Cryptography Module With CMAC Memory Checks for Program Integrity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cryptographic hardware modules lack the capability to efficiently check and control the execution of memory contents to prevent unsecure or compromised computer programs from being executed, potentially compromising cryptographic operations.

Innovation Solution

A cryptography module that temporarily controls a computing device's operation by checking memory areas using a key-based message authentication code (CMAC) and comparing the results with reference values, holding the device in a reset state until the check is complete, and selectively providing cryptographic keys based on the check results.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a cryptography module checks memory areas using CMAC to prevent execution of compromised programs, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent embeds a cryptography module within the computing device that contains an integrated memory unit storing reference values. This nested structure allows the cryptography module to access and verify memory areas of the computing device without requiring external verification systems, thereby improving security while managing complexity through integration.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent implements verification of memory areas before the computing device executes any programs. The cryptography module performs CMAC checks on memory contents in advance, holding the device in a reset state until verification is complete. This preliminary action ensures security is established before operation begins, preventing execution of compromised programs.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the cryptography module holds the computing device in reset state until check is complete, then security is improved, but execution speed decreases

Engineering Contradiction:
ImprovesecurityVSAvoidexecution speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The verification process is performed during system initialization before the computing device begins normal operation. By completing the security check in advance and holding the device in reset state only temporarily during boot-up, the patent ensures security without significantly impacting subsequent execution speed during normal operation.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If the cryptography module provides cryptographic keys selectively based on check results, then security is improved, but ease of operation decreases

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The cryptography module automatically provides cryptographic keys to the computing device based on the results of CMAC verification. If the memory check succeeds, keys are made available; if it fails, keys are withheld. This automated feedback mechanism maintains security while requiring minimal manual intervention, balancing security with ease of operation.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12430448B2Cryptography module for controlling device
Publication Date: 2025.09.30 ROBERT BOSCH GMBH
  • US12430448B2 patent drawing
  • US12430448B2 patent drawing
  • US12430448B2 patent drawing

AI summary

A cryptography module for at least temporarily controlling an operation of at least one computing device. The cryptography module is designed to check at least one memory area of a memory unit capable of being accessed by the computing device, and to control the operation of the at least one computing device as a function of the check.