Secure Hardware Key Derivation for Symmetric Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for secure key management in symmetric encryption are complex and resource-intensive, particularly in real-time applications, making it difficult to protect keys against attacks and impacting system performance.
Innovation Solution
An integrated circuit with a secure hardware environment that generates a unique derived key from a hardware key and execution context information, enabling secure encryption and decryption of secret keys within the hardware environment, thus avoiding software-based key management and ensuring robust protection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If software-based key management is used, then key management functionality is provided, but system complexity and resource consumption increase
Solution Approach 1:
The patent replaces software-based key management with a hardware-based secure environment (security module) that automatically performs key generation, storage, and cryptographic operations. This substitution eliminates the need for complex software key management systems while providing the same functionality through dedicated hardware circuits.
Solution Approach 2:
The secure hardware environment autonomously manages cryptographic keys without requiring external software intervention. The security module independently generates keys, performs encryption/decryption operations, and manages key lifecycles, reducing system complexity by making the key management system self-sufficient.
2Ease of operation
If software-based key management is used, then key management is provided, but execution time and resource usage increase
Solution Approach 1:
The patent replaces software-based key management operations with hardware-based operations in a secure environment. Cryptographic operations that would execute as software instructions are instead performed by dedicated hardware circuits, significantly reducing execution time and resource consumption while maintaining key management functionality.
3Ease of operation
If keys are stored in software, then key accessibility is provided, but security against attacks decreases
Solution Approach 1:
The patent extracts key storage and management operations from the general software environment into a dedicated secure hardware environment. This separation isolates cryptographic keys from vulnerable software contexts, providing physical and architectural security protections while maintaining controlled accessibility through the security module's interfaces.
Solution Approach 2:
The secure hardware environment acts as an intermediary between applications and cryptographic keys. Instead of applications directly accessing keys in software, all key operations must go through the secure hardware module, which provides security protections while enabling controlled key usage through standardized interfaces.
4Reliability
If unique derived keys are generated for each context, then security is improved, but computational complexity increases
Solution Approach 1:
The secure hardware environment autonomously generates unique derived keys for different execution contexts without requiring external computational resources. The security module internally manages the complexity of key derivation operations, providing enhanced security through context-specific keys while keeping the computational burden contained within the hardware module.
Data Source
AI summary
A unique hardware key is recorded a secure hardware environment. A first logic circuit of the secure hardware environment is configured to generate a unique derived key from said unique hardware key and at least one piece of information. The at least one piece of information relates to one or more of an execution context and a use of a secret key. The secure hardware environment further includes a first encryption device that performs a symmetric encryption of the secret key using the unique derived key. This symmetric encryption generates an encrypted secret key for use outside of the secure hardware environment.


