Encryption Engine Secure Mode Key Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing key decryption and derivation processes are vulnerable to exposure through hostile applications or bus snooping, leading to potential unauthorized access to encryption keys and derived application keys.

Innovation Solution

An encryption/decryption engine operates in multiple modes, including secure modes where output is restricted from being forwarded to the bus, with key diversification and localized secure storage ensuring that sensitive keys are not exposed externally, and are accessible only to the engine.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If key decryption and key derivation operations are performed using standard bus-accessible storage, then ease of operation and accessibility are improved, but security against bus snooping and hostile application attacks deteriorates

Engineering Contradiction:
ImproveAccessibility of keysVSAvoidBus snooping exposure
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the storage system into two distinct parts: secure storage (accessible only to the E/D engine) and non-secure storage (accessible via bus). Key materials are stored in the secure storage portion, which is physically or logically separated from the main bus interface, preventing bus snooping while maintaining operational accessibility through controlled interfaces.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary secure storage component that sits between the E/D engine and the external bus system. This intermediary provides controlled access mechanisms, allowing the E/D engine to retrieve key materials when needed while blocking direct bus access to prevent exposure to hostile applications and snooping.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of manufacture

If encrypted key values are stored in external memory accessible via bus, then ease of manufacture and device simplicity are improved, but reliability against key recovery attacks deteriorates

Engineering Contradiction:
ImproveDevice simplicityVSAvoidKey security
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent divides the memory system into secure and non-secure regions. The secure storage portion is implemented with restricted access controls, while the non-secure portion interfaces with the standard bus. This segmentation allows the device to maintain relative simplicity while providing robust key protection through the isolated secure storage architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different security qualities to different parts of the storage system. The secure storage portion implements stringent access controls and protection mechanisms specifically for key materials, while other portions of the system maintain standard accessibility. This localized security approach provides strong key protection without requiring the entire system to be overly complex.

Inventive Principle:
Principle #3Local quality

3Productivity

If E/D engine output is always forwarded to the bus for processing, then productivity and data accessibility are improved, but security against key exposure deteriorates

Engineering Contradiction:
ImproveData processing speedVSAvoidKey exposure risk
Core Design Contradiction:
ProductivityVSObject-generated harmful factors

Solution Approach 1:

The patent implements dynamic output routing in the E/D engine, where the destination of the output signal is determined by the operation type. For key derivation and decryption operations, the output is dynamically routed to the secure storage portion. For other operations, the output can be forwarded to the bus. This dynamic switching maintains high productivity while preventing key exposure.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies different output handling qualities based on the operation being performed. Key-sensitive operations route their outputs to the secure storage portion with restricted access, while non-sensitive operations can forward outputs to the bus for general processing. This localized handling approach ensures security for critical operations without sacrificing overall system productivity.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS8347112B2Encryption/decryption engine with secure modes for key decryption and key derivation
Publication Date: 2013.01.01 TEXAS INSTRUMENTS INC
  • US8347112B2 patent drawing
  • US8347112B2 patent drawing
  • US8347112B2 patent drawing

AI summary

In at least some embodiments, an electronic device comprises a processor and an encryption/decryption (E/D) engine coupled to the processor via a bus. The E/D engine selectively operates in a first mode and a second mode. For the first mode, an E/D engine output is provided to the bus. For the second mode, the E/D engine output is not provided to the bus and is accessible only to the E/D engine.