Cryptography Module With CMAC Memory Checks for Program Integrity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cryptographic hardware modules lack the capability to efficiently check and control the execution of memory contents to prevent unsecure or compromised computer programs from being executed, potentially compromising cryptographic operations.
Innovation Solution
A cryptography module that temporarily controls a computing device's operation by checking memory areas using a key-based message authentication code (CMAC) and comparing the results with reference values, holding the device in a reset state until the check is complete, and selectively providing cryptographic keys based on the check results.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a cryptography module checks memory areas using CMAC to prevent execution of compromised programs, then security is improved, but device complexity increases
Solution Approach 1:
The patent embeds a cryptography module within the computing device that contains an integrated memory unit storing reference values. This nested structure allows the cryptography module to access and verify memory areas of the computing device without requiring external verification systems, thereby improving security while managing complexity through integration.
Solution Approach 2:
The patent implements verification of memory areas before the computing device executes any programs. The cryptography module performs CMAC checks on memory contents in advance, holding the device in a reset state until verification is complete. This preliminary action ensures security is established before operation begins, preventing execution of compromised programs.
2Reliability
If the cryptography module holds the computing device in reset state until check is complete, then security is improved, but execution speed decreases
Solution Approach 1:
The verification process is performed during system initialization before the computing device begins normal operation. By completing the security check in advance and holding the device in reset state only temporarily during boot-up, the patent ensures security without significantly impacting subsequent execution speed during normal operation.
3Reliability
If the cryptography module provides cryptographic keys selectively based on check results, then security is improved, but ease of operation decreases
Solution Approach 1:
The cryptography module automatically provides cryptographic keys to the computing device based on the results of CMAC verification. If the memory check succeeds, keys are made available; if it fails, keys are withheld. This automated feedback mechanism maintains security while requiring minimal manual intervention, balancing security with ease of operation.
Data Source
AI summary
A cryptography module for at least temporarily controlling an operation of at least one computing device. The cryptography module is designed to check at least one memory area of a memory unit capable of being accessed by the computing device, and to control the operation of the at least one computing device as a function of the check.


