Security Chip Child Key Generation for Cryptographic Integrity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing key processing methods fail to guarantee the integrity of cryptographic algorithm firmware and the credibility of cryptographic operation execution environments during high-speed cryptographic operations in trusted platform control modules.
Innovation Solution
A security chip generates a child key based on a platform measurement root key and a random number, which is used to encrypt loading and execution processes measured by a dynamic measurement module, ensuring the integrity and credibility of cryptographic operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If a non-cryptographic operation is used to dynamically measure a relevant key, then the measurement speed is improved, but the integrity of cryptographic algorithm firmware and credibility of execution environment cannot be guaranteed
Solution Approach 1:
The patent introduces a measurement key as an intermediary element that bridges the gap between fast non-cryptographic measurement operations and cryptographic security requirements. The measurement key is used to encrypt measurement data, allowing rapid measurement while maintaining cryptographic integrity. This mediator enables the system to achieve both high-speed measurement and reliable integrity verification without compromising either aspect.
2Productivity
If existing key processing methods are used in trusted high-speed encryption cards, then cryptographic operation speed is improved, but the integrity of cryptographic algorithm firmware and credibility of execution environment cannot be guaranteed
Solution Approach 1:
The patent applies preliminary action by generating and storing measurement keys in advance during platform initialization, before cryptographic operations commence. The measurement keys are pre-computed and securely stored in the trusted platform module, enabling subsequent high-speed cryptographic measurements without compromising security. This preliminary preparation allows the system to maintain both high productivity and reliability during actual cryptographic operations.
Solution Approach 2:
The measurement key serves as a mediator that enables high-speed cryptographic operations while guaranteeing firmware integrity and execution environment credibility. By using the measurement key to encrypt and protect measurement data, the system achieves both fast cryptographic processing and reliable security verification simultaneously.
Data Source
AI summary
Key processing methods and apparatuses, storage media, and processors are disclosed. A method includes: a security chip receiving a dynamic measurement request for a cryptographic operation; and the security chip generating a child key of a platform measurement root key based on the platform measurement root key and a random number, wherein the child key of the platform measurement root key is used for encrypting a loading process and an execution process measured by a dynamic measurement module, and the dynamic measurement module is a module used for measuring a firmware that performs cryptographic operations. The present disclosures solves the technical problems that existing key processing methods cannot guarantee the integrity of cryptographic operation algorithm firmware and the credibility of cryptographic operation execution environments during a cryptographic operation process.


