Secure Cryptographic Coprocessor Architecture for Attack Resistance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security circuitry approaches are inadequate to combat the diverse and varied software, hardware, and wireless attacks on electronic devices, often resulting in interoperability issues and increased design and testing complexities.
Innovation Solution
The implementation of a secure cryptographic coprocessor with adaptable and flexible security hardware, utilizing a comportable component design framework that enables seamless interaction between different security-related circuits, and incorporating features like hardware-based root of trust, cryptographic processing, and advanced randomness generation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing security circuitry approaches are used, then basic security functionality is provided, but interoperability issues and increased design and testing complexities occur
Solution Approach 1:
The patent implements a universal security circuitry architecture where a single security processor can perform multiple security functions including cryptographic operations, random number generation, and secure key management. This multi-functional design eliminates the need for separate dedicated circuits for each security operation, thereby reducing overall design complexity while maintaining comprehensive security functionality.
Solution Approach 2:
The patent combines previously separate security components (cryptographic processor, random number generator, key management unit) into a single integrated security circuitry block. This merging approach simplifies the overall system architecture, reduces the number of interfaces that need to be tested, and improves interoperability while preserving all essential security functions.
2Reliability
If hardware-based protection is implemented, then security against physical attacks is improved, but device complexity increases
Solution Approach 1:
The patent segments the security architecture into a dedicated security processor that operates independently from the main application processor. This security processor contains all hardware-based protection mechanisms (tamper detection, secure key storage, cryptographic operations) in a modular fashion, allowing these complex features to be implemented without significantly increasing the overall device complexity. The segmented design also simplifies testing and verification.
3Reliability
If comprehensive security measures are implemented, then attack resistance is improved, but interoperability between security circuits deteriorates
Solution Approach 1:
The security processor is designed with universal interfaces and standardized communication protocols that enable seamless interoperability with different types of security circuits and components. The processor can adapt to various cryptographic algorithms, key management schemes, and physical protection mechanisms through software configuration rather than hardware changes, thereby maintaining high interoperability while implementing comprehensive security measures.
Data Source
Figure 1
Figure 2
Figure 3-1
AI summary
An apparatus with an integrated circuit (IC) chip can provide protection against attacks on a cryptographic coprocessor. An attacker can compromise a cryptographic coprocessor by, for instance, obtaining a private encryption key or instruction code. To combat these attacks, example implementations store information in encrypted form. The information may correspond to data, instruction code, or intermediate values located in state registers. To securely and quickly "erase" such stored information, the cryptographic coprocessor can change the encryption key. In other example implementations, random numbers are provided with two different levels of "randomness quality" that is appropriate for different types of procedures. A cryptographic coprocessor can include two registers that store randomized bits in accordance with the two different quality levels for rapid access during cryptographic operations. To further thwart would-be attacks, a cryptographic coprocessor can verify the contents or usage of instruction code that is executed to perform cryptographic operations.