Entropy Manager Circuit for Immediate Cryptographic Availability
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cryptographic processing systems face delays in acquiring new entropy after power cycling, as the entropy generation process requires time to reinitialize, compromising immediate cryptographic function availability.
Innovation Solution
An entropy manager circuit that extracts, qualifies, and cryptographically secures entropy values from various sources, storing them for future use, ensuring immediate availability even when the entropy manager is offline, by using encryption algorithms and hash functions like HMAC to detect tampering.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Use of energy by moving object
If the entropy manager is turned off to save power, then energy consumption is reduced, but entropy availability is lost requiring time-consuming reinitialization
Solution Approach 1:
The patent applies preliminary action by generating and storing multiple blocks of conditioned entropy in advance while the entropy manager is active. These pre-generated entropy blocks are stored in a buffer or memory, allowing the system to immediately retrieve ready-to-use entropy without reinitializing the entropy source after the entropy manager is turned off. This resolves the contradiction by preparing entropy beforehand so that energy savings from powering down do not result in time-consuming reinitialization delays.
2Speed
If entropy is stored for later use, then immediate availability is improved, but security vulnerability increases during storage
Solution Approach 1:
The patent applies preliminary anti-action by cryptographically securing the entropy blocks through encryption and generating authentication tags (such as HMACs) before storage. This preemptive security measure protects the stored entropy from tampering or unauthorized access, allowing the system to store entropy in advance for immediate availability without compromising security. The cryptographic protections are established beforehand, preventing potential security issues during storage.
3Reliability
If cryptographic verification is performed on stored entropy, then tampering detection is improved, but processing overhead increases
Solution Approach 1:
The patent applies the extraction principle by separating the cryptographic verification process into a distinct authentication stage. The authentication tag (such as HMAC) is computed and stored separately from the encrypted entropy block. During verification, only the authentication tag needs to be validated against a freshly computed tag, rather than reprocessing the entire entropy block. This extraction of the verification step reduces processing overhead while maintaining reliable tampering detection.
Data Source
AI summary
Apparatus and method for managing entropy in a cryptographic processing system. In some embodiments, a first block of conditioned entropy is generated from at least one entropy source. The first block of conditioned entropy is subjected to a first cryptographic process to generate cryptographically secured entropy which is stored in a memory. The cryptographically secured entropy is subsequently retrieved from the memory and subjected to a second cryptographic process to generate a second block of conditioned entropy, which is thereafter used as an input in a third cryptographic process such as to encrypt or decrypt user data in a data storage device. The first cryptographic process may include an encryption algorithm to generate ciphertext and a hash function to generate a keyed digest value, such as an HMAC value, to detect tampering with the ciphertext by an attacker. The second cryptographic process may decrypt or further encrypt the ciphertext.


