Hardware Security Component for Encrypted Code Execution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional code protection technologies are insufficient in deterring determined adversaries, as they can be susceptible to attacks that exploit decryption keys, especially in software-based systems and require robust hardware that is difficult to maintain.
Innovation Solution
A hardware-based security processing component and architecture that uses online authentication and encrypted code execution, where a security processing component decrypts and executes encrypted application code, utilizing a stored encryption key to provide multileveled protection against unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If software based CP technologies are used, then ease of operation is improved, but security reliability deteriorates because decryption keys can be extracted and content can be decrypted and copied
Solution Approach 1:
The patent replaces software-based code protection with a dedicated hardware security processing component that performs decryption and code execution. This hardware component includes a secure key storage unit and execution unit that are physically isolated from the main software system, preventing software-based attacks while maintaining operational ease through automated secure execution.
Solution Approach 2:
The security processing component is divided into distinct functional modules: a key storage unit that securely holds decryption keys, a decryption unit that processes encrypted code, and an execution unit that runs decrypted code. This segmentation isolates security-critical functions from the rest of the system, preventing key extraction while maintaining operational efficiency.
2Reliability
If hardware based CP technologies are used, then security reliability is improved, but device complexity increases and manufacturing difficulty increases
Solution Approach 1:
The security processing component is designed as a universal module that can be integrated into various existing hardware platforms. It provides multiple functions including key storage, decryption, and code execution within a single integrated component, reducing overall system complexity while maintaining high security reliability. The component can work with different encryption schemes and application types.
Solution Approach 2:
The security processing component is implemented as a nested structure where the key storage unit is embedded within the execution unit, which is in turn integrated into the broader hardware system. This nesting allows the security functions to be contained within existing hardware architectures without requiring completely separate complex systems.
3Ease of manufacture
If conventional CP technologies are used, then ease of manufacture is improved, but security reliability deteriorates against determined adversaries
Solution Approach 1:
The security processing component performs preliminary actions by pre-storing encryption keys in secure memory and pre-processing encrypted code before execution. The key storage unit securely holds keys that are loaded in advance, and the decryption unit is prepared to process code as it arrives, eliminating the need for complex real-time key management during execution.
Solution Approach 2:
The security processing component acts as an intermediary between the encrypted code and the execution environment. It receives encrypted code, performs decryption using securely stored keys, and then executes the decrypted code. This intermediary function isolates the security-critical operations from the main system, maintaining ease of manufacture while providing robust protection against determined adversaries.
Data Source
AI summary
Methods for code protection are disclosed. A method includes using a security processing component to access an encrypted portion of an application program that is encrypted by an on-line server, after a license for use of the application program is authenticated by the on-line server. The security processing component is used to decrypt the encrypted portion of the application program using an encryption key that is stored in the security processing component. The decrypted portion of the application program is executed based on stored state data. Results are provided to the application program that is executing on a second processing component.


