Secure Protection Zone for Cryptographic Key Storage and Operations

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack a secure mechanism to verify the authenticity and integrity of information stored in client devices connected to hosts, particularly in scenarios where asymmetric cryptographic mechanisms are used, and there is a need for robust security to prevent unauthorized access and modification of cryptographic keys and data.

Innovation Solution

An integrated circuit device with a secure protection zone that includes persistent storage for cryptographic keys and data, ephemeral memory for temporary operations, and instructions for performing cryptographic operations, allowing for secure communication and authentication with remote devices, using asymmetric key pairs and hardware-based security features to prevent unauthorized access and modification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If cryptographic keys and data are stored in standard storage devices, then ease of access and operation is improved, but security against unauthorized access and modification deteriorates

Engineering Contradiction:
Improveaccess to cryptographic keysVSAvoidsecurity of cryptographic keys
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The storage system is segmented into a secure protection zone and a non-secure zone. The secure protection zone contains persistent storage for cryptographic keys and data, while the non-secure zone contains ephemeral memory for temporary operations. This segmentation allows cryptographic keys to be stored securely while still enabling operational access through controlled cryptographic operations within the secure zone.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The secure protection zone acts as an intermediary between the external environment and the cryptographic keys. Instead of directly accessing keys stored in standard storage, all operations must go through the secure protection zone which performs cryptographic operations using the keys without exposing them. This intermediary mechanism maintains both security and operational capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If cryptographic operations are performed outside the secure zone, then processing speed and productivity are improved, but security against unauthorized modification deteriorates

Engineering Contradiction:
Improvecryptographic operation speedVSAvoidintegrity of cryptographic operations
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The secure protection zone merges multiple functions into a single integrated unit: secure storage of cryptographic keys, execution of cryptographic operations, and verification of operation integrity. By combining these functions within the secure zone, the system ensures that cryptographic operations maintain security and integrity while still achieving productivity through hardware-accelerated cryptographic processing.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If persistent storage is made highly secure with restricted modifications, then security against unauthorized access is improved, but ease of operation and flexibility deteriorates

Engineering Contradiction:
Improveprotection of stored dataVSAvoidmodification of stored data
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

Different quality levels of security are applied to different storage zones. The persistent storage within the secure protection zone has high security with restricted modifications, while the ephemeral memory in the non-secure zone allows temporary storage and modification of data during operations. This local differentiation of security qualities allows the system to maintain both high protection for cryptographic keys and operational flexibility for temporary data.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9323950B2Generating signatures using a secure device
Publication Date: 2016.04.26 ATMEL CORP
  • US9323950B2 patent drawing
  • US9323950B2 patent drawing
  • US9323950B2 patent drawing

AI summary

An integrated circuit device comprises a processor and a secure protection zone with security properties that can be verified by a remote device communicating with the integrated circuit device. The secure protection zone includes a persistent storage that is configured for storing cryptographic keys and data. The secure protection zone also includes instructions that are configured for causing the processor to perform cryptographic operations using the cryptographic keys. In addition, the secure protection zone includes an ephemeral memory that is configured for storing information associated with the cryptographic operations. The instructions are configured for causing the processor to perform the cryptographic operations on the data stored in the persistent storage and the information in the ephemeral memory as part of a secure communication exchange with the remote device.