Secure Protection Zone for Cryptographic Key Storage and Operations
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems lack a secure mechanism to verify the authenticity and integrity of information stored in client devices connected to hosts, particularly in scenarios where asymmetric cryptographic mechanisms are used, and there is a need for robust security to prevent unauthorized access and modification of cryptographic keys and data.
Innovation Solution
An integrated circuit device with a secure protection zone that includes persistent storage for cryptographic keys and data, ephemeral memory for temporary operations, and instructions for performing cryptographic operations, allowing for secure communication and authentication with remote devices, using asymmetric key pairs and hardware-based security features to prevent unauthorized access and modification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If cryptographic keys and data are stored in standard storage devices, then ease of access and operation is improved, but security against unauthorized access and modification deteriorates
Solution Approach 1:
The storage system is segmented into a secure protection zone and a non-secure zone. The secure protection zone contains persistent storage for cryptographic keys and data, while the non-secure zone contains ephemeral memory for temporary operations. This segmentation allows cryptographic keys to be stored securely while still enabling operational access through controlled cryptographic operations within the secure zone.
Solution Approach 2:
The secure protection zone acts as an intermediary between the external environment and the cryptographic keys. Instead of directly accessing keys stored in standard storage, all operations must go through the secure protection zone which performs cryptographic operations using the keys without exposing them. This intermediary mechanism maintains both security and operational capability.
2Productivity
If cryptographic operations are performed outside the secure zone, then processing speed and productivity are improved, but security against unauthorized modification deteriorates
Solution Approach 1:
The secure protection zone merges multiple functions into a single integrated unit: secure storage of cryptographic keys, execution of cryptographic operations, and verification of operation integrity. By combining these functions within the secure zone, the system ensures that cryptographic operations maintain security and integrity while still achieving productivity through hardware-accelerated cryptographic processing.
3Reliability
If persistent storage is made highly secure with restricted modifications, then security against unauthorized access is improved, but ease of operation and flexibility deteriorates
Solution Approach 1:
Different quality levels of security are applied to different storage zones. The persistent storage within the secure protection zone has high security with restricted modifications, while the ephemeral memory in the non-secure zone allows temporary storage and modification of data during operations. This local differentiation of security qualities allows the system to maintain both high protection for cryptographic keys and operational flexibility for temporary data.
Data Source
AI summary
An integrated circuit device comprises a processor and a secure protection zone with security properties that can be verified by a remote device communicating with the integrated circuit device. The secure protection zone includes a persistent storage that is configured for storing cryptographic keys and data. The secure protection zone also includes instructions that are configured for causing the processor to perform cryptographic operations using the cryptographic keys. In addition, the secure protection zone includes an ephemeral memory that is configured for storing information associated with the cryptographic operations. The instructions are configured for causing the processor to perform the cryptographic operations on the data stored in the persistent storage and the information in the ephemeral memory as part of a secure communication exchange with the remote device.


