Cryptographic Key Access Control for Data-at-Rest Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current protective measures for cryptographic keys in integrated cryptographic engines require regenerating and reprogramming keys for each change in computing device state, leading to inefficiencies and performance degradation.

Innovation Solution

Implement a cryptographic key access control scheme that maintains cryptographic keys at the key memory and controls access based on computing device states, using cryptographic key access indicators to enable or disable access as needed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic keys are evicted from ICE memory for locked state and regenerated for unlocked state, then security against data at rest attacks is improved, but resource consumption increases and performance degrades

Engineering Contradiction:
ImprovesecurityVSAvoidperformance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the cryptographic key management into two independent parts: key storage (maintained in ICE memory) and key access control (managed through access indicators and control logic). This allows the keys to remain stored while access is controlled, eliminating the need to evict and regenerate keys for security states.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent sets cryptographic key access indicators in advance to control future access to stored keys. By pre-configuring access control indicators and policies, the system can immediately enforce security states without requiring key regeneration, thus maintaining both security and performance.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If cryptographic keys are evicted from ICE memory for locked state, then security against data at rest attacks is improved, but resource consumption increases

Engineering Contradiction:
ImprovesecurityVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent separates key storage from key access control, allowing keys to remain in ICE memory while access is restricted through control indicators. This eliminates the energy-intensive operations of key eviction and regeneration while maintaining security through access control mechanisms.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent uses cryptographic key access indicators as control copies that manage access to the actual cryptographic keys. These indicators act as surrogate control structures that enable security enforcement without manipulating the actual key material, reducing resource consumption.

Inventive Principle:
Principle #26Copying

3Productivity

If cryptographic keys are left accessible in ICE memory without protective measures, then performance is improved, but security against data at rest attacks deteriorates

Engineering Contradiction:
ImproveperformanceVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces cryptographic key access indicators and access control policies as intermediary control structures between the stored keys and access requests. These intermediaries enable performance-optimized key access while enforcing security requirements, resolving the contradiction between speed and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12519630B2Approach to protect hardware managed integrated cryptographic engine keys efficiently while preventing data at rest attacks
Publication Date: 2026.01.06 QUALCOMM INC
  • US12519630B2 patent drawing
  • US12519630B2 patent drawing
  • US12519630B2 patent drawing

AI summary

Various embodiments include methods implemented in a processor for management of cryptographic keys of an integrated cryptographic engine. Embodiments may include detecting a cryptographic key access control event, determining whether the cryptographic key access control event is for disabling cryptographic key access at a cryptographic key memory of the integrated cryptographic engine, disabling cryptographic key access at the cryptographic key memory in response to determining that the cryptographic key access control event is for disabling cryptographic key access at the cryptographic key memory, and maintaining one or more cryptographic keys at the cryptographic key memory for which cryptographic key access is disabled. Embodiments may further include enabling cryptographic key access at the cryptographic key memory in response to determining that the cryptographic key access control event is not for disabling cryptographic key access at the cryptographic key memory.