Asymmetric Cryptographic Device Local Key Generation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional asymmetric cryptographic systems face high costs and security vulnerabilities due to centralized private key generation, distribution, and storage, which can lead to breaches and compromised security, especially when used in untrustworthy environments.
Innovation Solution
A data processing device with an integrated asymmetric cryptographic circuit generates its own private key locally, establishing a secure boundary within the device to reduce reliance on untrustworthy components and environments, using a random number generator and secure microcode to produce strong keys without user-supplied seeds, thereby minimizing exposure and enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If private keys are generated at a central facility and distributed to data processing systems, then key generation can be controlled and monitored, but security vulnerabilities increase and costs increase due to the need to protect the central facility and distribute keys through untrustworthy environments
Solution Approach 1:
The patent extracts the private key generation function from the untrustworthy external environment and places it entirely within the trusted boundaries of the data processing system. The random number generator and key generation logic are implemented as integrated circuits that operate autonomously inside the system, eliminating the need to receive private keys from external sources and thereby removing the security vulnerabilities associated with key distribution through untrustworthy environments.
Solution Approach 2:
Each data processing system generates its own private keys using its own integrated random number generator and key generation circuitry. The system is self-sufficient in producing cryptographic keys without requiring external intervention or trust in external key distribution infrastructure. This self-service approach eliminates the central facility vulnerability while maintaining security control.
2Reliability
If strong security measures are implemented to protect private key generation and storage, then security is improved, but costs increase significantly
Solution Approach 1:
The patent implements security at the circuit level within inexpensive integrated circuits rather than requiring expensive hardware security modules or heavily fortified physical facilities. The security function is embedded in standard semiconductor technology that can be mass-produced at low cost, making strong cryptographic security accessible without the prohibitive costs of traditional high-security key management infrastructure.
3Duration of action of stationary object
If private keys are stored within data processing systems for extended periods, then cryptographic operations can be performed continuously, but security boundaries must be maintained which is costly and troublesome
Solution Approach 1:
The patent merges the random number generation, private key generation, and private key storage functions into a single integrated circuit module that resides entirely within the data processing system. This consolidation eliminates the need for complex security boundaries around separate key management infrastructure, as the entire key lifecycle occurs within the trusted boundaries of the system itself, reducing both complexity and cost.
Data Source
AI summary
An asymmetric cryptographic integrated circuit 20 and a data processing device 10 in which the integrated circuit 20 is used are disclosed. A security boundary 44 is confined to the interior of integrated circuit 20. A random number generator 50 with a hardware entropy source 54 and an arithmetic unit 62 programmed through microcode 38″ to perform a variety of cryptographically useful functions are included within security boundary 44. One of these functions is a primality tester 72. A controller 36 for integrated circuit 20 may cause cryptographically sensitive data, such as large random prime numbers and a clear private key to be generated within the confines of security boundary 44. A symmetric key encryption engine 56 is included within security boundary 44 and used to encrypt the clear private key so that a resulting encrypted private key may be stored outside security boundary 44 in a non-volatile memory 12.


