Security Processor Memory Isolation for Secure Data Processing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Security processors with read-only memory, random access memory, and cryptographic functions face challenges in maintaining the integrity of executed programs and authenticating administrators, as they often store external programs or data, compromising security.
Innovation Solution
The security processor does not include any additional storage memory, with external storage isolated from the execution system, using a public key for initial administrator authentication and monotonic counters for incremental operations, and an external memory for secure data processing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the security processor stores external programs or data in its memory, then the functionality and adaptability are improved, but the security integrity and protection against unauthorized access deteriorate
Solution Approach 1:
The patent extracts the storage function from the security processor by introducing a separate external memory component. The security processor no longer stores external programs or data internally, but instead accesses them through the external memory via controlled interfaces. This separation ensures that the security processor's internal memory remains dedicated to secure execution contexts, eliminating the risk of stored external data compromising security integrity.
Solution Approach 2:
The system is segmented into distinct functional components: the security processor handles secure computation and authentication, while the external memory handles data and program storage. This segmentation allows each component to optimize for its specific function without compromising the other, with the security processor maintaining control over access to external memory through authentication mechanisms.
2Productivity
If the security processor includes additional storage memory for external data, then the data processing capability is improved, but the vulnerability to data tampering and unauthorized access increases
Solution Approach 1:
The external memory acts as an intermediary between the security processor and the stored data. Access to external memory is not direct but is mediated through authentication mechanisms and controlled interfaces managed by the security processor. This intermediary layer ensures that only authenticated operations can access external data, preventing unauthorized tampering while maintaining data processing capability.
3Reliability
If the security processor separates the execution system from stored data, then the security integrity is improved, but the device complexity increases
Solution Approach 1:
The external memory is designed with multi-functionality, serving both as a storage device for programs and data, and as an authenticated interface for the security processor. This universal component handles multiple functions (storage, retrieval, authentication) through a single integrated design, reducing the need for separate dedicated components and thereby limiting the increase in overall device complexity.
Data Source
AI summary
Devices and methods for executing instructions in an automatic and secure manner include a security processor having at least a read-only memory, a random access memory, a computer capable of performing cryptographic functions, a monotonic counter management unit associated with one or more monotonic counters, is such that it does not include any other storage memory, meaning that the security processor does not store any program or external data, a public key allowing at least one initial enrolled administrator to be authenticated is stored before the first use of same in its read-only memory, its random access memory is capable of loading a set of data and instructions that can be authenticated by a public key cryptographic module, the execution by the computer, after the authentication of same, of certain instructions, increments one of the monotonic counters.


