Secure Cryptographic Coprocessor Architecture for Attack Resistance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security circuitry approaches are inadequate to combat the diverse and varied software, hardware, and wireless attacks on electronic devices, often resulting in interoperability issues and increased design and testing complexities.

Innovation Solution

The implementation of a secure cryptographic coprocessor with adaptable and flexible security hardware, utilizing a comportable component design framework that enables seamless interaction between different security-related circuits, and incorporating features like hardware-based root of trust, cryptographic processing, and advanced randomness generation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing security circuitry approaches are used, then basic security functionality is provided, but interoperability issues and increased design and testing complexities occur

Engineering Contradiction:
Improvesecurity functionalityVSAvoiddesign and testing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal security circuitry architecture where a single security processor can perform multiple security functions including cryptographic operations, random number generation, and secure key management. This multi-functional design eliminates the need for separate dedicated circuits for each security operation, thereby reducing overall design complexity while maintaining comprehensive security functionality.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent combines previously separate security components (cryptographic processor, random number generator, key management unit) into a single integrated security circuitry block. This merging approach simplifies the overall system architecture, reduces the number of interfaces that need to be tested, and improves interoperability while preserving all essential security functions.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If hardware-based protection is implemented, then security against physical attacks is improved, but device complexity increases

Engineering Contradiction:
Improveprotection against physical attacksVSAvoidhardware complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security architecture into a dedicated security processor that operates independently from the main application processor. This security processor contains all hardware-based protection mechanisms (tamper detection, secure key storage, cryptographic operations) in a modular fashion, allowing these complex features to be implemented without significantly increasing the overall device complexity. The segmented design also simplifies testing and verification.

Inventive Principle:
Principle #1Segmentation

3Reliability

If comprehensive security measures are implemented, then attack resistance is improved, but interoperability between security circuits deteriorates

Engineering Contradiction:
Improveattack resistanceVSAvoidinteroperability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The security processor is designed with universal interfaces and standardized communication protocols that enable seamless interoperability with different types of security circuits and components. The processor can adapt to various cryptographic algorithms, key management schemes, and physical protection mechanisms through software configuration rather than hardware changes, thereby maintaining high interoperability while implementing comprehensive security measures.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP4281892B1Secure cryptographic coprocessor
Publication Date: 2025.06.04 GOOGLE LLC
  • EP4281892B1 patent drawingFigure 1
  • EP4281892B1 patent drawingFigure 2
  • EP4281892B1 patent drawingFigure 3-1

AI summary

An apparatus with an integrated circuit (IC) chip can provide protection against attacks on a cryptographic coprocessor. An attacker can compromise a cryptographic coprocessor by, for instance, obtaining a private encryption key or instruction code. To combat these attacks, example implementations store information in encrypted form. The information may correspond to data, instruction code, or intermediate values located in state registers. To securely and quickly "erase" such stored information, the cryptographic coprocessor can change the encryption key. In other example implementations, random numbers are provided with two different levels of "randomness quality" that is appropriate for different types of procedures. A cryptographic coprocessor can include two registers that store randomized bits in accordance with the two different quality levels for rapid access during cryptographic operations. To further thwart would-be attacks, a cryptographic coprocessor can verify the contents or usage of instruction code that is executed to perform cryptographic operations.