Encryption system with an application-specific
integrated circuit (ASIC) which has a permanent memory for the non-volatile storage of the
operating system (OS) of a processor and
software modules for encrypting the
data memory of the processor and which has a hardware-implemented
encryption algorithm, characterized in that a security module (SM) is integrated in the ASIC for autonomous
booting of the
operating system (OS), consisting of: - a symmetric
cryptosystem (SK) for
processing symmetric keys, - an asymmetric
cryptosystem (AK) for the use of public and private keys, - a module for generating cryptographic hash functions (KH), - a module for the secure exchange of keys using hardware-implemented
key exchange protocols (SP), - a
key storage (SS) for the secure storage of root keys (WS), which are protected by appropriate measures in the physical structures of the ASIC and - a
key management system (SMS) for the secure introduction of authenticated-encrypted key packets, and that the security module (SM) communicates with a
central processing unit (CPU) via a
communication interface (CS1), and that the
central processing unit (CPU) communicates with at least one internal storage (IS) and one
external storage (ES), as well as with at least one internal persistent storage (IP) and one external persistent storage (EP), such that the
operating system (OS) is loaded by a second-stage bootloader (SSB) stored in the external persistent storage (EP), and then the operating
system (OS) loads the applications, the second-stage bootloader (SSB) itself being decrypted and loaded by a first-stage bootloader (FSB) stored in the internal persistent storage (IP), and a public key (PUBOS) to verify the operating system (OS).and a symmetric key (KOS) to decrypt the operating system (OS), and that the contents of the
internal memory (IS) and the external memory (ES) are decrypted by the security module (SM) during read accesses by the
central management unit (CMU) or other modules integrated on the ASIC, and re-encrypted during write accesses by the same.