Multi-core Processor Key Protection via Dedicated Cryptographic Core
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for securing private keys in computer systems using public-key cryptographic algorithms face challenges such as potential unauthorized access and cold boot attacks when keys are stored in physical memory, and existing solutions like storing keys in registers or external media have limitations in scalability and convenience.
Innovation Solution
A multi-core processor-based key protection method where one core is configured as a cryptographic operation core, dedicated to performing public-key cryptographic operations, with the private key and intermediate variables stored exclusively in its cache, ensuring isolation from other processes and enhanced security against memory-based attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If private keys are stored in physical memory for cryptographic operations, then cryptographic operations can be performed efficiently, but the system becomes vulnerable to unauthorized access and cold boot attacks
Solution Approach 1:
The patent divides the processor into multiple cores, designating one core specifically for cryptographic operations. This segmentation isolates the cryptographic operations from other system processes, creating a dedicated secure environment that maintains efficiency while preventing unauthorized access to private keys stored in memory.
Solution Approach 2:
The patent introduces a hardware security module or trusted execution environment as an intermediary between the cryptographic operations and the rest of the system. This intermediary layer provides additional security measures to protect private keys while allowing efficient cryptographic operations to proceed.
2Reliability
If private keys are stored in registers or external media, then security against memory attacks is improved, but scalability and user convenience are compromised
Solution Approach 1:
The patent designs the dedicated cryptographic core to perform multiple functions including key storage, cryptographic operations, and security management. This multi-functional approach provides scalability by allowing the same architectural framework to support various cryptographic algorithms and applications without compromising security or convenience.
Solution Approach 2:
The patent implements preliminary security measures such as secure key generation, encryption of private keys, and isolation of cryptographic operations before they are exposed to the system. These preliminary actions ensure that even if keys are stored in registers or external media, they remain protected while maintaining system scalability.
3Reliability
If a dedicated cryptographic core is created to isolate sensitive data, then security against cold boot attacks is enhanced, but device complexity increases
Solution Approach 1:
The patent merges the cryptographic operations with the processor architecture by integrating a dedicated cryptographic core into the multi-core processor. This integration combines the security benefits of isolation with the efficiency of hardware acceleration, reducing overall system complexity while maintaining enhanced security against cold boot attacks.
Solution Approach 2:
The patent changes the architectural parameters of the processor by introducing a dedicated core with specific memory access rights and isolation mechanisms. This parameter change enables enhanced security without requiring complete redesign of the entire system architecture, thus managing complexity while achieving the security goals.
Data Source
AI summary
A multi-core processor based key protection method and system is described. An Operating System (OS) supporting Symmetric Multi-Processing (SMP) is set up on a multi-core processor. One core of the multi-core processor is configured as a cryptographic operation core, which is prohibited from running other processes of the OS and dedicated to perform a public-key cryptographic operation. The private key and an intermediate variable in a process of the public-key cryptographic operation are stored in a cache exclusively occupied by the cryptographic operation core.


