Cryptographic Processor for Encrypted Binary Execution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The authenticity of software in computer devices is difficult to verify, and reverse engineering of binary images exposes vulnerabilities, making systems susceptible to exploitation and counterfeiting, which existing security measures fail to adequately address without compromising system performance.

Innovation Solution

A cryptographic processor system that embeds multiple cryptographic key elements within an integrated circuit, enabling decryption, verification, and re-encryption of binary images, using symmetric and asymmetric encryption methods to authenticate and protect software from modification and reverse engineering, with embedded cryptographic processing engines and memory elements ensuring secure execution.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing security measures are implemented to verify software authenticity and prevent reverse engineering, then security is improved, but system performance is compromised

Engineering Contradiction:
Improvesoftware authenticity verificationVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by encrypting the binary image before execution and verifying its authenticity in advance. The cryptographic processor decrypts and validates the encrypted binary image prior to execution, ensuring security measures are already in place before the system operates, thus avoiding performance penalties during runtime operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts the cryptographic processing functions into a dedicated cryptographic processor separate from the main processor. This extraction allows security-critical operations (encryption, decryption, verification) to be handled by specialized hardware, preventing these security operations from interfering with the main system's performance while maintaining strong security guarantees.

Inventive Principle:
Principle #2Taking out (Extraction)

2Object-affected harmful factors

If binary images are protected from reverse engineering through encryption, then security against exploitation is improved, but ease of operation and system complexity increase

Engineering Contradiction:
Improvereverse engineering vulnerabilityVSAvoidcryptographic processing system
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent merges multiple security functions (encryption, decryption, authenticity verification, and protected execution) into a single integrated cryptographic processor. This consolidation reduces overall system complexity compared to implementing separate security modules, while still providing comprehensive protection against reverse engineering and exploitation through the unified security architecture.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8774407B2System and method for executing encrypted binaries in a cryptographic processor
Publication Date: 2014.07.08 CISCO TECHNOLOGY INC
  • US8774407B2 patent drawing
  • US8774407B2 patent drawing
  • US8774407B2 patent drawing

AI summary

An example method is provided and includes providing an encrypted image to a central processing unit of an integrated circuit and decrypting the encrypted image using a cryptographic key element. The cryptographic key element is embedded within the integrated circuit. The method also includes evaluating the decrypted image in order to verify its authenticity, and executing the decrypted image if the decrypted image is successfully verified. In more particular embodiments, the verification includes utilizing an executable and linkable format (ELF) to signify that encryption has been enabled for at least a portion of the encrypted image. A processor within the integrated circuit can be provided with the cryptographic key element that corresponds to a product family of devices. The method can also include providing a corresponding image of the decrypted image to an external memory of the integrated circuit.