Finite State Machine Secure Key Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing security measures for non-volatile fuse-type memory in integrated circuits are vulnerable to attacks, as the generation and storage of cipher keys are controlled by a non-secure processor, potentially allowing unauthorized access.

Innovation Solution

A finite state machine coupled to a random number generator via a dedicated bus stores a random value in a non-volatile memory area accessible only by the finite state machine, ensuring the cipher key is securely generated and stored, and only accessible to a cryptographic processor, with additional volatile storage elements for secure key loading and scan test protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a non-secure processor controls the generation and storage of cipher keys in non-volatile memory, then the device can be manufactured and operated with standard processing components, but the security of the cipher keys is compromised and they become accessible to potential attackers

Engineering Contradiction:
Improvesecurity of cipher keysVSAvoidaccess control structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the system into distinct components: a secure dedicated state machine for key management, a non-secure processor for general operations, and separated memory access paths. The cipher key is stored in non-volatile memory that is segmented into accessible and non-accessible portions, with only the dedicated state machine able to access the key portion, thus isolating the security-critical functions from the non-secure processor.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a dedicated state machine as an intermediary between the random number generator and the non-volatile memory. This intermediary component exclusively controls the generation and storage of cipher keys, acting as a mediator that prevents direct access by the non-secure processor while enabling secure key management functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If the non-volatile memory containing cipher keys is accessible by a non-secure processor, then the processor can manage cryptographic operations, but physical connections could be exploited by attackers to access the keys

Engineering Contradiction:
Improveprocessor access to keysVSAvoidphysical attacks on circuit
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The memory is segmented into distinct access zones: a first portion accessible by both the dedicated state machine and non-secure processor, and a second portion containing the cipher key accessible only by the dedicated state machine. This segmentation allows the non-secure processor to perform cryptographic operations without exposing the actual key material to physical attacks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts the cipher key management functions from the non-secure processor and places them in a dedicated secure state machine. The key itself is extracted from general memory access and placed in a protected memory portion with restricted access, separating the sensitive key material from the non-secure processing environment.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If a dedicated bus couples the state machine to the random number generator, then secure key generation is achieved, but the device complexity increases due to additional dedicated connections

Engineering Contradiction:
Improvesecure key generationVSAvoiddedicated bus structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The dedicated state machine acts as an intermediary that requires a dedicated bus connection to the random number generator. This intermediary architecture ensures that only the secure state machine can access the random number generator for key generation purposes, creating a isolated secure channel that justifies the additional dedicated connection infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12135799B2Hardware storage unique key
Publication Date: 2024.11.05 STMICROELECTRONICS (GRENOBLE 2) SAS
  • US12135799B2 patent drawing
  • US12135799B2 patent drawing
  • US12135799B2 patent drawing

AI summary

The present disclosure relates to a method wherein a random value, generated by a random number generator, is stored, by a finite state machine coupled to the generator by a first dedicated bus, in a memory area of a non-volatile fuse-type memory of an integrated circuit, the memory area being only accessible by the finite state machine.