Hardware Cryptographic Engine Access Control for Secure Computing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cryptographic operations in computing devices are inefficient and prone to security risks due to software-based implementations, which fail to meet performance needs and are vulnerable to physical and malicious attacks.

Innovation Solution

A security architecture system incorporating a hardware cryptographic engine controlled via an access interface by subsystems with varying access authorities, including a REE, TEE, and SE, ensuring secure cryptographic operations by isolating sensitive resources and using asymmetric, symmetric, and hash algorithms, along with true random number generation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If cryptographic operations are implemented using common operation instructions in software, then the implementation is flexible and easy to deploy, but the cryptographic operation performance is low and security risks are high

Engineering Contradiction:
Improvecryptographic operation performanceVSAvoidsecurity risk
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent replaces software-based cryptographic operations with a hardware cryptographic engine. The processor includes a dedicated hardware module that performs cryptographic operations (encryption, decryption, hashing) through specialized circuitry rather than software instructions, thereby improving both performance and security against physical and malicious attacks

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a controller as an intermediary that manages access to the hardware cryptographic engine. The controller receives cryptographic operation requests from subsystems, verifies access authority, and controls the hardware engine to perform operations, thereby resolving the contradiction between providing hardware acceleration and maintaining security control

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If a hardware cryptographic engine is introduced to improve performance, then cryptographic operation speed increases, but system complexity increases

Engineering Contradiction:
Improvecryptographic operation performanceVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The hardware cryptographic engine is designed to perform multiple cryptographic functions (symmetric encryption, asymmetric encryption, hashing, random number generation) within a single integrated module. This multi-functionality reduces system complexity compared to having separate hardware components for each cryptographic operation type

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The controller serves as an intermediary that abstracts the complexity of hardware cryptographic engine management from subsystems. It handles access control, operation scheduling, and resource allocation, thereby simplifying the interface while enabling hardware acceleration

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If access authority is granted to multiple subsystems for the hardware cryptographic engine, then system versatility improves, but security control becomes more difficult

Engineering Contradiction:
Improvesubsystem access capabilityVSAvoidsecurity control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements differential access control where different subsystems (REE, TEE, SE) have different levels of access authority to the hardware cryptographic engine based on their security requirements. The controller verifies access authority for each subsystem and controls the hardware engine accordingly, allowing versatile access while maintaining security through localized access policies

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12591693B2Security architecture system, cryptographic operation method for security architecture system, and computing device
Publication Date: 2026.03.31 PHYTIUM TECH CO LTD
  • US12591693B2 patent drawing
  • US12591693B2 patent drawing
  • US12591693B2 patent drawing

AI summary

A security architecture system includes one or more subsystems, a hardware cryptographic engine, and a controller. At least one of the one or more subsystems has access authority to the hardware cryptographic engine; and the controller is configured to instruct a subsystem having access authority to access the hardware cryptographic engine via an access interface to control the hardware cryptographic engine to perform a cryptographic operation.