Hardware Cryptographic Engine Access Control for Secure Computing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cryptographic operations in computing devices are inefficient and prone to security risks due to software-based implementations, which fail to meet performance needs and are vulnerable to physical and malicious attacks.
Innovation Solution
A security architecture system incorporating a hardware cryptographic engine controlled via an access interface by subsystems with varying access authorities, including a REE, TEE, and SE, ensuring secure cryptographic operations by isolating sensitive resources and using asymmetric, symmetric, and hash algorithms, along with true random number generation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If cryptographic operations are implemented using common operation instructions in software, then the implementation is flexible and easy to deploy, but the cryptographic operation performance is low and security risks are high
Solution Approach 1:
The patent replaces software-based cryptographic operations with a hardware cryptographic engine. The processor includes a dedicated hardware module that performs cryptographic operations (encryption, decryption, hashing) through specialized circuitry rather than software instructions, thereby improving both performance and security against physical and malicious attacks
Solution Approach 2:
The patent introduces a controller as an intermediary that manages access to the hardware cryptographic engine. The controller receives cryptographic operation requests from subsystems, verifies access authority, and controls the hardware engine to perform operations, thereby resolving the contradiction between providing hardware acceleration and maintaining security control
2Productivity
If a hardware cryptographic engine is introduced to improve performance, then cryptographic operation speed increases, but system complexity increases
Solution Approach 1:
The hardware cryptographic engine is designed to perform multiple cryptographic functions (symmetric encryption, asymmetric encryption, hashing, random number generation) within a single integrated module. This multi-functionality reduces system complexity compared to having separate hardware components for each cryptographic operation type
Solution Approach 2:
The controller serves as an intermediary that abstracts the complexity of hardware cryptographic engine management from subsystems. It handles access control, operation scheduling, and resource allocation, thereby simplifying the interface while enabling hardware acceleration
3Adaptability or versatility
If access authority is granted to multiple subsystems for the hardware cryptographic engine, then system versatility improves, but security control becomes more difficult
Solution Approach 1:
The patent implements differential access control where different subsystems (REE, TEE, SE) have different levels of access authority to the hardware cryptographic engine based on their security requirements. The controller verifies access authority for each subsystem and controls the hardware engine accordingly, allowing versatile access while maintaining security through localized access policies
Data Source
AI summary
A security architecture system includes one or more subsystems, a hardware cryptographic engine, and a controller. At least one of the one or more subsystems has access authority to the hardware cryptographic engine; and the controller is configured to instruct a subsystem having access authority to access the hardware cryptographic engine via an access interface to control the hardware cryptographic engine to perform a cryptographic operation.


