Secure Microprocessor Key Management via External Non-Volatile Memory
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In electronic systems with multiple microprocessors, securely managing and updating encryption keys is challenging due to the lack of erasable and programmable non-volatile memory within the secure microprocessor, which complicates key storage and management.
Innovation Solution
An electronic system is designed with a secure microprocessor that manages encryption keys for other microprocessors, using a combination of internal and external non-volatile memories, where keys are encrypted and decrypted as needed, and a monotonic counter is used for versioning and validation, allowing secure key storage and updates.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If host keys are stored in external erasable and programmable non-volatile memory, then key modification capability is improved, but key management security deteriorates
Solution Approach 1:
The system divides key management into two separate components: a secure microprocessor that generates and protects keys, and external non-volatile memory that stores encrypted key data. This segmentation allows the secure microprocessor to maintain security while the external memory provides modification capability, resolving the contradiction between security and adaptability.
Solution Approach 2:
The patent introduces encrypted data as an intermediary between the secure microprocessor and external memory. Keys are encrypted before being stored externally, and the secure microprocessor acts as the only entity capable of decrypting them. This intermediary mechanism enables external storage with modification capability while maintaining security through cryptographic protection.
2Device complexity
If secure microprocessor has no internal erasable and programmable non-volatile memory, then device complexity is reduced, but key storage capability deteriorates
Solution Approach 1:
The patent extracts the erasable and programmable non-volatile memory function from the secure microprocessor and places it in external memory. This extraction allows the microprocessor to remain simple and secure while delegating key storage and modification capabilities to the external memory system, resolving the contradiction between device simplicity and storage capability.
Solution Approach 2:
The system creates encrypted copies of keys in external non-volatile memory while the originals remain protected in the secure microprocessor. This copying approach enables the microprocessor to maintain its simple structure without internal programmable memory while still providing key storage capability through the encrypted external copies.
Data Source
AI summary
The present description concerns an electronic system including one or a plurality of first microprocessors, a second microprocessor for securely managing first encryption keys of the first microprocessors, the second microprocessor being configured to communicate with each first microprocessor and including a first non-volatile memory having at least one second key stored therein, and for each first microprocessor, a second non-volatile memory external to the second microprocessor and containing the first keys of the first microprocessor encrypted with the second key.


