Cryptographic Key Registers With Tamper-Resistant Access Attributes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern computing devices face security breaches through malicious software that subverts security measures, leading to issues like identity theft and data compromise, necessitating improved cryptographic key management systems.

Innovation Solution

A cryptographic key management system with an access and tamper-resistant circuit block that stores cryptographic keys and attributes, preventing key exposure and modification, allowing only authorized operations through a limited hardware interface.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If cryptographic keys are stored in traditional software-based key management systems, then key accessibility and operational flexibility are improved, but security against malicious software and intentional breaches deteriorates

Engineering Contradiction:
Improvekey accessibilityVSAvoidsecurity against malicious software
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a hardware-based access and tamper resistant circuit block as an intermediary between software applications and cryptographic keys. This hardware module acts as a mediator that enforces security policies and prevents malicious software from accessing or modifying keys, while still allowing authorized cryptographic operations to proceed.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces software-based key management mechanisms with a hardware-based cryptographic module. This substitution moves critical security functions from the software realm (vulnerable to malware) to the hardware realm (physically protected and harder to compromise), thereby improving security while maintaining operational capability through standardized hardware interfaces.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If cryptographic keys are made accessible to multiple software components, then system versatility and functionality are improved, but risk of unauthorized access and key exposure increases

Engineering Contradiction:
Improvekey usage flexibilityVSAvoidunauthorized access risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the key management system into distinct functional components: a hardware-protected storage area for keys, an access control module with attribute indicators, and a cryptographic processing unit. This segmentation isolates keys from direct software access while maintaining controlled functionality through defined interfaces and access policies.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different access qualities to different keys based on their attribute indicators. Each key can have customized access control properties (e.g., which software components can read/write, key derivation permissions), allowing fine-grained control that balances versatility with security on a per-key basis.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If attribute indicators are stored separately from cryptographic keys, then key management flexibility and attribute customization are improved, but system complexity and data management burden increase

Engineering Contradiction:
Improveattribute customizationVSAvoidkey management structure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges the cryptographic key and its associated attribute indicators into a unified data structure stored together in the hardware module. This combination eliminates the complexity of managing separate key and attribute storage, while still allowing flexible attribute customization. The merged structure is processed as a single unit by the cryptographic module.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal key management structure where the same hardware module handles multiple functions: storing keys, managing attributes, controlling access, and performing cryptographic operations. This multi-functional design reduces overall system complexity by consolidating what would otherwise require separate systems into a single integrated solution.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3732609B1Secure crypto system attributes
Publication Date: 2025.08.27 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3732609B1 patent drawingFigure 1
  • EP3732609B1 patent drawingFigure 2A
  • EP3732609B1 patent drawingFigure 2B

AI summary

Disclosed is a cryptographic key management system implemented in access and tamper resistant circuitry. The circuitry includes processing circuitry to perform cryptographic processing based cryptographic keys. Cryptographic key registers include key portions and attribute portions. An interface receives commands from exposed circuitry that controls the processing circuitry to perform cryptographic processing based on the keys and associated attributes. The attributes indicate what operations may be performed on, or using, the associated keys. of the associated keys. The attributes indicate intended uses of the keys.