Asymmetric Cryptographic Device Local Key Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional asymmetric cryptographic systems face high costs and security vulnerabilities due to centralized private key generation, distribution, and storage, which can lead to breaches and compromised security, especially when used in untrustworthy environments.

Innovation Solution

A data processing device with an integrated asymmetric cryptographic circuit generates its own private key locally, establishing a secure boundary within the device to reduce reliance on untrustworthy components and environments, using a random number generator and secure microcode to produce strong keys without user-supplied seeds, thereby minimizing exposure and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If private keys are generated at a central facility and distributed to data processing systems, then key generation can be controlled and monitored, but security vulnerabilities increase and costs increase due to the need to protect the central facility and distribute keys through untrustworthy environments

Engineering Contradiction:
Improvesecurity controlVSAvoidsecurity vulnerabilities
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the private key generation function from the untrustworthy external environment and places it entirely within the trusted boundaries of the data processing system. The random number generator and key generation logic are implemented as integrated circuits that operate autonomously inside the system, eliminating the need to receive private keys from external sources and thereby removing the security vulnerabilities associated with key distribution through untrustworthy environments.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Each data processing system generates its own private keys using its own integrated random number generator and key generation circuitry. The system is self-sufficient in producing cryptographic keys without requiring external intervention or trust in external key distribution infrastructure. This self-service approach eliminates the central facility vulnerability while maintaining security control.

Inventive Principle:
Principle #25Self-service

2Reliability

If strong security measures are implemented to protect private key generation and storage, then security is improved, but costs increase significantly

Engineering Contradiction:
ImprovesecurityVSAvoidcost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent implements security at the circuit level within inexpensive integrated circuits rather than requiring expensive hardware security modules or heavily fortified physical facilities. The security function is embedded in standard semiconductor technology that can be mass-produced at low cost, making strong cryptographic security accessible without the prohibitive costs of traditional high-security key management infrastructure.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Duration of action of stationary object

If private keys are stored within data processing systems for extended periods, then cryptographic operations can be performed continuously, but security boundaries must be maintained which is costly and troublesome

Engineering Contradiction:
Improvekey storage durationVSAvoidsecurity boundary maintenance
Core Design Contradiction:
Duration of action of stationary objectVSDevice complexity

Solution Approach 1:

The patent merges the random number generation, private key generation, and private key storage functions into a single integrated circuit module that resides entirely within the data processing system. This consolidation eliminates the need for complex security boundaries around separate key management infrastructure, as the entire key lifecycle occurs within the trusted boundaries of the system itself, reducing both complexity and cost.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9111122B2Asymmetric cryptographic device with local private key generation and method therefor
Publication Date: 2015.08.18 NXP USA INC
  • US9111122B2 patent drawing
  • US9111122B2 patent drawing
  • US9111122B2 patent drawing

AI summary

An asymmetric cryptographic integrated circuit 20 and a data processing device 10 in which the integrated circuit 20 is used are disclosed. A security boundary 44 is confined to the interior of integrated circuit 20. A random number generator 50 with a hardware entropy source 54 and an arithmetic unit 62 programmed through microcode 38″ to perform a variety of cryptographically useful functions are included within security boundary 44. One of these functions is a primality tester 72. A controller 36 for integrated circuit 20 may cause cryptographically sensitive data, such as large random prime numbers and a clear private key to be generated within the confines of security boundary 44. A symmetric key encryption engine 56 is included within security boundary 44 and used to encrypt the clear private key so that a resulting encrypted private key may be stored outside security boundary 44 in a non-volatile memory 12.