Key Management Device Bypass Channels for Secure Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional key management devices face challenges in managing and storing multiple keys, requiring users to know storage locations and being vulnerable to key theft if the bus is tapped.
Innovation Solution
A key management device with bypass channels, including a static random-access memory, register, and arbitration circuit, allows direct key transmission to encryption/decryption circuits, using a control circuit to manage a key database and lookup table, and is integrated into a processor chip for enhanced security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If keys are stored in conventional memory locations accessible via bus, then key retrieval is possible, but the system is vulnerable to eavesdropping and key theft
Solution Approach 1:
The patent extracts the key transmission path from the public bus and creates a dedicated bypass channel between the key management device and encryption/decryption circuits. This separation removes the vulnerable bus communication for key transmission, allowing keys to be retrieved and transmitted securely without exposing them to eavesdropping on the main bus.
Solution Approach 2:
The bypass channel acts as a secure intermediary pathway that enables direct communication between the key management device and encryption/decryption circuits. This intermediary channel isolates key transmission from the public bus system, providing a protected route that prevents external eavesdropping while maintaining necessary functionality.
2Ease of operation
If users need to know storage locations of keys, then key management is transparent, but user convenience deteriorates
Solution Approach 1:
The key management device autonomously manages key storage locations and retrieval operations without requiring user knowledge of specific memory addresses. The device performs self-service by automatically locating and retrieving keys based on key identifiers, eliminating the burden of remembering storage locations while maintaining transparent key management for users.
Solution Approach 2:
The key management device acts as an intermediary between users and the key storage system. It abstracts the complex storage location management from users, handling the lookup and retrieval processes internally through the bypass channel, while presenting a simplified interface to users who only need to request keys by identifier.
3Device complexity
If keys are transmitted through the bus, then communication is simple, but security against key theft is compromised
Solution Approach 1:
The communication structure is segmented into two separate paths: the public bus for general data transmission and the dedicated bypass channel for secure key transmission. This segmentation allows the system to maintain simple bus communication for non-sensitive data while providing enhanced security for key transmission through the isolated bypass pathway.
Solution Approach 2:
The key transmission function is extracted from the public bus communication system and placed in a separate bypass channel. This extraction removes the security vulnerability of bus-based key transmission while preserving the simplicity of bus communication for other purposes, creating a dual-path architecture that addresses both simplicity and security requirements.
Data Source
AI summary
A key management device for data encryption/decryption is provided. The key management device includes a static random access memory (SRAM), a register, an arbitration circuit, and a control circuit. The arbitration circuit is electrically connected to an encryption/decryption device having a plurality of encryption/decryption circuits. There is a bypass channel between each encryption/decryption circuit and the arbitration circuit. The control circuit arranges a key lookup table in the SRAM or the register, and manages a key database including the SRAM and a one-time programmable memory. The key lookup table includes a key number and metadata of each key stored in the key database. In response to the control circuit retrieving a specific key corresponding to a specific key number indicated by a key read command, the control circuit directly transmits the retrieved specific key to the corresponding encryption/decryption circuit through the corresponding bypass channel.


