Finite State Machine Secure Key Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing security measures for non-volatile fuse-type memory in integrated circuits are vulnerable to attacks, as the generation and storage of cipher keys are controlled by a non-secure processor, potentially allowing unauthorized access.
Innovation Solution
A finite state machine coupled to a random number generator via a dedicated bus stores a random value in a non-volatile memory area accessible only by the finite state machine, ensuring the cipher key is securely generated and stored, and only accessible to a cryptographic processor, with additional volatile storage elements for secure key loading and scan test protection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a non-secure processor controls the generation and storage of cipher keys in non-volatile memory, then the device can be manufactured and operated with standard processing components, but the security of the cipher keys is compromised and they become accessible to potential attackers
Solution Approach 1:
The patent segments the system into distinct components: a secure dedicated state machine for key management, a non-secure processor for general operations, and separated memory access paths. The cipher key is stored in non-volatile memory that is segmented into accessible and non-accessible portions, with only the dedicated state machine able to access the key portion, thus isolating the security-critical functions from the non-secure processor.
Solution Approach 2:
The patent introduces a dedicated state machine as an intermediary between the random number generator and the non-volatile memory. This intermediary component exclusively controls the generation and storage of cipher keys, acting as a mediator that prevents direct access by the non-secure processor while enabling secure key management functions.
2Ease of operation
If the non-volatile memory containing cipher keys is accessible by a non-secure processor, then the processor can manage cryptographic operations, but physical connections could be exploited by attackers to access the keys
Solution Approach 1:
The memory is segmented into distinct access zones: a first portion accessible by both the dedicated state machine and non-secure processor, and a second portion containing the cipher key accessible only by the dedicated state machine. This segmentation allows the non-secure processor to perform cryptographic operations without exposing the actual key material to physical attacks.
Solution Approach 2:
The patent extracts the cipher key management functions from the non-secure processor and places them in a dedicated secure state machine. The key itself is extracted from general memory access and placed in a protected memory portion with restricted access, separating the sensitive key material from the non-secure processing environment.
3Reliability
If a dedicated bus couples the state machine to the random number generator, then secure key generation is achieved, but the device complexity increases due to additional dedicated connections
Solution Approach 1:
The dedicated state machine acts as an intermediary that requires a dedicated bus connection to the random number generator. This intermediary architecture ensures that only the secure state machine can access the random number generator for key generation purposes, creating a isolated secure channel that justifies the additional dedicated connection infrastructure.
Data Source
AI summary
The present disclosure relates to a method wherein a random value, generated by a random number generator, is stored, by a finite state machine coupled to the generator by a first dedicated bus, in a memory area of a non-volatile fuse-type memory of an integrated circuit, the memory area being only accessible by the finite state machine.


