Security Processor Memory Isolation for Secure Data Processing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Security processors with read-only memory, random access memory, and cryptographic functions face challenges in maintaining the integrity of executed programs and authenticating administrators, as they often store external programs or data, compromising security.

Innovation Solution

The security processor does not include any additional storage memory, with external storage isolated from the execution system, using a public key for initial administrator authentication and monotonic counters for incremental operations, and an external memory for secure data processing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the security processor stores external programs or data in its memory, then the functionality and adaptability are improved, but the security integrity and protection against unauthorized access deteriorate

Engineering Contradiction:
ImprovefunctionalityVSAvoidsecurity integrity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent extracts the storage function from the security processor by introducing a separate external memory component. The security processor no longer stores external programs or data internally, but instead accesses them through the external memory via controlled interfaces. This separation ensures that the security processor's internal memory remains dedicated to secure execution contexts, eliminating the risk of stored external data compromising security integrity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system is segmented into distinct functional components: the security processor handles secure computation and authentication, while the external memory handles data and program storage. This segmentation allows each component to optimize for its specific function without compromising the other, with the security processor maintaining control over access to external memory through authentication mechanisms.

Inventive Principle:
Principle #1Segmentation

2Productivity

If the security processor includes additional storage memory for external data, then the data processing capability is improved, but the vulnerability to data tampering and unauthorized access increases

Engineering Contradiction:
Improvedata processing capabilityVSAvoidvulnerability to data tampering
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The external memory acts as an intermediary between the security processor and the stored data. Access to external memory is not direct but is mediated through authentication mechanisms and controlled interfaces managed by the security processor. This intermediary layer ensures that only authenticated operations can access external data, preventing unauthorized tampering while maintaining data processing capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the security processor separates the execution system from stored data, then the security integrity is improved, but the device complexity increases

Engineering Contradiction:
Improvesecurity integrityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The external memory is designed with multi-functionality, serving both as a storage device for programs and data, and as an authenticated interface for the security processor. This universal component handles multiple functions (storage, retrieval, authentication) through a single integrated design, reducing the need for separate dedicated components and thereby limiting the increase in overall device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11822795B2Secure data processing
Publication Date: 2023.11.21 LEDGER SAS
  • US11822795B2 patent drawing
  • US11822795B2 patent drawing
  • US11822795B2 patent drawing

AI summary

Devices and methods for executing instructions in an automatic and secure manner include a security processor having at least a read-only memory, a random access memory, a computer capable of performing cryptographic functions, a monotonic counter management unit associated with one or more monotonic counters, is such that it does not include any other storage memory, meaning that the security processor does not store any program or external data, a public key allowing at least one initial enrolled administrator to be authenticated is stored before the first use of same in its read-only memory, its random access memory is capable of loading a set of data and instructions that can be authenticated by a public key cryptographic module, the execution by the computer, after the authentication of same, of certain instructions, increments one of the monotonic counters.