IoT Secure Memory Encryption During Low Power Mode
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
IoT devices face challenges in securing data stored in their memory, especially when entering low power mode, as secure parts are disabled, leading to potential insecurity and loss of encryption keys, and clock synchronization issues.
Innovation Solution
A method where the memory content of a secure part is encrypted and stored externally during low power mode, using a secure stamp from a remote client access server for decryption upon exiting low power mode, ensuring secure data loading and preventing anti-replay attacks, with the secure stamp being retained for secure functions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Use of energy by moving object
If the IoT device enters low power mode to conserve energy, then power consumption is reduced, but the secure memory is disabled and encryption keys are lost, compromising data security
Solution Approach 1:
The patent applies preliminary action by encrypting the memory content with a first cryptographic key before the IoT device enters low power mode. This encryption is performed in advance while the secure memory is still accessible and powered, ensuring that even if the memory is read in low power mode, the data remains protected. The encryption key is stored in a way that persists through power cycles, maintaining security without requiring continuous power to the secure memory.
Solution Approach 2:
The patent introduces an intermediary mechanism by using a separate power domain for the secure memory that remains powered during low power mode, while other parts of the device are powered down. This intermediary power domain acts as a bridge, allowing the secure memory to maintain its protective function without requiring the entire device to remain powered, thus resolving the contradiction between power conservation and security maintenance.
2Ease of operation
If a global key is used to protect secure memory, then data can be accessed after low power mode, but previous content can be reloaded, eliminating anti-replay countermeasures
Solution Approach 1:
The patent applies asymmetry by using different cryptographic keys for different purposes: a first key for encrypting memory content and a second key for authenticating access. The encryption key remains persistent across power cycles to allow data access, while a separate authentication mechanism using a second key provides anti-replay protection. This asymmetric key approach allows the system to simultaneously achieve data accessibility and replay protection that a single global key cannot provide.
Solution Approach 2:
The patent segments the security function into two separate key roles: one key for encryption (maintaining data confidentiality) and another for authentication (providing anti-replay protection). This segmentation allows each key to specialize in its function, with the encryption key persisting for data access and the authentication key providing security validation, thereby resolving the contradiction between accessibility and replay protection.
3Productivity
If the secure part performs commands before security initialization is complete, then device functionality is maintained, but security may not be ensured
Solution Approach 1:
The patent applies preliminary action by pre-configuring the secure memory with persistent encryption keys before the device enters low power mode or before security initialization is complete. This preliminary configuration ensures that even if commands are executed before full security initialization, the data in secure memory remains protected by the pre-established encryption, maintaining both functionality and security assurance.
4Duration of action of moving object
If the clock is lost or sourced from non-secure components during low power mode, then the device can exit low power mode, but secure and accurate clock synchronization cannot be ensured
Solution Approach 1:
The patent introduces an intermediary approach by maintaining a separate, secure clock source or clock reference in the always-on memory domain that remains active during low power mode. This intermediary clock reference allows the device to maintain accurate timekeeping and clock synchronization without requiring the main system clock to remain powered, enabling both extended low power mode operation and secure clock accuracy.
Data Source
AI summary
The disclosure relates to a method for enabling the secure functions of a chipset (1) and especially the encryption of the content of the secure memory (7) when the device goes into low power mode. The content of the secure memory (7) may be encrypted and stored in an external memory (20) during low power mode of the chipset (1).


