Hardware Key Management via State Machine Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional data encryption techniques lack effective hardware-level key management, making encryption keys vulnerable to unauthorized access and interception.

Innovation Solution

A hardware system and method that integrates an I/O controller with a cryptocontext memory and a key unwrap engine, accessible only via state machines, to manage and decrypt wrapped keys, preventing unauthorized access to encryption keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional encryption techniques are used, then data can be encrypted, but encryption keys become vulnerable to unauthorized access and interception

Engineering Contradiction:
Improvedata securityVSAvoidkey vulnerability to unauthorized access
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system segments key management into distinct functional components: a key wrap engine that encrypts keys, a cryptocontext memory that stores wrapped keys, and state machines that control access. This segmentation isolates the key material from general system access, preventing unauthorized interception while maintaining encryption functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces wrapped keys as an intermediary form between plain text keys and encrypted data. Instead of transmitting or storing plain text keys, the system uses wrapped keys that require unwrapping by authorized state machines. This intermediary layer protects keys from unauthorized access while enabling controlled decryption when needed.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If keys are stored in accessible memory, then key management is simplified, but keys become vulnerable to interception

Engineering Contradiction:
Improvekey managementVSAvoidkey interception
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies a protective shell metaphor through the key wrap engine and cryptocontext memory structure. Wrapped keys are stored in a protected memory structure that acts as a shell, concealing the actual key material from unauthorized access while allowing authorized state machines to unwrap and access the keys when necessary.

Inventive Principle:
Principle #30Flexible shells and thin films

Solution Approach 2:

The system changes the state parameter of keys from plain text to wrapped/encrypted form for storage and transmission. This parameter change ensures that even if memory is accessed unauthorized, the key material remains protected. The state can be temporarily changed to unwrapped form only within authorized state machines when key access is legitimately required.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9064135B1Hardware implemented key management system and method
Publication Date: 2015.06.23 MARVELL ASIA PTE LTD
  • US9064135B1 patent drawing
  • US9064135B1 patent drawing
  • US9064135B1 patent drawing

AI summary

A hardware implemented system and method of encryption key management may facilitate access to a connected device. In some embodiments, an Input/Output (I/O) controller coupled to a host system may comprise a cryptocontext memory that is only accessible via state machines running on the controller and a key unwrap engine to decrypt wrapped keys associated with commands received from the host system.