Split-Key Management Using Tamper-Triggered Volatile Memory Erasure
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing key management systems are vulnerable to attacks, as adversaries can exploit weaknesses in hardware components to access protected keys, necessitating a more secure solution to prevent unauthorized access and use of secret keys.
Innovation Solution
A computerized system with a processor and memory unit (PMU) stores a first secret key portion in a persistent memory module and a second portion in a 'hybrid' memory module powered independently, using an anti-tampering module to instantly erase the second key portion upon detection of tampering, rendering it undecipherable.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If hardware-based solutions (TPM, HSM) are used to store secret keys, then security and resistance to tampering are improved, but vulnerability to advanced attacks increases as adversaries constantly seek weaknesses in hardware components
Solution Approach 1:
The secret key is divided into two separate portions: the first portion is stored in a persistent memory module (TPM/HSM) while the second portion is stored in a volatile memory module. This segmentation ensures that even if one memory module is compromised, the other portion remains secure, thereby resolving the contradiction between hardware security and vulnerability to attacks.
Solution Approach 2:
A separate volatile memory module is introduced as an intermediary storage location for the second key portion. This intermediary component provides an additional layer of security by storing key material that can be easily erased, thus reducing the harmful effect of hardware vulnerabilities while maintaining overall key protection reliability.
2Device complexity
If a single memory module stores the complete secret key, then device complexity is reduced, but security against tampering and unauthorized access deteriorates
Solution Approach 1:
The secret key is segmented into two portions stored in different memory modules with different security characteristics. This segmentation increases key protection reliability without significantly increasing overall device complexity, as the memory modules are standard components that can be integrated into existing systems.
3Ease of operation
If the volatile memory module maintains power to preserve the second key portion, then key availability is improved, but the ability to instantly erase the key upon tampering detection deteriorates
Solution Approach 1:
The volatile memory module is designed to lose power automatically upon detection of tampering conditions, preparing the system in advance for key erasure. This preliminary action ensures that the second key portion can be instantly erased when needed, while still maintaining key availability during normal operation through its volatile storage capability.
Data Source
AI summary
A computerized system operatively powered by a first power source that includes a processor and memory unit (PMU) and a persistent memory module configured to store a first secret key portion. A “hybrid” memory module associated with the PMU and being configured to store a second secret key portion and further being operatively powered by a second power source independent of the first power source, thereby maintaining the second key portion, even when the first power source is disconnected from the computerized system. An anti-tampering module configured to detect tampering with the computerized system, and. in response. generate a power disconnect signal for disconnecting the second power source from the “hybrid” memory module, thereby instantaneously erasing the second secret key portion which will result in an undecipherable secret key.


