Hardware Anti-Tamper Device for Secure Key Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing application management systems are vulnerable to tampering due to lack of robust security, particularly in enterprise environments, where software-only anti-tamper solutions expose decryption keys and rely on operating system security, leading to potential key exfiltration and incompatibility issues with existing systems.

Innovation Solution

An anti-tamper hardware security device that communicates with a host machine, featuring a host interface, key manager, whitelist manager, and controller to validate applications, manage cryptographic keys, and provide secure decryption and execution, while being physically isolated to prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If software-only anti-tamper solutions are used, then ease of operation is improved, but security reliability deteriorates due to key exfiltration risks

Engineering Contradiction:
Improveease of operationVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system separates cryptographic key management from the host system by implementing a dedicated key manager component. This segmentation ensures that keys are managed in an isolated environment, preventing key exfiltration while maintaining ease of operation through centralized key management.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A hardware security module acts as an intermediary between the host system and cryptographic operations. This intermediary securely handles key storage and cryptographic operations, providing security reliability while allowing the host system to operate easily without direct key exposure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If cryptographic keys are exposed in memory, then ease of operation is improved, but security reliability deteriorates due to vulnerability to attacks

Engineering Contradiction:
Improveease of operationVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts cryptographic keys from the host system memory and stores them in a secure, isolated key manager. This extraction prevents keys from being exposed in host memory, eliminating the vulnerability to attacks while maintaining ease of operation through automated key management.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system uses ephemeral memory allocations for cryptographic operations that are immediately cleared after use. This approach allows easy operation with temporary key usage while preventing persistent key exposure that could lead to security breaches.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Reliability

If physical isolation of cryptographic keys is implemented, then security reliability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines the key manager, whitelist manager, and application validation functions into a single integrated security device. This merging provides physical isolation for security operations (improving reliability) while presenting a unified interface that minimizes perceived complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The security device performs multiple functions including key management, application validation, and cryptographic operations within a single physically isolated unit. This multi-functionality improves security reliability while reducing the number of separate components needed.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8843739B2Anti-tamper device, system, method, and computer-readable medium
Publication Date: 2014.09.23 LOCKHEED MARTIN CORP
  • US8843739B2 patent drawing
  • US8843739B2 patent drawing
  • US8843739B2 patent drawing

AI summary

An anti-tamper hardware security device that communicates with a host machine, including a host interface coupled to the host machine and configured to receive an access request from the host machine, the access request being associated with an application; a key manager configured to manage cryptographic keys; a whitelist manager configured to manage application validation information; and a controller configured to receive the access request from the host interface, validate the application using the application validation information, retrieve a cryptographic key associated with the application, and transmit a response to the host machine through the host interface if the controller determines that the application is valid.