Hardware Security Component for Encrypted Code Execution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional code protection technologies are insufficient in deterring determined adversaries, as they can be susceptible to attacks that exploit decryption keys, especially in software-based systems and require robust hardware that is difficult to maintain.

Innovation Solution

A hardware-based security processing component and architecture that uses online authentication and encrypted code execution, where a security processing component decrypts and executes encrypted application code, utilizing a stored encryption key to provide multileveled protection against unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If software based CP technologies are used, then ease of operation is improved, but security reliability deteriorates because decryption keys can be extracted and content can be decrypted and copied

Engineering Contradiction:
Improveease of operationVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces software-based code protection with a dedicated hardware security processing component that performs decryption and code execution. This hardware component includes a secure key storage unit and execution unit that are physically isolated from the main software system, preventing software-based attacks while maintaining operational ease through automated secure execution.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The security processing component is divided into distinct functional modules: a key storage unit that securely holds decryption keys, a decryption unit that processes encrypted code, and an execution unit that runs decrypted code. This segmentation isolates security-critical functions from the rest of the system, preventing key extraction while maintaining operational efficiency.

Inventive Principle:
Principle #1Segmentation

2Reliability

If hardware based CP technologies are used, then security reliability is improved, but device complexity increases and manufacturing difficulty increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security processing component is designed as a universal module that can be integrated into various existing hardware platforms. It provides multiple functions including key storage, decryption, and code execution within a single integrated component, reducing overall system complexity while maintaining high security reliability. The component can work with different encryption schemes and application types.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The security processing component is implemented as a nested structure where the key storage unit is embedded within the execution unit, which is in turn integrated into the broader hardware system. This nesting allows the security functions to be contained within existing hardware architectures without requiring completely separate complex systems.

Inventive Principle:
Principle #7Nested doll (Nesting)

3Ease of manufacture

If conventional CP technologies are used, then ease of manufacture is improved, but security reliability deteriorates against determined adversaries

Engineering Contradiction:
Improveease of manufactureVSAvoidsecurity reliability
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The security processing component performs preliminary actions by pre-storing encryption keys in secure memory and pre-processing encrypted code before execution. The key storage unit securely holds keys that are loaded in advance, and the decryption unit is prepared to process code as it arrives, eliminating the need for complex real-time key management during execution.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security processing component acts as an intermediary between the encrypted code and the execution environment. It receives encrypted code, performs decryption using securely stored keys, and then executes the decrypted code. This intermediary function isolates the security-critical operations from the main system, maintaining ease of manufacture while providing robust protection against determined adversaries.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9177121B2Code protection using online authentication and encrypted code execution
Publication Date: 2015.11.03 NVIDIA CORP
  • US9177121B2 patent drawing
  • US9177121B2 patent drawing
  • US9177121B2 patent drawing

AI summary

Methods for code protection are disclosed. A method includes using a security processing component to access an encrypted portion of an application program that is encrypted by an on-line server, after a license for use of the application program is authenticated by the on-line server. The security processing component is used to decrypt the encrypted portion of the application program using an encryption key that is stored in the security processing component. The decrypted portion of the application program is executed based on stored state data. Results are provided to the application program that is executing on a second processing component.