Cryptographic Key Revocation Using AES-GCM Tags and Encrypted Bits

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional cryptographic key revocation methods relying on programmable electronic fuses are economically costly, limiting the number of revocable cryptographic keys in a device.

Innovation Solution

Utilizing AES-GCM encryption/decryption circuitry to encrypt user keys, metadata, and revocation bits, along with a random number generator to generate symmetric keys, allowing for nearly unlimited revocation of cryptographic keys by checking GCM tags and usage limits, without relying on electronic fuses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If electronic fuses are used for key revocation, then key revocation is achieved, but the number of revocable keys is limited due to high cost

Engineering Contradiction:
Improvekey revocation capabilityVSAvoidnumber of revocable keys
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent replaces the physical electronic fuse with a virtual copy mechanism using encrypted revocation bits stored in reconfigurable memory. Instead of using expensive physical fuse bits, the system creates a software-based revocation mechanism where revocation status is stored as encrypted data that can be freely updated without physical constraints, allowing unlimited key revocations.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent substitutes the mechanical/physical electronic fuse system with a cryptographic software-based system. The physical electronic fuse that physically melts or changes state is replaced by encrypted revocation bits in reconfigurable memory, controlled through cryptographic operations (encryption/decryption) rather than physical manipulation, enabling unlimited revocations without additional hardware cost.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If electronic fuses are used for key revocation, then key revocation is achieved, but economic cost increases

Engineering Contradiction:
Improvekey revocation capabilityVSAvoidmanufacturing cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent replaces the physical electronic fuse with a virtual copy mechanism using encrypted revocation bits stored in reconfigurable memory. Instead of using expensive physical fuse bits, the system creates a software-based revocation mechanism where revocation status is stored as encrypted data that can be freely updated without physical constraints, allowing unlimited key revocations.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent substitutes the mechanical/physical electronic fuse system with a cryptographic software-based system. The physical electronic fuse that physically melts or changes state is replaced by encrypted revocation bits in reconfigurable memory, controlled through cryptographic operations (encryption/decryption) rather than physical manipulation, enabling unlimited revocations without additional hardware cost.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Quantity of substance

If revocation bits are added to electronic fuse, then more keys can be revoked, but device complexity increases

Engineering Contradiction:
Improvenumber of revocable keysVSAvoiddevice structure
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent makes the reconfigurable memory serve multiple functions: it stores encrypted cryptographic keys, encrypted metadata, encrypted revocation bits, and usage counters all in the same storage medium. This eliminates the need for separate physical structures for each function, reducing overall device complexity while enabling unlimited key management operations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent replaces the physical electronic fuse with a virtual copy mechanism using encrypted revocation bits stored in reconfigurable memory. Instead of using expensive physical fuse bits, the system creates a software-based revocation mechanism where revocation status is stored as encrypted data that can be freely updated without physical constraints, allowing unlimited key revocations.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS20260031977A1Revocable cryptographic keys
Publication Date: 2026.01.29 XILINX INC
  • US20260031977A1 patent drawing
  • US20260031977A1 patent drawing
  • US20260031977A1 patent drawing

AI summary

Examples herein describe revocable cryptographic keys. An integrated circuit includes an input/output interface configured to receive inputs including plaintext user keys, metadata, and revocation bits. Cryptographic circuitry is configured to read a key from a first memory. Plaintext user keys are encrypted based on the key to provide encrypted user keys. Metadata is encrypted based on the key to provide encrypted metadata. Revocation bits are encrypted based on the key to provide encrypted revocation bits. A Galois/Counter Mode (GCM) tag is computed based on the key. A processor is configured to write the encrypted user keys, the encrypted metadata, the encrypted revocation bits, and the GCM tag to a second memory to provision the plaintext user keys.