Cryptographic Device Memory Clearing via Capacitor Backup
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cryptographic devices, such as Postal Security Devices, face security breaches when external power is disrupted, allowing attackers to obtain cryptographic keys by preventing memory clearing, especially when battery power is shorted or memory discharge is slowed by cold temperatures, enabling the generation of counterfeit digital signatures or MACs.
Innovation Solution
A cryptographic device with a tamper detection circuit, low battery detection circuit, volatile memory, and a capacitor within a physical security boundary, where the capacitor stores charge to enable active memory clearing even without external power, using a latch to trigger clearing and a discharge prevention mechanism to maintain power integrity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cryptographic keys are stored in volatile memory to prevent permanent storage, then security is improved, but memory contents can be lost when power is removed which requires uninterrupted power supply
Solution Approach 1:
The patent implements preliminary action by detecting tamper events or low battery conditions before they can compromise security, and proactively clearing memory contents in advance. The system monitors battery voltage and tamper signals continuously, and when thresholds are breached, it executes memory clearing before the attacker can extract keys, preventing the security breach before it occurs.
2Reliability
If tamper detection triggers immediate memory clearing, then security is improved, but memory clearing cannot occur when external power is disrupted or battery is shorted
Solution Approach 1:
The patent applies beforehand cushioning by implementing protective circuitry including voltage detection circuits and alternative power sources that cushion against power disruption attacks. When external power is removed or battery shorted, the voltage detection circuit identifies the anomaly and activates alternative power sources to maintain memory clearing capability, protecting against the harmful effect of power disruption.
Solution Approach 2:
The patent uses intermediary elements including voltage detection circuits and alternative power sources that mediate between the external power source and the memory clearing function. These intermediaries detect power anomalies and provide backup power, allowing the memory clearing operation to proceed even when external power is disrupted, thus maintaining security despite power attacks.
3Duration of action of stationary object
If memory discharge is slowed by cold temperatures to extend operational life, then device longevity is improved, but attackers can obtain cryptographic keys before memory fully discharges
Solution Approach 1:
The patent implements preliminary anti-action by detecting tamper events or low battery conditions and proactively clearing memory contents before an attacker can extract cryptographic keys. This preemptive clearing occurs regardless of memory discharge rate, counteracting the harmful effect of extended memory retention that would otherwise allow key extraction during cold temperature operation.
4Duration of action of moving object
If cryptographic device uses external battery for power, then operational continuity is improved, but battery shorting prevents memory clearing operation
Solution Approach 1:
The patent introduces intermediary voltage detection circuits and alternative power sources between the external battery and the memory clearing function. These intermediaries detect battery shorting conditions and activate alternative power sources, allowing the memory clearing operation to proceed even when the external battery is shorted, thus maintaining security while preserving operational continuity.
Solution Approach 2:
The patent changes the power source parameter dynamically based on operating conditions. When the external battery is shorted or voltage drops below thresholds, the system switches to alternative power sources, changing the power supply parameter to maintain the memory clearing capability and prevent security breaches.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
Ensures immediate and secure clearing of memory contents upon tamper detection or low battery condition, preventing key extraction, thus maintaining confidentiality and preventing counterfeiting, even when external power is removed or disrupted.
Implementation Method 1
a capacitor, located within the physical security boundary, having a first node coupled to the power input of the memory device and a second node coupled to ground, the capacitor storing charge from the battery under normal operating conditions
Implementation Method 2
the capacitor, when the battery is shorted, providing the stored charge to the memory device, thereby allowing the memory device to use the stored charge to perform an active clearing operation
Data Source
Figure 1
Figure 2
AI summary
A cryptographic device (20) that will actively clear its memory even in the absence of external power when a security breach is detected is provided. The memory cell clusters (42a,42b,42c) of the cryptographic device are provided with an internal power source (62) that provides sufficient energy for the memory cell clusters to perform a clearing operation. If the external power source (60) for the memory is removed and a physical security breach is detected, the power from the internal power source (62) will allow the memory cells (42a,42b,42c) to actively clear their contents, thereby rendering any attempt to obtain the contents of the memory cells fruitless.