Secure Accelerator Interface for Encryption Key Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing electronic devices face challenges in accelerating data processing operations while maintaining the secrecy of cryptographic keys, as prior art hardware accelerators either incur significant overhead or expose keys to unauthorized access when used outside the secure execution environment.

Innovation Solution

An electronic device with a secure execution environment and an accelerator that uses a first logical interface for data processing and a secure second logical interface for cryptographic keys, allowing only protected applications to access the keys, thereby preventing exposure to unauthorized parties.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If hardware accelerators are used outside the secure execution environment to accelerate data processing operations, then processing speed is improved, but cryptographic keys become exposed to unauthorized access

Engineering Contradiction:
Improvedata processing speedVSAvoidcryptographic key security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The accelerator is divided into two distinct interfaces: a first logical interface for data processing and a second logical interface for key provisioning. This segmentation allows data processing to occur outside the secure environment while key management remains isolated and protected, resolving the contradiction between speed and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The second logical interface acts as an intermediary between the secure execution environment and the accelerator. It securely provisions cryptographic keys to the accelerator without exposing them to the rest of the system, enabling fast processing while maintaining key security through controlled access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If secure entries to and exits from the secure execution environment are undertaken for encryption operations, then cryptographic key security is maintained, but processing overhead increases

Engineering Contradiction:
Improvecryptographic key securityVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Cryptographic keys are provisioned to the accelerator in advance through the second logical interface before data processing operations begin. This preliminary action eliminates the need for repeated secure environment entries and exits during processing, reducing overhead while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The second logical interface serves as a dedicated intermediary channel for key management, separating it from data processing operations. This allows keys to be securely made available to the accelerator without requiring the processor to repeatedly enter and exit the secure environment, thus reducing time loss.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If prior art hardware accelerators are used for encryption operations, then data processing efficiency is improved, but additional security measures and hardware are required increasing device costs

Engineering Contradiction:
Improveencryption processing efficiencyVSAvoidsecurity hardware and software requirements
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The accelerator is designed to serve multiple functions: it performs data processing operations efficiently while also incorporating integrated key management capabilities through the second logical interface. This multi-functionality eliminates the need for separate security hardware and software measures, reducing device complexity while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8028164B2Practical and secure storage encryption
Publication Date: 2011.09.27 NOKIA TECHNOLOGIES OY
  • US8028164B2 patent drawing
  • US8028164B2 patent drawing
  • US8028164B2 patent drawing

AI summary

The present invention relates to an electronic device (301) in which acceleration of data processing operations is provided, the device comprising a secure execution environment to which access is controlled. A basic idea of the present invention is to provide a device (311) for acceleration of data processing operations (an “accelerator”). In particular, the accelerator is used to accelerate cryptographic data operations such that it performs cryptographic operations on data provided to it via a first logical interface. The cryptographic operations are performed by means of encryption/decryption keys provided to the accelerator via a secure second logical interface which may share a same physical interface (312) with the first logical interface or which may use a distinct physical interface (414) from that of a distinct physical interface (412) used as the first logical interface.