Multi-core Processor Key Protection via Dedicated Cryptographic Core

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for securing private keys in computer systems using public-key cryptographic algorithms face challenges such as potential unauthorized access and cold boot attacks when keys are stored in physical memory, and existing solutions like storing keys in registers or external media have limitations in scalability and convenience.

Innovation Solution

A multi-core processor-based key protection method where one core is configured as a cryptographic operation core, dedicated to performing public-key cryptographic operations, with the private key and intermediate variables stored exclusively in its cache, ensuring isolation from other processes and enhanced security against memory-based attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If private keys are stored in physical memory for cryptographic operations, then cryptographic operations can be performed efficiently, but the system becomes vulnerable to unauthorized access and cold boot attacks

Engineering Contradiction:
Improvecryptographic operation efficiencyVSAvoidkey security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent divides the processor into multiple cores, designating one core specifically for cryptographic operations. This segmentation isolates the cryptographic operations from other system processes, creating a dedicated secure environment that maintains efficiency while preventing unauthorized access to private keys stored in memory.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a hardware security module or trusted execution environment as an intermediary between the cryptographic operations and the rest of the system. This intermediary layer provides additional security measures to protect private keys while allowing efficient cryptographic operations to proceed.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If private keys are stored in registers or external media, then security against memory attacks is improved, but scalability and user convenience are compromised

Engineering Contradiction:
Improvekey securityVSAvoidsystem scalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent designs the dedicated cryptographic core to perform multiple functions including key storage, cryptographic operations, and security management. This multi-functional approach provides scalability by allowing the same architectural framework to support various cryptographic algorithms and applications without compromising security or convenience.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements preliminary security measures such as secure key generation, encryption of private keys, and isolation of cryptographic operations before they are exposed to the system. These preliminary actions ensure that even if keys are stored in registers or external media, they remain protected while maintaining system scalability.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If a dedicated cryptographic core is created to isolate sensitive data, then security against cold boot attacks is enhanced, but device complexity increases

Engineering Contradiction:
Improvesecurity against cold boot attacksVSAvoidprocessor architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the cryptographic operations with the processor architecture by integrating a dedicated cryptographic core into the multi-core processor. This integration combines the security benefits of isolation with the efficiency of hardware acceleration, reducing overall system complexity while maintaining enhanced security against cold boot attacks.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent changes the architectural parameters of the processor by introducing a dedicated core with specific memory access rights and isolation mechanisms. This parameter change enables enhanced security without requiring complete redesign of the entire system architecture, thus managing complexity while achieving the security goals.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9898624B2Multi-core processor based key protection method and system
Publication Date: 2018.02.20 DATA ASSURANCE & COMM SECURITY CENT CHINESE ACADEMY OF SCI
  • US9898624B2 patent drawing
  • US9898624B2 patent drawing
  • US9898624B2 patent drawing

AI summary

A multi-core processor based key protection method and system is described. An Operating System (OS) supporting Symmetric Multi-Processing (SMP) is set up on a multi-core processor. One core of the multi-core processor is configured as a cryptographic operation core, which is prohibited from running other processes of the OS and dedicated to perform a public-key cryptographic operation. The private key and an intermediate variable in a process of the public-key cryptographic operation are stored in a cache exclusively occupied by the cryptographic operation core.