Hardware Key Storage with Configurable Destination Addresses

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for securing cryptographic key data on integrated-circuit devices lack flexibility and are vulnerable to key exposure, even when using hardware separation and secure modes.

Innovation Solution

A hardware key-storage system that allows configurable destination memory addresses for cryptographic keys, preventing modification and ensuring secure storage and usage, with hardware logic enforcing secure access and one-time programmability to protect keys from unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic keys are stored in hardware-separated key storage slots with software-controlled selection, then security is improved, but flexibility is reduced

Engineering Contradiction:
ImprovesecurityVSAvoidflexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The key storage system is segmented into multiple independent key storage slots, each with its own dedicated key register and address register. This segmentation allows selective activation and configuration of individual key slots, providing both security through isolation and flexibility through selective usage of different slots for different purposes and destinations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system employs dynamic configuration where destination addresses for cryptographic keys are programmable and can be modified through a control interface. The key storage system transitions from static hardwired connections to dynamic programmable routing, allowing the same hardware to adapt to different security requirements and key distribution scenarios.

Inventive Principle:
Principle #15Dynamics

2Reliability

If cryptographic keys are transferred via a separate key bus, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system merges the key storage memory with standard memory structures and integrates the key bus interface with existing system buses. By combining key storage functionality with conventional memory architectures and using standardized bus interfaces, the system achieves secure key transfer without proportionally increasing overall device complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The key storage system is designed with universal interfaces that can interact with multiple types of cryptographic engines and processors. The same key storage slots and bus interface serve multiple functions: storing different types of cryptographic keys, supporting various cryptographic algorithms, and interfacing with different processor types, thereby reducing complexity through multi-functionality.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If key destination addresses are configurable, then flexibility is improved, but vulnerability to attacks increases

Engineering Contradiction:
ImproveflexibilityVSAvoidvulnerability to attacks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary configuration of destination addresses through a controlled programming interface before key transfer operations. Destination addresses are pre-validates and registered in the system, ensuring that keys can only be transferred to authorized destinations. This preliminary action prevents unauthorized redirection while maintaining the flexibility to configure legitimate destinations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where the control interface monitors and validates destination address configurations. The system provides feedback on whether a configured destination is authorized, and can prevent or alert on attempted unauthorized key redirection. This feedback loop maintains flexibility for legitimate configuration while protecting against attacks.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3788536B1Cryptographic key distribution
Publication Date: 2023.04.26 NORDIC SEMICONDUCTOR
  • EP3788536B1 patent drawingFigure 1
  • EP3788536B1 patent drawingFigure 2
  • EP3788536B1 patent drawingFigure 3

AI summary

An integrated-circuit device (1) comprises a processor (5), a hardware key-storage system (12), and a key bus (13). The hardware key-storage system (12) comprises a non-volatile key storage memory (12a), which includes a key register, for storing a cryptographic key, and an address register, for storing a destination memory address for the cryptographic key. The hardware key-storage system (12) further comprises output logic (12b) for sending the cryptographic key over the key bus (13) to the destination memory address, and write-once logic (12b) for preventing an address being written to the address register unless the address register is in an erased state.