Secure Processor Segmentation for Cryptographic Key Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional digital computer systems lack a secure environment for performing cryptography due to unfettered access to processors and memory, compromising the preservation of sensitive information.
Innovation Solution
A system is provided that employs a hardware-specific secret identifier within a secure processor environment, using a combination of secure hardware and software environments to restrict access and perform key-based cryptographic processes, with the secret key being internally accessible only within the processor and not exposed externally.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional digital computer systems are used for information processing, then general-purpose computing capabilities are provided, but security of sensitive information is compromised due to unfettered access to processors and memory
Solution Approach 1:
The system divides the processor into two distinct environments: a secure hardware environment that stores the digital secret and performs cryptographic operations, and a general-purpose software environment that handles standard computing tasks. This segmentation isolates sensitive cryptographic operations from potential attacks on the general system, resolving the contradiction between providing general computing access and securing sensitive information.
Solution Approach 2:
The secure hardware environment is nested within the general-purpose processor system. The secure environment contains the digital secret and cryptographic functional blocks, while being accessible only through controlled interfaces from the outer software environment. This nested structure allows the system to maintain general-purpose capabilities while protecting the inner secure core from external access.
2Reliability
If a secure hardware environment is created to protect sensitive information, then security is improved, but device complexity increases due to separate cryptographic functional blocks
Solution Approach 1:
The patent merges the secure hardware environment and general-purpose software environment into a single integrated processor system. The cryptographic functional blocks are combined with standard processing units, allowing both secure cryptography and general computing to coexist in one device. This reduces overall system complexity compared to having completely separate secure and non-secure systems.
Solution Approach 2:
The processor is designed with multi-functionality, where the same physical device can operate in both secure cryptographic mode and general-purpose computing mode. The cryptographic functional blocks can perform both encryption/decryption operations and standard data processing, eliminating the need for entirely separate hardware systems and reducing overall device complexity.
Data Source
AI summary
A system with secure cryptographic capabilities using a hardware specific digital secret.


