Secure Processor Instruction Authentication and Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current secure processor systems are inadequate in preventing malicious execution codes, as they lack a secure software execution environment and inefficient encryption processing due to external encryption hardware and inappropriate key selection for encryption/decryption.

Innovation Solution

A secure processor with integrated encryption processing and key management, where the processor authenticates and encrypts instruction codes stored in a non-rewritable format, allowing only authenticated codes to execute, and dynamically selects encryption keys based on executed instructions to enhance security and performance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption processing is performed externally on another chip, then security is improved, but encryption processing performance deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidencryption processing performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges the encryption processing function with the processor by providing an encryption processing unit that includes both an encryption key generation unit and an encryption processing unit integrated within the processor chip. This integration allows the processor to perform encryption operations internally without requiring external encryption hardware, thereby improving encryption processing performance while maintaining security through the use of processor-specific keys generated based on instruction characteristics.

Inventive Principle:
Principle #5Merging (Combining)

2Ease of operation

If encryption key is determined externally, then key management is simplified, but appropriate key selection for different instructions becomes impossible

Engineering Contradiction:
Improvekey managementVSAvoidkey selection adaptability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic key selection by providing an encryption key generation unit that generates different encryption keys based on the specific instructions to be executed. The key selection is dynamically adjusted according to instruction characteristics, allowing the system to select appropriate keys for different operations while maintaining simplified key management through automated generation and selection processes.

Inventive Principle:
Principle #15Dynamics

3Device complexity

If traditional processor security measures are used, then implementation is simple, but secure software execution environment cannot be provided

Engineering Contradiction:
Improveimplementation simplicityVSAvoidsecure software execution environment
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent implements preliminary authentication of execution codes before they are executed by the processor. The authentication processing unit authenticates instruction codes based on processor-specific keys before execution, preventing malicious codes from running. This preliminary security check provides a secure software execution environment while maintaining relatively simple implementation by integrating the authentication function within the processor architecture.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10303901B2Secure processor and a program for a secure processor
Publication Date: 2019.05.28 SOCIONEXT INC
  • US10303901B2 patent drawing
  • US10303901B2 patent drawing
  • US10303901B2 patent drawing

AI summary

The instruction code including an instruction code stored in the area where the encrypted instruction code is stored in a non-rewritable format is authenticated using a specific key which is specific to the core where the instruction code is executed or an authenticated key by a specific key to perform an encryption processing for the input and output data between the core and the outside.