Secure Processor Segmentation for Cryptographic Key Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional digital computer systems lack a secure environment for performing cryptography due to unfettered access to processors and memory, compromising the preservation of sensitive information.

Innovation Solution

A system is provided that employs a hardware-specific secret identifier within a secure processor environment, using a combination of secure hardware and software environments to restrict access and perform key-based cryptographic processes, with the secret key being internally accessible only within the processor and not exposed externally.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional digital computer systems are used for information processing, then general-purpose computing capabilities are provided, but security of sensitive information is compromised due to unfettered access to processors and memory

Engineering Contradiction:
Improvesecurity of sensitive informationVSAvoidunfettered access to processors and memory
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system divides the processor into two distinct environments: a secure hardware environment that stores the digital secret and performs cryptographic operations, and a general-purpose software environment that handles standard computing tasks. This segmentation isolates sensitive cryptographic operations from potential attacks on the general system, resolving the contradiction between providing general computing access and securing sensitive information.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The secure hardware environment is nested within the general-purpose processor system. The secure environment contains the digital secret and cryptographic functional blocks, while being accessible only through controlled interfaces from the outer software environment. This nested structure allows the system to maintain general-purpose capabilities while protecting the inner secure core from external access.

Inventive Principle:
Principle #7Nested doll (Nesting)

2Reliability

If a secure hardware environment is created to protect sensitive information, then security is improved, but device complexity increases due to separate cryptographic functional blocks

Engineering Contradiction:
Improvesecurity environmentVSAvoidseparate cryptographic functional blocks
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the secure hardware environment and general-purpose software environment into a single integrated processor system. The cryptographic functional blocks are combined with standard processing units, allowing both secure cryptography and general computing to coexist in one device. This reduces overall system complexity compared to having completely separate secure and non-secure systems.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The processor is designed with multi-functionality, where the same physical device can operate in both secure cryptographic mode and general-purpose computing mode. The cryptographic functional blocks can perform both encryption/decryption operations and standard data processing, eliminating the need for entirely separate hardware systems and reducing overall device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7681046B1System with secure cryptographic capabilities using a hardware specific digital secret
Publication Date: 2010.03.16 INTELLECTUAL VENTURES HOLDING 81 LLC
  • US7681046B1 patent drawing
  • US7681046B1 patent drawing
  • US7681046B1 patent drawing

AI summary

A system with secure cryptographic capabilities using a hardware specific digital secret.