Key Management Device Bypass Channels for Secure Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional key management devices face challenges in managing and storing multiple keys, requiring users to know storage locations and being vulnerable to key theft if the bus is tapped.

Innovation Solution

A key management device with bypass channels, including a static random-access memory, register, and arbitration circuit, allows direct key transmission to encryption/decryption circuits, using a control circuit to manage a key database and lookup table, and is integrated into a processor chip for enhanced security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If keys are stored in conventional memory locations accessible via bus, then key retrieval is possible, but the system is vulnerable to eavesdropping and key theft

Engineering Contradiction:
Improvekey securityVSAvoideavesdropping risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the key transmission path from the public bus and creates a dedicated bypass channel between the key management device and encryption/decryption circuits. This separation removes the vulnerable bus communication for key transmission, allowing keys to be retrieved and transmitted securely without exposing them to eavesdropping on the main bus.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The bypass channel acts as a secure intermediary pathway that enables direct communication between the key management device and encryption/decryption circuits. This intermediary channel isolates key transmission from the public bus system, providing a protected route that prevents external eavesdropping while maintaining necessary functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If users need to know storage locations of keys, then key management is transparent, but user convenience deteriorates

Engineering Contradiction:
Improvekey management convenienceVSAvoidstorage location knowledge burden
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The key management device autonomously manages key storage locations and retrieval operations without requiring user knowledge of specific memory addresses. The device performs self-service by automatically locating and retrieving keys based on key identifiers, eliminating the burden of remembering storage locations while maintaining transparent key management for users.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The key management device acts as an intermediary between users and the key storage system. It abstracts the complex storage location management from users, handling the lookup and retrieval processes internally through the bypass channel, while presenting a simplified interface to users who only need to request keys by identifier.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If keys are transmitted through the bus, then communication is simple, but security against key theft is compromised

Engineering Contradiction:
Improvecommunication structureVSAvoidkey transmission security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The communication structure is segmented into two separate paths: the public bus for general data transmission and the dedicated bypass channel for secure key transmission. This segmentation allows the system to maintain simple bus communication for non-sensitive data while providing enhanced security for key transmission through the isolated bypass pathway.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The key transmission function is extracted from the public bus communication system and placed in a separate bypass channel. This extraction removes the security vulnerability of bus-based key transmission while preserving the simplicity of bus communication for other purposes, creating a dual-path architecture that addresses both simplicity and security requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11368302B2Key management device and processor chip having bypass channels
Publication Date: 2022.06.21 NUVOTON
  • US11368302B2 patent drawing
  • US11368302B2 patent drawing
  • US11368302B2 patent drawing

AI summary

A key management device for data encryption/decryption is provided. The key management device includes a static random access memory (SRAM), a register, an arbitration circuit, and a control circuit. The arbitration circuit is electrically connected to an encryption/decryption device having a plurality of encryption/decryption circuits. There is a bypass channel between each encryption/decryption circuit and the arbitration circuit. The control circuit arranges a key lookup table in the SRAM or the register, and manages a key database including the SRAM and a one-time programmable memory. The key lookup table includes a key number and metadata of each key stored in the key database. In response to the control circuit retrieving a specific key corresponding to a specific key number indicated by a key read command, the control circuit directly transmits the retrieved specific key to the corresponding encryption/decryption circuit through the corresponding bypass channel.