Method for providing a digital key
Patent Information
- Application Number
- EP2023754812
- Authority / Receiving Office
- EP · EP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-08-19
- Filing Date
- 2023-08-21
- Publication Date
- 2025-06-25
AI Technical Summary
Existing methods for providing digital keys to processor units lack sufficient security measures to prevent unauthorized access, as they do not effectively hide the key within the application code and rely on conventional encryption methods that can be vulnerable to attacks.
A method where a digital key is split into multiple parts and embedded within an application code, specifically in unused fields of R-type instructions, and calculated using a hardware identifier, making it difficult for unauthorized users to reconstruct the key without the necessary hardware information.
This approach enhances security by hiding the key within the application code and requiring specific hardware information for reconstruction, significantly increasing the difficulty for attackers to access the digital key, while maintaining the overall size of the application code unchanged.
Smart Images

Figure 1.1
Abstract
Description
[0001] Method for providing a digital key
[0002] The present invention is in the field of cryptography. In particular, the present invention relates to a method for providing a digital key by a computer system to a processor unit, as well as a corresponding method for reconstructing a digital key by a processor unit.
[0003] In some application scenarios, it is desirable to provide a digital key for a processing unit. The digital key contains secret information intended for a specific processing unit. For example, the provided secret information can be used for subsequent authentication of the processing unit.
[0004] Numerous methods for providing digital keys are known in cryptography, each with advantages and disadvantages. However, all methods require the digital key to be provided securely, preventing unauthorized access. While no method can generally offer 100% security, it is at least desirable to make a potential attack by an unauthorized person as difficult as possible.
[0005] US 2019 / 028273 A1 describes a method for encrypting data. This method does not use conventional keys for encryption. Instead, future events are used as a secret key for encryption. Transient keys, which are not permanently stored, are used to encrypt the data. This reduces the risk of key theft.
[0006] US 2020 / 159676 A1 proposes a method for encrypting data. This method uses cryptographically encoded pointers in a multi-party environment. For example, first instructions are provided to generate a first address key for a private memory area in a memory unit and to generate a first cryptographically encoded pointer directed to the private memory area of the memory unit. The generation of the first cryptographically encoded pointer includes storing context information associated with the private memory area. This method may allow one party in the multi-party environment to access the first address key and the first cryptographically generated pointer directed to the private memory area.
[0007] Taking into account the situation described above, it is the object of the present invention to provide a method for providing a digital key for a processor unit, in which access to the digital key by an unauthorized person is made as difficult as possible.
[0008] To achieve the stated object, the present invention proposes a method for providing a digital key by a computer system for a processor unit, wherein the digital key is provided within an application code, and wherein a sequence of instructions is stored in the application code. The method according to the invention comprises the following method steps:
[0009] generating a digital key to be provided by a computer system;
[0010] Dividing the digital key into at least two key parts;
[0011] Embedding the key parts in at least two instructions of the application code; and
[0012] Transferring the application code from the computer system to the processor unit.
[0013] In the method according to the invention, the digital key is embedded in application code and "hidden" therein. The different key components are stored in different instructions of the application code. The processor unit has knowledge of the locations in the application code where the secret information is stored, so that after receiving the application code, the processor unit can reconstruct the digital key and the secret information contained therein. In this way, the key to be transmitted is hidden in the application code in such a way that it is difficult for a potential attacker to reconstruct the secret information, since they lack knowledge of the location in the application code where the individual key components are stored. In this respect, the application code has areas in which instructions are encoded, as well as areas in which the secret information is encoded.The division of the digital key and the embedding of the key parts are carried out by the computer system, which in the context of the present invention can also be referred to as a compiler system.
[0014] According to one embodiment of the present invention, it can be provided that embedding the key parts in at least two instructions of the application code comprises embedding the key parts in specific fields of the instructions that typically remain unused. In practice, it has been found that some instruction sets for processor units provide instructions that contain specific fields that are not used. Therefore, it is advantageous to arrange the key parts in the unused fields of the instructions. In this way, a particularly efficient provision of a digital key can be achieved. The preferred embodiment therefore allows a digital key to be embedded in application code without increasing the overall size of the application code.
[0015] Preferably, it can be provided that the application code is designed as RISC-V (Reduced Instruction Set Computers V) application code, wherein the instructions are designed in particular as R-type instructions and wherein the embedding of the key parts preferably takes place in Funct7 fields. As already explained above, the key parts can preferably be embedded in unused fields of the instructions. An example of this are the aforementioned R-type instructions of the RISC-V instruction sets. Within the R-type instructions, for example, the Funct7 fields are provided, which are typically unused. The Funct7 fields are therefore particularly suitable for embedding the key parts in these fields. In this way, a digital key can be embedded in an application code without increasing the amount of data required by the application code.This ensures particularly efficient provision of the digital key. Although the Funct7 fields of the R-type instructions were mentioned above, for example, it will be apparent to those skilled in the art that the present application is not limited to these fields. Rather, the key parts can also be embedded in a variety of other fields or other instructions.
[0016] In an advantageous embodiment of the method according to the invention, it can further be provided that the generation of the digital key to be provided by the computer system comprises the following method steps:
[0017] generating a first key by the computer system, wherein the first key contains secret information to be transmitted to the processor unit;
[0018] Reading a hardware identifier from the processor unit, wherein the hardware identifier has a unique identifier of the processor unit; and
[0019] Calculating the digital key to be provided by the computer system, wherein the calculation is carried out from the first key and the hardware identifier.
[0020] The first key can also be considered a software key, as it is generated using software and contains no hardware-related information. In particular, this first key does not contain any hardware-dependent information that specifies the processor unit. In contrast, the hardware identifier contains specific information about the processor unit. In particular, the hardware identifier allows for a unique assignment of the respective processor unit for which the digital key is to be provided. The hardware identifier can also be referred to as a hardware fingerprint. In general, various hardware identifiers are known that allow the unique identification of a processor unit. Some specific examples of hardware identifiers are given below.The hardware identifier can be read out by a request from the computer system to the processor unit and a subsequent response from the processor unit to the computer system. Calculating the digital key to be provided from the first key and the hardware identifier has the advantage that the hardware identifier of the processor unit must be known for the subsequent reconstruction of the first key. In other words, the first key is encrypted with the hardware identifier. An unauthorized person who has previously succeeded in gaining knowledge of the digital key cannot therefore easily reconstruct the first key. In this way, the security of the method according to the invention is further increased. Various options are available for calculating the digital key to be provided from the first key and the hardware identifier.For example, the digital key can be calculated as the sum of the first key and the hardware identifier. In this case, the processor unit, which possesses its specific hardware identifier, can calculate the first key by subtracting the hardware identifier from the received digital key. Similarly, it can also be provided that the digital key to be provided is calculated by multiplying the first key and the hardware identifier, or by subtracting the hardware identifier from the first key.
[0021] According to the method according to the invention, it can be provided that the hardware identifier has a serial number of the processor unit or a serial number of a memory element of the processor unit.
[0022] Furthermore, the method according to the invention can provide for the hardware identifier to contain specific information about a memory element, in particular a DRAM memory element of the processor unit. This takes advantage of the fact that the memory elements of a processor unit are in fact never completely identical, but rather have marginal differences, which enables identification of the memory element or processor unit.
[0023] The method according to the invention can also provide that the calculation of the digital key to be provided from the first key and the hardware identifier comprises the application of an XOR operator to the first key and the hardware identifier.
[0024] According to a preferred embodiment of the method according to the invention, the hardware identifier can be configured as a temperature-dependent hardware identifier. This further increases the security of the method according to the invention. An attacker who has previously succeeded in obtaining knowledge of the provided digital key and also of a hardware identifier cannot easily reconstruct the first key, since the key required for decryption (= hardware identifier) can only be read at a specific temperature.For example, if a hardware identifier was read at a temperature of 20°C during the generation of the digital key to be provided by the computer system, but the attack by the unauthorized person was carried out at a temperature of 25°C, the attacker will obtain a hardware identifier that is unsuitable for reconstructing the first key. This significantly complicates a potential unauthorized attack.
[0025] According to an advantageous embodiment of the method according to the invention, the hardware identifier can contain information about the specific charging time of the capacitors of the DRAM memory element or information about the latency times of the DRAM memory element. The specific charging time of the capacitors of the DRAM memory element and the information about the latency times of the DRAM memory element are specific quantities that allow reliable identification of the corresponding DRAM memory element. During the subsequent reconstruction of the first key, the processor unit, which has knowledge of the information concerning the DRAM memory element, can decrypt the digital key using this information.For a potential attacker who does not have the aforementioned hardware information, however, it is impossible (or at least significantly more difficult) to obtain the first key without the necessary hardware information. Furthermore, according to a preferred embodiment of the method according to the invention, the hardware identifier can be determined using a machine learning-based method. The machine learning-based method can have been previously trained with training data.The training data can, for example, have temperature values (or temperature ranges) and read-out measured values (for example, specifically read-out information from a DRAM memory element, in particular specific information about the specific charging time of the capacitors or about the latency times of the memory element) as input variables, as well as hardware identifiers corresponding to the input variables as output variables. The read-out measured values can, in particular, be temperature-dependent values. In this way, the machine learning-based method can learn during a training process which hardware identifier is to be generated for one or more processor units at specific temperatures. If a hardware identifier orIf the measured values assigned to the hardware identifier are read at a specific temperature, the machine learning-based process can, for example, calculate a uniform hardware identifier that allows unique identification of the processor unit. This way, temperature-dependent effects can be compensated for, so that the same hardware identifier is always output for a processor unit, regardless of the current ambient temperature.
[0026] Furthermore, to achieve the above-described problem, a method for reconstructing a digital key by a processor unit is proposed, the method comprising the following steps:
[0027] Receiving application code from a computer system, wherein a sequence of instructions and a digital key are stored in the application code; and wherein the digital key has at least two key parts that are not stored contiguously in the application code;
[0028] Compiling the digital key from the at least two key parts. The processor unit has advance information about where in the application code the individual key parts are stored. For example, the processor unit may know that a specific field of a specific instruction is intended for storing the key parts. In this way, the processor unit can search the application code for the specific fields, extract the individual key parts from these fields, and then assemble the individual key parts into a digital key. Furthermore, the processor unit can be modified to interpret additional instructions regarding the total number of key parts stored in the application code. This is advantageous in that its length is determined as early as possible for later use of the overall key.This also enables effective partial use of the entire key for various applications at a later date. It is well known from the state of the art in cryptography that the same key should, if possible, only be used for one specific purpose, such as encryption or the creation of a digital signature, but not both at the same time.
[0029] Preferably, it can be provided that the application code is designed as an R.ISC-V application code, wherein the instructions are designed in particular as R-type instructions and wherein the embedding of the key parts preferably takes place in Funct7 fields.
[0030] In addition, the procedure may include the following step:
[0031] Calculating a first key containing secret information from the digital key received from the computer system and a hardware identifier of the processor unit.
[0032] The first key is calculated depending on how the digital key was previously calculated. The first digital key can be calculated, for example, by addition, subtraction, or by applying the XOR operator to the received digital key and the hardware identifier. Preferably, the hardware identifier can contain specific information of a DRAM memory element of the processor unit.
[0033] Advantageously, it can be provided that the hardware identifier is designed as a temperature-dependent hardware identifier.
[0034] It can further be provided that the hardware identifier contains information about the specific charging time of the capacitors of the DRAM memory element or information about the latency times of the DRAM memory element.
[0035] Furthermore, to achieve the object described above, a computer system comprising a computing unit, a memory unit and a communication unit is proposed, wherein the computer system is provided for providing a digital key within an application code and wherein the computing unit of the computer system is configured to provide a digital key; to divide the digital key into at least two key parts; to embed the key parts in at least two instructions of the application code; and to transmit the application code to a processor unit.
[0036] Furthermore, to achieve the object described above, a processor unit for reconstructing a digital key is proposed, wherein the processor unit is configured to receive an application code from a computer system, wherein a sequence of instructions and a digital key are stored in the application code; and wherein the digital key has at least two key parts that are not stored contiguously in the application code; to assemble the digital key from the at least two key parts.Furthermore, to advantageously carry out the present task and to increase security, a cryptographic processing unit can be provided which, in cooperation with the latter units of the overall system, applies any error corrections, but also isolates the overall key from the processor unit in such a way that cryptographic operations such as encryption or digital signatures are executed directly by this unit, and only the results of these operations are transmitted to the processor unit. This results in a strong separation and secrecy of the overall key from the higher-level program logic.
[0037] The present invention will be explained in more detail below with reference to the figures.
[0038] Fig. 1 shows a first embodiment of the method according to the invention,
[0039] Fig. 2 shows the method steps for generating the digital key to be provided according to an embodiment of the invention,
[0040] Fig. 3 an instruction with different fields that are partly occupied and partly unused, and
[0041] Fig. 4 a system comprising a computer system and a processor unit.
[0042] Fig. 1 shows a first exemplary embodiment of the method 100 according to the invention. In this exemplary embodiment, the method 100 according to the invention comprises the method steps 110-140. In the first method step 110, a computer system generates a digital key to be provided. The digital key can be a randomly generated number. The digital key contains information that is to be provided to the processor unit in a secure manner so that potential attackers cannot easily reconstruct this key. In the second method step 120, the digital key is divided into at least two key parts. In practice, the digital key can be divided into several tens, several hundreds, or even several thousand thousand key parts. The inventive principle remains the same regardless of the exact number of key parts.Subsequently, in the third method step 130, the respective key parts are embedded in at least two instructions 20 of the application code. According to a particularly efficient embodiment of the present invention, the key parts can be embedded in specific fields of instructions that normally remain unused. This allows a digital key to be embedded in application code without affecting the overall size of the application code. On the one hand, this is particularly efficient because a digital key can be integrated without increasing the amount of data required by the application code. On the other hand, it can prevent a potential attacker from being able to deduce whether the application code contains a key or not based on the size of the application code. For example, the application code can be an R.This could be ISC-V application code, with the key parts being embedded in Funct7 fields of the R-type instructions. Subsequently, in the fourth method step 140, the application code is transmitted from the computer system to the processor unit. The processor unit can then reconstruct the digital key from the received application code.
[0043] Fig. 2 shows the method steps for generating (step 110 in Fig. 1) the digital key to be provided by the computer system according to a first exemplary embodiment of the invention. In a first sub-step 112, a first key is generated which contains secret information to be transmitted to the processor unit. The first key is encrypted before transmission to the processor unit using a hardware-based key so that a potential attacker cannot easily reconstruct this first key. In the second sub-step 114, a hardware identifier of the processor unit is read out. The hardware identifier (also referred to as hardware ID) has a unique identifier for the processor unit and thus enables unique identification of the processor unit.In particular, the hardware identifier can contain specific information of a DRAM memory element of the processor unit. In a third part, step 116, the digital key to be provided, which is transmitted to the processor unit, is calculated from the first key and the hardware identifier. As already explained above, the calculation can be performed, for example, by addition, subtraction, or by applying the XOR operator to the first digital key and the hardware identifier. The first digital key and the hardware identifier can be embodied, for example, as binary numbers, each with 128 bits or 256 bits.
[0044] Fig. 3 shows an instruction 20 with various fields 22, some of which are occupied and some of which are unused. For example, each field 22 can be 10 bits long. The instruction 20 shown in Fig. 3 can thus comprise 80 bits. Of the total of eight fields 22, five fields 22 are occupied with information relating to the instruction 20. These are shown in Fig. 3 as hatched fields 22. Furthermore, the instruction 20 shown in Fig. 3 comprises three fields 22 that are unused. The unused fields 22 are particularly well suited as containers for holding the key parts. If the key parts are stored in these containers, the digital key can be provided in a particularly efficient manner without changing the amount of data required by the application code.
[0045] Fig. 4 depicts a system 10 comprising a computer system 12 and a processor unit 14. In the exemplary embodiment shown in Fig. 4, bidirectional communication exists between the computer system 12 and the processor unit 14. For example, the computer system 12 can read a hardware identifier of the processor unit 14 and then calculate the digital key to be provided from a first key containing secret information and the hardware identifier. In this way, the computer system 12 can generate a key to be provided that is encrypted with hardware information of the processor unit 14.After the digital key to be provided has been generated by the computer system 12, the digital key to be provided can be divided into at least two key parts, wherein the individual key parts are embedded in at least two instructions of the application code before the application code is transmitted to the processor unit 14. LIST OF REFERENCE SYMBOLS.
[0046] system
[0047] computer system
[0048] Processor unit
[0049] Instruction
[0050] Field
[0051] Process first process step first sub-step second sub-step third sub-step second process step third process step fourth process step
Claims
CLAIMS Method (100) for providing a digital key by a computer system (12) for a processor unit (14), wherein the digital key is provided within an application code and wherein a sequence of instructions (20) is stored in the application code, characterized in that the method (100) comprises the following steps: generating (110) a digital key to be provided by a computer system (12); dividing (120) the digital key into at least two key parts; Embedding (130) the key parts in at least two instructions (20) of the application code; and Transmitting (140) the application code from the computer system (12) to the processor unit (14). The method (100) according to claim 1, characterized in that embedding (130) the key parts in at least two instructions (20) of the application code comprises embedding the key parts in specific fields of the instructions (20) that typically remain unused. The method (100) according to claim 1 or 2, characterized in that the application code is designed as an R.ISC-V application code, wherein the instructions (20) are designed in particular as R-type instructions, and wherein the embedding of the key parts preferably takes place in Funct7 fields. The method (100) according to one of claims 1 to 3, characterized in that generating (110) the digital key to be provided by the computer system (12) comprises the following steps: Generating (112) a first key containing secret information to be transmitted to the processor unit (14); Reading (114) a hardware identifier, wherein the hardware identifier has a unique identifier of the processor unit (14); and Calculating (116) the digital key to be provided from the first key and the hardware identifier. The method (100) according to claim 4, characterized in that the hardware identifier comprises specific information of a DRAM memory element of the processor unit (14). The method (100) according to claim 4 or 5, characterized in that calculating the digital key to be provided from the first key and the hardware identifier comprises applying an XOR operation to the first key and the hardware identifier. The method (100) according to any one of claims 4 to 6, characterized in that the hardware identifier is embodied as a temperature-dependent hardware identifier.Method (100) according to claim 7, characterized in that the hardware identifier comprises information about the specific charging time of the capacitors of the DRAM memory element or information about the latency times of the DRAM memory element. Method (100) according to one of claims 4 to 8, characterized in that the hardware identifier is determined by a machine learning-based method (100). Method for reconstructing a digital key by a processor unit (14), characterized in that the method comprises the following steps: Receiving an application code from a computer system (12), wherein a sequence of instructions (20) and a digital key are stored in the application code; and wherein the digital Key has at least two key parts that are not stored contiguously in the application code; Assembling the digital key from the at least two key parts. The method according to claim 10, characterized in that the application code is designed as a RISC-V application code, wherein the instructions (20) are designed in particular as R-type instructions, and wherein the embedding (130) of the key parts preferably takes place in Funct7 fields. The method according to claim 10 or 11, characterized in that the method further comprises the following step: Calculating a first key, which contains secret information, from the digital key received from the computer system (12) and a hardware identifier of the processor unit. Method according to one of claims 10 to 12, characterized in that the hardware identifier comprises specific information of a DRAM memory element of the processor unit (14). Method according to one of claims 10 to 13, characterized in that the hardware identifier is designed as a temperature-dependent hardware identifier. Method according to one of claims 10 to 14, characterized in that the hardware identifier comprises information about the specific charging time of the capacitors of the DRAM memory element or information about the latency times of the DRAM memory element.