion (e.g., one or more bytes) of a secure information asset has been read, written, or otherwise accessed or used. In some examples, the counters may be used to enforce a periodic re-masking process for the secure information assets stored in secure storage device 116. As an example, computing device 100 may be configured with a usage threshold. In some examples, the usage threshold is a threshold number of times all or any portion of a secure information asset has been read, written, etc., exceeding which a re-masking process for the secure information assets stored in secure storage device 116 is initiated. As another example, computing device 100 may be configured with a usage difference threshold. In some examples, the usage difference threshold is a threshold amount of difference between an operation (e.g., read, write, etc.) performed on one portion (e.g., one or more bytes) of a secure information asset relative to another portion (e.g., one or more bytes) of the secure information asset. In some examples, if the usage difference threshold is exceeded, a re-masking process can be triggered for the secure information asset stored in secure storage device 116. In some examples, if any of the aforementioned thresholds is exceeded one or more times, computing device 100 can be configured to cancel the use of the secure information asset.
[0047] Although Figure 1 Although a certain number of components are shown in a particular configuration, persons of ordinary skill in the art will appreciate that the computing device 100 may include more components, fewer components, and / or components arranged in any number of alternative configurations without departing from the scope of the examples described herein. Figure 1 Although not shown, it should be understood by those skilled in the art that the computing device 100 can execute any amount or type of software or firmware (e.g., boot loader, operating system, hypervisor, virtual machine, computer application, mobile device application, etc.). Therefore, the examples disclosed herein should not be limited to Figure 1 The configuration of the components shown in . Figure 1 The components shown in the figure may or may not be discrete components. In some aspects, one or more of these components may be combined into different hardware elements, implemented in software, and / or otherwise implemented using software and / or hardware. As used herein, the term "device" may be a discrete component or device, or may not be a discrete component. In some aspects, other devices may exist within, be part of, and / or utilize the same hardware components as the device.
[0048] Figure 2 An example process 200 according to one or more examples described herein is illustrated. The following examples are provided for illustrative purposes only and are not intended to limit the scope of the examples described herein. Additionally, although the examples illustrate certain aspects of the examples described herein, not all possible aspects of such examples may be illustrated in this particular example.
[0049] In some examples, a computing device (e.g., Figure 1 The computing device 100) or any portion thereof (e.g., a subsystem) is configured to use a security component (e.g., Figure 1 118 and 120 as shown in and described above). In such a scenario, one or more secure information assets are initially stored on a secure information asset storage device (e.g., Figure 1 When the computing device is powered on, restarted, and / or at other times during the operation of the computing device, the randomization engine obtains a particular secure information asset from the secure information asset storage device (e.g., Figure 2 202 as shown), and the particular secure information asset may also be replicated in any number of memory device locations and / or registers of the computing device.
[0050] After obtaining the secure information asset from the secure information asset storage device in operation 202, in some cases, a randomization engine (e.g., Figure 1The randomization engine 114 shown in FIG and described above may perform one or more operations using the security information asset at operation 204. One example operation is randomizing the order of portions (e.g., bytes) of the security information asset and sending the security information asset to the secure execution environment (e.g., the server) in the randomized order at operation 206. Figure 1 , and the secure execution environment 112 shown in and described above) of a secure storage device (e.g., Figure 1 The randomization engine may also perform a masking or re-masking process on the secure information asset. If the secure information asset has already been masked, a re-masking process may or may not be performed. If the secure information asset has not been masked, a masking process may be performed. In some examples, after the randomization engine performs masking, re-masking, and / or randomization, the randomization engine provides the secure information asset to the secure storage device at operation 206.
[0051] At operation 208, re-masking is performed while the secure information asset is stored on the secure storage device. In this example, the computing device is configured with both a usage threshold and a usage difference threshold, each of which is tracked by a counter operatively connected to the secure storage device. In one illustrative example, the usage threshold may be configured to be 10, and re-masking may be triggered any time all or any portion of a particular secure information asset exceeds a threshold for the total amount of reads and writes. In another illustrative example, the usage difference threshold may be configured to be 50, and re-masking may be triggered any time any portion of the secure information asset (e.g., any one or more bytes) is read and written 50 times more than any other portion of the secure information asset. In some cases, the computing device may include another counter that tracks the number of times both thresholds have been exceeded. In such cases, if both thresholds have been exceeded more than 10 times, use of the particular secure information asset on the computing device is revoked. In some examples, re-masking is performed when (e.g., only when) the secure information asset is transferred back to the randomization engine (discussed below), with periodic re-masking of the secure information asset while stored on the secure storage device being an optional feature. In some aspects, the counter is configured to automatically increment regardless of system events that occur.
[0052] At operation 210, one or more security components may require a security information asset for performing one or more cryptographic services on a computing device. A randomization engine may again obtain the security information asset, which may have been masked or re-masked before being transmitted to the secure storage device, randomized for transmission as a randomized security information asset to the secure storage device, and periodically subjected to enforced re-masking based on a counter threshold while stored in the secure storage device.
[0053] The randomization engine may then perform another re-masking of the security information asset and may again randomize the order in which portions (eg, bytes) of the security information asset are sent at operation 212 .
[0054] After initially obtaining the secure information asset from the secure information asset storage device by the randomization engine at operation 202, the secure information asset is masked and / or re-masked, randomized at operation 204, sent to the secure storage device as a randomized secure information asset at operation 206, periodically re-masked while stored in the secure storage device at operation 208, obtained from the secure storage device by the randomization engine at operation 210, and re-masked and randomized again at operation 212. At operation 214, the secure information asset is provided to one or more security components.
[0055] Based on the process 200 described above, after randomizing the security information asset, the security information asset is transmitted within the computing device after initially obtaining the security information asset from the security information asset storage device, and the security information asset is masked and re-masked for transmission and re-masked when stored. Such a process can provide protection against side-channel attacks and fault injection attacks by ensuring that the security information asset is always in a different state (e.g., randomized transmission order of bytes, repeated re-masking), thereby preventing attempts to discern the contents of the security information asset.
[0056] Figure 3 is a flow chart illustrating an example of a process 300 for image authentication for secure boot according to one or more examples described herein. The process 300 may be performed at least in part by, for example Figure 1 The computing device 100 shown in and described above, or any component therein (such as, for example, the randomization engine 114 ), executes.
[0057] At block 302, process 300 includes executing a randomization command in a randomization engine (e.g., Figure 1 In some examples, the security information asset is an encryption key. In some examples, the security information asset is obtained from a security information asset storage device (e.g., Figure 1 The secure information asset may be obtained from the secure information asset storage device 106. The secure information asset may be masked or unmasked when obtained.
[0058] At block 304, process 300 includes performing a first randomization on the security information asset to obtain a randomized security information asset. As an example, the first randomization may be performed by Figure 1 The randomization engine 114 executes the above Figure 1 and Figure 2 Randomization is discussed in the description of . As an example, randomization may include randomizing the order of portions (e.g., bytes) of the security information asset before and / or during any transmission of the security information asset. In some examples, in addition to randomization, the security information asset may be masked or re-masked. In some examples, if the obtained security information asset was not masked when it was obtained, it may be masked by the randomization engine. In some examples, if the obtained security information asset was masked when it was obtained, re-masking may be performed by the randomization engine. In some examples, even if the obtained security information asset was masked when it was obtained, re-masking may be performed by the randomization engine. In some examples, masking and / or re-masking is performed before randomization. In other examples, masking and / or re-masking is performed after randomization.
[0059] At block 306, process 300 includes providing the randomized secure information asset to a secure storage device (e.g., Figure 1 In some examples, the randomized secure asset is generated by a randomization engine (e.g., Figure 1 The randomized security asset may or may not have been masked and / or re-masked prior to transmission. In some examples, providing the randomized security asset includes transmitting portions (e.g., bytes) of the security asset such that the order of the portions is randomized for transmission but can be stored in the correct order by the secure storage device.
[0060] In some aspects, the secure asset undergoes periodic re-masking while stored in a secure storage device. In some cases, the re-masking process is initiated when a usage threshold for the secure information asset is exceeded. In some examples, the re-masking process is initiated based on a determination that one or more bytes of the secure information asset have a usage exceeding a usage difference threshold relative to one or more other bytes of the secure information asset. In some cases, based on a determination that the usage difference threshold is exceeded for one or more bytes of the secure information asset, use of the secure information asset may be revoked.
[0061] At block 308, process 300 includes retrieving the data from the secure storage device (e.g., Figure 1 In some examples, the randomized secure information asset is generated by a randomization engine (e.g., Figure 1The randomized security information asset is obtained by the randomization engine 114. In some aspects, as discussed above, the randomized security information asset may have been re-masked any number of times while stored in the secure storage device before being obtained by the randomization engine from the secure storage device. In some examples, the randomized security information asset is randomized in order with respect to the portions of the security information during transmission from the secure storage device to the randomization engine.
[0062] At block 310, process 300 includes performing a second randomization on the security information asset to obtain an updated randomized security information asset. In some aspects, the second randomization is performed by a randomization engine (e.g., Figure 1 The randomization engine 114 of FIG. 1 is executed. In some examples, similar to the above description of block 304, the randomized secure asset may or may not be masked and / or re-masked before or after the second randomization. In some cases, the second randomization randomizes the order in which the portions (e.g., bytes) are transmitted.
[0063] At block 312, process 300 includes providing the updated randomized security information asset to a security component (e.g., Figure 1 The security components 118 and 120 may be configured to perform security operations, wherein the updated randomized security information asset is used to perform security operations. In some examples, the security component is aware of any randomization or masking applied to the security information asset, allowing the security information asset to be recovered for use. In some examples, the security information asset may then be used to perform security operations (e.g., encryption, decryption, additional cryptographic key derivation, any other steps and / or transformations performed using the security information asset, etc.).
[0064] In some examples, process 300 or any other process described herein can be performed by a computing device or apparatus and / or one or more components thereof and / or one or more components to which the computing device is operatively connected. As an example, process 300 can be performed in whole or in part by Figure 1 and described above, or Figure 1 any other components of the secure execution environment 112 shown in and described above, and / or Figure 4 The computing system 400 (or any one or more components thereof) shown in and described below executes.
[0065] The computing device can be any suitable device, can include any suitable device, or can be a component of any suitable device, such as a vehicle or a computing device for a vehicle (e.g., a driver monitoring system (DMS) for a vehicle), a mobile device (e.g., a mobile phone), a desktop computing device, a tablet computing device, a wearable device (e.g., a VR headset, an AR headset, AR glasses, a web-connected watch or smartwatch, or other wearable device), a server computer, a robotic device, a television, a smart speaker, a voice assistant device, a SoC, and / or any other device with the resources to perform the processes described herein (including process 300 and / or other processes described herein). In some cases, a computing device or apparatus (e.g., including a hardware identity emulator) can include various components, such as one or more input devices, one or more output devices, one or more processors, one or more microprocessors, one or more microcomputers, one or more cameras, one or more sensors, and / or other components configured to perform the operations of the processes described herein. In some examples, the computing device can include a display, a network interface configured to communicate and / or receive data, an RF sensing component, any combination thereof, and / or other components. The network interface may be configured to communicate and / or receive Internet Protocol (IP) based data or other types of data.
[0066] Computing devices (e.g. Figure 1 Components of the computing device 100 may be implemented at least in part in circuitry. For example, a component may include and / or be implemented using electronic circuitry or other electronic hardware, which may include one or more programmable electronic circuits (e.g., a microprocessor, a graphics processing unit (GPU), a digital signal processor (DSP), a central processing unit (CPU), a finite state machine, and / or other suitable electronic circuitry), and / or may include and / or be implemented at least in part using computer software, firmware, or any combination thereof for performing the various operations described herein.
[0067] Figure 3The process 300 shown in FIG is illustrated as a logical flow diagram, the operations of which represent a sequence of operations that can be implemented by hardware, computer instructions, or a combination thereof. In the context of computer instructions, each operation represents computer-executable instructions stored on one or more computer-readable storage media that, when executed by one or more processors, perform the described operations. Generally speaking, computer-executable instructions include routines, programs, objects, components, data structures, etc. that perform specific functions or implement specific data types. The order in which the operations are described is not intended to be construed as a limitation, and any number of the described operations may be combined in any order and / or in parallel to implement the process.
[0068] Additionally, process 300 and / or other processes described herein may be performed under the control of one or more computer systems configured with executable instructions and may be implemented as code (e.g., executable instructions, one or more computer programs, or one or more applications) that executes together on one or more processors, implemented in hardware, or implemented by a combination thereof. As noted above, the code may be stored on a computer-readable or machine-readable storage medium, for example, in the form of a computer program comprising a plurality of instructions that may be executed by one or more processors. The computer-readable or machine-readable storage medium may be non-transitory.
[0069] Figure 4 is a diagram illustrating an example of a system for implementing certain aspects of the present technology. Specifically, Figure 4 An example of a computing system 400 is illustrated, which can be any computing device, for example, constituting an internal computing system, a remote computing system, a camera, or any component thereof, wherein the components of the system communicate with each other using a connection 405. Connection 405 can be a physical connection using a bus, or a direct connection into processor 410, such as in a chipset architecture. Connection 405 can also be a virtual connection, a networked connection, or a logical connection.
[0070] In some examples, computing system 400 is a distributed system, in which the functionality described in this disclosure can be distributed within a data center, multiple data centers, a peer-to-peer network, etc. In some examples, one or more of the described system components represent a plurality of such components, each of which performs some or all of the functionality for which the component is described. In some examples, each component can be a physical or virtual device.
[0071] Example system 400 includes at least one processing unit (CPU or processor) 410 and connections 405 that couple various system components including system memory 415, such as read-only memory (ROM) 420 and random access memory (RAM) 425, to processor 410. Computing system 400 may include a cache 412 of high-speed memory directly connected to, in close proximity to, or integrated as part of processor 410.
[0072] Processor 410 may include any general-purpose processor and hardware or software services, such as services 432, 434, and 436 stored in storage device 430, configured to control processor 410 as well as a dedicated processor where software instructions are incorporated into the actual processor design. Processor 410 may essentially be a completely independent computing system containing multiple cores or processors, a bus, a memory controller, a cache, etc. Multi-core processors may be symmetric or asymmetric.
[0073] To enable user interaction, computing system 400 includes input device 445, which can represent any number of input mechanisms or sensors, such as a microphone for voice (e.g., user speaking), a touch-sensitive screen for gesture or graphical input (e.g., user performing a sign, user shaking a phone, etc.), a keyboard (e.g., user pressing a key), a mouse, motion input, determination that the user is at a location indicated by a positioning system or modem subsystem, etc. This can be used to activate the counters described in the previous section and enable / disable the asset delivery chain at any stage described previously. Computing system 400 can also include output device 435, which can be one or more of a plurality of output mechanisms. In some cases, a multimodal system can enable a user to provide multiple types of input / output to communicate with computing system 400. Computing system 400 can also include communication interface 440, which generally governs and manages user input and system output. The communication interface can perform or facilitate the reception and / or transmission of wired or wireless communications using wired and / or wireless transceivers, including utilizing audio jacks / plugs, microphone jacks / plugs, Universal Serial Bus (USB) ports / plugs, Apple ® Lightning ® Ports / plugs, Ethernet ports / plugs, Fiber optic ports / plugs, Dedicated wired ports / plugs, Bluetooth ® Wireless signal transmission, Bluetooth ® Low energy (BLE) wireless signal transmission, IBEACON ®The communication interface 440 may also include one or more global navigation satellite system (GNSS) receivers or transceivers for determining the location of the computing system 400 based on one or more signals received from one or more satellites associated with the one or more GNSS systems. GNSS systems include, but are not limited to, the United States' Global Positioning System (GPS), Russia's Global Navigation Satellite System (GLONASS), China's BeiDou Navigation Satellite System (BDS), and Europe's Galileo GNSS. There is no restriction on operating on any particular hardware arrangement, and thus the base features herein may be readily substituted for improved hardware or firmware arrangements as they are developed.
[0074] The storage device 430 may be a non-volatile and / or non-transitory and / or computer-readable memory device and may be a hard disk or other type of computer-readable medium that can store data that can be accessed by a computer, such as a magnetic tape cartridge, a flash memory card, a solid-state memory device, a digital versatile disk, a magnetic cassette, a floppy disk, a flexible disk, a hard disk, a magnetic tape, a magnetic stripe / strip, any other magnetic storage medium, a flash memory device, a memristor memory, any other solid-state memory, a compact disk read-only memory (CD-ROM) optical disk, a rewritable compact disk (CD) optical disk, a digital video disk (DVD) optical disk, a Blu-ray ® optical disc (BDD), holographic disc, another optical medium, Secure Digital (SD) card, micro Secure Digital (microSD) card, Memory Stick ®The memory device 430 may include a card, a smart card chip, an EMV chip, a subscriber identity module (SIM) card, a mini / micro / nano / pico SIM card, another integrated circuit (IC) chip / card, a random access memory (RAM), a static RAM (SRAM), a dynamic RAM (DRAM), a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a flash EPROM (FLASHEPROM), a cache memory (L1 / L2 / L3 / L4 / L5 / L#), a resistive random access memory (RRAM / ReRAM), a phase change memory (PCM), a spin-transfer torque RAM (STT-RAM), another memory chip or cartridge, and / or a combination thereof. The memory device 430 may include software instructions or code that can be executed by the processor 410 to enable the system 400 to perform functions.
[0075] As used herein, the term "computer-readable medium" includes, but is not limited to, portable or non-portable storage devices, optical storage devices, and various other media capable of storing, containing, or carrying instructions and / or data. Computer-readable media may include non-transitory media that can store data and does not include carrier waves and / or transient electronic signals propagating wirelessly or over a wired connection. Examples of non-transitory media include, but are not limited to, magnetic disks or tapes, optical storage media (such as compact discs (CDs) or digital versatile discs (DVDs)), flash memory, memory, or storage devices. A computer-readable medium may have stored thereon code and / or machine-executable instructions, which may represent a procedure, function, subroutine, program, routine, subroutine, module, software package, class, or any combination of instructions, data structures, or program statements. A code segment may be coupled to another code segment or hardware circuit by passing and / or receiving information, data, arguments, parameters, or memory contents. Information, arguments, parameters, data, etc. may be passed, forwarded, or transmitted using any suitable means, including memory sharing, message passing, token passing, network transmission, and the like.
[0076] In some examples, computer-readable storage devices, media, and memories may include cables or wireless signals containing bit streams, etc. However, when referred to, non-transitory computer-readable storage media specifically excludes media such as power consumption, carrier signals, electromagnetic waves, and signals themselves.
[0077] Specific details are provided in the description above to provide a thorough understanding of the examples and examples provided herein. However, it will be understood by those skilled in the art that examples can be implemented without these specific details. For clarity of explanation, in some cases, the present technology can be presented as including separate functional blocks, including functional blocks that include devices, device components, operations, steps or routines in methods embodied in a combination of software, hardware or hardware and software. Additional components other than those components shown in the accompanying drawings and / or described herein can be used. For example, circuits, systems, networks, processes and other components can be shown as components in block diagram form so as not to obscure examples in unnecessary details. In other cases, known circuits, processes, algorithms, structures and techniques may be shown without unnecessary details to avoid obscuring examples.
[0078] The various examples above may be described as processes or methods, which may be depicted as flow charts, flow diagrams, data flow diagrams, structure diagrams, or block diagrams. Although a flow chart may describe operations as a sequential process, many of the operations may be performed in parallel or concurrently. Furthermore, the order of the operations may be rearranged. A process is terminated when its operations are completed, but a process may have additional operations not included in the accompanying figures. A process may correspond to a method, function, procedure, subroutine, subprogram, etc. When a process corresponds to a function, the termination of the process may correspond to the function returning to the calling function or the main function.
[0079] The processes and methods according to the examples described above can be implemented using stored computer-executable instructions or computer-executable instructions otherwise obtained from a computer-readable medium. Such instructions may include, for example, instructions and data that cause or otherwise configure a general-purpose computer, a special-purpose computer, or a processing device to perform a certain function or group of functions. Portions of the computer resources used may be accessible over a network. The computer-executable instructions may be, for example, binary, intermediate format instructions such as assembly language, firmware, source code, etc. Examples of computer-readable media that can be used to store instructions, information used, and / or information created during the methods according to the described examples include magnetic or optical disks, flash memory, USB devices with non-volatile memory, networked storage devices, etc.
[0080] Devices implementing the processes and methods according to these disclosures may include hardware, software, firmware, middleware, microcode, hardware description languages, or any combination thereof, and may take any of a variety of form factors. When implemented in software, firmware, middleware, or microcode, program code or code segments (e.g., a computer program product) for performing the necessary tasks may be stored in a computer-readable or machine-readable medium. A processor may perform the necessary tasks. Typical examples of form factors include laptop computers, smartphones, mobile phones, tablet devices or other small form factor personal computers, personal digital assistants, rack-mounted devices, stand-alone devices, etc. The functionality described herein may also be embodied in peripheral devices or add-in cards. By way of further example, such functionality may also be implemented on circuit boards in different chips or different processes executed on a single device.
[0081] Instructions, media for conveying such instructions, computing resources for executing them, and other structures for supporting such computing resources are example means for providing the functionality described in this disclosure.
[0082] In the foregoing description, various aspects of the present application have been described with reference to the specific examples of the present application, but those skilled in the art will recognize that the present application is not limited thereto. Therefore, although the illustrative examples of the present application have been described in detail herein, it should be understood that the inventive concept can be implemented and adopted in various other ways, and the appended claims are intended to be interpreted as including these variations, unless limited by the prior art. The various features and aspects of the application described above can be used individually or in combination. In addition, the examples described herein can be utilized in any number of environments and applications beyond those described herein without departing from the broader essence and scope of this specification. Therefore, the description and the accompanying drawings should be considered to be illustrative and not restrictive. For illustrative purposes, each method is described in a specific order. It should be understood that in an alternative example, the method can be performed in an order different from the described order.
[0083] It should be understood by those skilled in the art that the less than ("<") and greater than (">") symbols or terms used herein may be replaced by less than or equal to (" ") and greater than or equal to (" ) symbol instead.
[0084] Where a component is described as being “configured to” perform certain operations, such configuration may be achieved, for example, by designing electronic circuits or other hardware to perform the operations, by programming programmable electronic circuits (e.g., a microprocessor or other suitable electronic circuits) to perform the operations, or any combination thereof.
[0085] The phrase “coupled to” refers to any component being directly or indirectly physically connected to another component, and / or any component being in direct or indirect communication with another component (e.g., connected to another component via a wired or wireless connection and / or other suitable communication interface).
[0086] Claim language or other language that recites "at least one of" a set and / or "one or more of" a set indicates that one member of the set or multiple members of the set (in any combination) satisfies the claim. For example, claim language that recites "at least one of A and B" or "at least one of A or B" means A, B, or A and B. In another example, claim language that recites "at least one of A, B, and C" or "at least one of A, B, or C" means A, B, C, or A and B, or A and C, or B and C, or A, B, and C. The language "at least one of" a set and / or "one or more of" a set does not limit the set to the items listed in the set. For example, claim language that recites "at least one of A and B" or "at least one of A or B" may mean A, B, or A and B, and may additionally include items not listed in the set of A and B.
[0087] The various illustrative logic blocks, modules, circuits, and algorithmic operations described in conjunction with the examples disclosed herein can be implemented as electronic hardware, computer software, firmware, or a combination thereof. In order to clearly illustrate this interchangeability of hardware and software, various illustrative components, blocks, modules, circuits, and operations have been generally described above in terms of their functionality. Whether such functionality is implemented as hardware or software depends on the specific application and the design constraints imposed on the entire system. Technicians can implement the described functionality in different ways for each specific application, but such specific implementation decisions should not be interpreted as departing from the scope of this application.
[0088] The techniques described herein may also be implemented in electronic hardware, computer software, firmware, or any combination thereof. Such techniques may be implemented in any of a variety of devices, such as general-purpose computers, wireless communication devices, or integrated circuit devices with multiple uses, including applications in wireless communication devices and other devices. Any features described as modules or components may be implemented together in an integrated logic device or separately as discrete but interoperable logic devices. If implemented in software, these techniques may be implemented at least in part by a computer-readable data storage medium containing program code, including instructions that, when executed, perform one or more of the methods described above. The computer-readable data storage medium may form part of a computer program product, which may include packaging materials. The computer-readable medium may include memory or data storage media, such as random access memory (RAM) (such as synchronous dynamic random access memory (SDRAM)), read-only memory (ROM), non-volatile random access memory (NVRAM), electrically erasable programmable read-only memory (EEPROM), flash memory, magnetic or optical data storage media, and the like. Additionally or alternatively, the technology may be implemented at least in part by a computer-readable communication medium that carries or communicates program code in the form of instructions or data structures and that can be accessed, read, and / or executed by a computer, such as a propagated signal or wave.
[0089] The program code may be executed by a processor, which may include one or more processors, such as one or more digital signal processors (DSPs), general-purpose microprocessors, application-specific integrated circuits (ASICs), field-programmable logic arrays (FPGAs), or other equivalent integrated or discrete logic circuitry. Such a processor may be configured to perform any of the techniques described in this disclosure. A general-purpose processor may be a microprocessor; however, in the alternative, the processor may be any conventional processor, controller, microcontroller, or state machine. A processor may also be implemented as a combination of computing devices, such as a combination of a DSP and a microprocessor, multiple microprocessors, one or more microprocessors in conjunction with a DSP core, or any other such configuration. Thus, as used herein, the term "processor" may refer to any of the foregoing structures, any combination of the foregoing structures, or any other structure or device suitable for implementing the techniques described herein.
[0090] Illustrative aspects of the present disclosure include:
[0091] Aspect 1: A method for information protection, the method comprising: obtaining a security information asset at a randomization engine; performing a first randomization on the security information asset to obtain a randomized security information asset; providing the randomized security information asset to a secure storage device; obtaining the randomized security information asset from the secure storage device; performing a second randomization on the security information asset to obtain an updated randomized security information asset; and providing the updated randomized security information asset to a security component, wherein the updated randomized security information asset is used to perform a security operation.
[0092] Aspect 2: The method according to aspect 1, wherein the security information asset is an encryption key.
[0093] Aspect 3: A method according to any one of Aspects 1 or 2, wherein the security information asset is obtained in a masked form, and the method further comprises: performing re-masking on the security information asset to obtain a re-masked security information asset, wherein the re-masked security information asset is used to perform the first randomization.
[0094] Aspect 4: A method according to any one of Aspects 1 to 3, wherein the security information asset is obtained in an unmasked form, and the method further comprises: performing a mask on the security information asset to obtain a masked security information asset, wherein the first randomization is performed using the masked security information asset.
[0095] Aspect 5: The method according to any one of aspects 1 to 5, wherein the secure information asset is obtained from a secure information asset storage device.
[0096] Aspect 6: The method according to any one of aspects 1 to 5, wherein the updated randomized security information asset is used to derive additional security information assets for performing security operations.
[0097] Aspect 7: A method according to any one of Aspects 1 to 6, wherein, before being provided to the security component, the updated randomized security information asset is enhanced to include additional information about the processing history of the security information asset and a security policy, wherein the security policy specifies allowed operations and one or more entities authorized to interact with the security information asset.
[0098] Aspect 8: The method according to any one of aspects 1 to 7, further comprising: forcing a re-masking process on the randomized secure information asset at the secure storage device.
[0099] Aspect 9: The method according to any one of aspects 1 to 8, wherein the re-masking process is initiated when a usage threshold of the secure information asset is exceeded.
[0100] Aspect 10: The method according to any one of Aspects 1 to 9, wherein the re-masking process is initiated based on determining that one or more bytes of the security information asset have a usage amount exceeding a usage difference threshold relative to one or more other bytes of the security information asset.
[0101] Aspect 11: The method of any one of aspects 1 to 10, further comprising: determining that one or more bytes of the secure information asset exceed a usage difference threshold; and canceling usage of the secure information asset based on the determination.
[0102] Aspect 12: The method of any one of aspects 1 to 11, wherein the randomization engine is included in a secure execution environment.
[0103] Aspect 13: The method according to any one of aspects 1 to 12, wherein the security component is a cryptographic engine.
[0104] Aspect 14: The method according to any one of aspects 1 to 13, wherein the security component is a key table.
[0105] Aspect 15: The method according to any one of aspects 1 to 14, wherein the security component is a key derivation function.
[0106] Aspect 16: An apparatus for information protection, the apparatus comprising: at least one memory; and at least one processor, the at least one processor being coupled to the at least one memory and configured to: obtain a security information asset at a randomization engine; perform a first randomization on the security information asset to obtain a randomized security information asset; provide the randomized security information asset to a secure storage device; obtain the randomized security information asset from the secure storage device; perform a second randomization on the security information asset to obtain an updated randomized security information asset; and provide the updated randomized security information asset to a security component, wherein the updated randomized security information asset is used to perform a security operation.
[0107] Aspect 17: The apparatus of aspect 16, wherein the security information asset is an encryption key.
[0108] Aspect 18: An apparatus according to Aspect 16 or 17, wherein the security information asset is obtained in a masked form, and the processor is further configured to: perform re-masking on the security information asset to obtain a re-masked security information asset, wherein the first randomization is performed using the re-masked security information asset.
[0109] Aspect 19: An apparatus according to any one of Aspects 16 to 18, wherein the security information asset is obtained in an unmasked form, and the processor is further configured to: perform a mask on the security information asset to obtain a masked security information asset, wherein the first randomization is performed using the masked security information asset.
[0110] Aspect 20: The apparatus according to any one of aspects 16 to 19, wherein the secure information asset is obtained from a secure information asset storage device.
[0111] Aspect 21: The apparatus of any one of aspects 16 to 20, wherein the updated randomized security information asset is used to derive additional security information assets for performing a security operation.
[0112] Aspect 22: An apparatus according to any one of Aspects 16 to 21, wherein, before being provided to the security component, the updated randomized security information asset is enhanced to include additional information about the processing history of the security information asset and a security policy that specifies permitted operations and one or more entities authorized to interact with the security information asset.
[0113] Aspect 23: The apparatus of any one of aspects 16 to 22, wherein the processor is further configured to: enforce a re-masking process on the randomized secure information asset at the secure storage device.
[0114] Aspect 24: The apparatus of any one of aspects 16 to 23, wherein the re-masking process is initiated when a usage threshold of the secure information asset is exceeded.
[0115] Aspect 25: An apparatus according to any one of Aspects 16 to 24, wherein the re-masking process is initiated based on determining that one or more bytes of the security information asset have a usage amount exceeding a usage difference threshold relative to one or more other bytes of the security information asset.
[0116] Aspect 26: The apparatus of any one of aspects 16 to 25, wherein the processor is further configured to: determine that one or more bytes of the secure information asset exceed a usage difference threshold; and cancel usage of the secure information asset based on the determination.
[0117] Aspect 27: The apparatus of any one of Aspects 16 to 26, wherein the randomization engine is included in a secure execution environment.
[0118] Aspect 28: The apparatus of any one of aspects 16 to 27, wherein the security component is a cryptographic engine.
[0119] Aspect 29: The apparatus of any one of aspects 16 to 28, wherein the security component is a key table.
[0120] Aspect 30: The apparatus of any one of aspects 16 to 29, wherein the security component is a key derivation function.
[0121] Aspect 31. A non-transitory computer-readable medium having instructions stored thereon, the instructions, when executed by at least one processor, causing the at least one processor to perform the operations of any one of aspects 1 to 15.
[0122] Aspect 32. An apparatus for information protection, the apparatus comprising one or more components for performing the operations according to any one of aspects 1 to 15.
Claims
1. A method for information protection, comprising: obtaining a security information asset at a randomization engine; performing a first randomization on the security information asset to obtain a randomized security information asset; providing the randomized secure information asset to a secure storage device; Obtaining the randomized secure information asset from the secure storage device; performing a second randomization on the security information asset to obtain an updated randomized security information asset; as well as The updated randomized security information assets are provided to a security component, wherein the updated randomized security information assets are used to perform a security operation.
2. The method of claim 1, wherein the security information asset is an encryption key.
3. The method according to claim 1, wherein the security information asset is obtained in a mask form, and the method further comprises: Re-masking is performed on the secure information asset to obtain a re-masked secure information asset, wherein the first randomization is performed using the re-masked secure information asset.
4. The method of claim 1 , wherein the secure information asset is obtained in an unmasked form, and further comprising: Masking is performed on the security information asset to obtain a masked security information asset, wherein the first randomization is performed using the masked security information asset. The method according to claim 1 , wherein the secure information asset is obtained from a secure information asset storage device.
6. The method of claim 1, wherein the updated randomized security information asset is used to derive additional security information assets for performing security operations.
7. The method of claim 1 , wherein, before being provided to the security component, the updated randomized security information asset is enhanced to include additional information associated with a processing history of the security information asset and a security policy specifying permitted operations and one or more entities authorized to interact with the security information asset.
8. The method according to claim 1, further comprising: A re-masking process is enforced on the randomized secure information asset at the secure storage device.
9. The method of claim 8, wherein the re-masking process is initiated when a usage threshold of the secure information asset is exceeded.
10. The method of claim 8, wherein the re-masking process is initiated based on determining that one or more bytes of the secure information asset have an amount of usage exceeding a usage difference threshold relative to one or more other bytes of the secure information asset.
11. The method according to claim 1 , further comprising: determining that one or more bytes of the security information asset exceed a usage difference threshold; as well as The secure information asset is removed from use based on the determination.
12. The method of claim 1, wherein the randomization engine is included in a secure execution environment.
13. The method of claim 1, wherein the security component is a cryptographic engine. The method of claim 1 , wherein the security component is a key table.
15. The method of claim 1, wherein the security component is a key derivation function.
16. A device for information protection, comprising: at least one memory; and at least one processor coupled to the at least one memory and configured to: obtaining a security information asset at a randomization engine; performing a first randomization on the security information asset to obtain a randomized security information asset; providing the randomized secure information asset to a secure storage device; Obtaining the randomized secure information asset from the secure storage device; performing a second randomization on the security information asset to obtain an updated randomized security information asset; as well as The updated randomized security information assets are provided to a security component, wherein the updated randomized security information assets are used to perform a security operation. The apparatus of claim 16 , wherein the security information asset is an encryption key.
18. The apparatus of claim 16, wherein the security information asset is obtained in a masked form, and the at least one processor is further configured to: perform a re-mask on the security information asset to obtain a re-masked security information asset, wherein the first randomization is performed using the re-masked security information asset.
19. The apparatus of claim 16, wherein the security information asset is obtained in an unmasked form, and the at least one processor is further configured to: perform a mask on the security information asset to obtain a masked security information asset, wherein the first randomization is performed using the masked security information asset.
20. The apparatus of claim 16, wherein the secure information asset is obtained from a secure information asset storage device.
21. The apparatus of claim 16, wherein the updated randomized security information assets are used to derive additional security information assets for performing security operations.
22. The apparatus of claim 16, wherein, before being provided to the security component, the updated randomized security information asset is enhanced to include additional information associated with a processing history of the security information asset and a security policy specifying permitted operations and one or more entities authorized to interact with the security information asset.
23. The apparatus of claim 16, wherein the at least one processor is further configured to: A re-masking process is enforced on the randomized secure information asset at the secure storage device.
24. The apparatus of claim 23, wherein the re-masking process is initiated when a usage threshold of the secure information asset is exceeded.
25. The apparatus of claim 23, wherein the re-masking process is initiated based on determining that one or more bytes of the secure information asset have an amount of usage exceeding a usage difference threshold relative to one or more other bytes of the secure information asset.
26. The apparatus of claim 16, wherein the at least one processor is further configured to: determining that one or more bytes for the security information asset exceeds a usage difference threshold; and The secure information asset is removed from use based on the determination.
27. The apparatus of claim 16, wherein the randomization engine is included in a secure execution environment.
28. The apparatus of claim 16, wherein the security component is a cryptographic engine.
29. The apparatus of claim 16, wherein the security component is a key table.
30. The apparatus of claim 16, wherein the security component is a key derivation function.