Virtualized Protected Storage via OS-Tagged Cryptographic Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cryptographic systems lack effective mechanisms for secure storage and access control of long-term secrets across multiple operating systems on a single device, leading to potential unauthorized access and performance bottlenecks due to hypervisor management.

Innovation Solution

The implementation of a cryptographic engine that tags binary large objects with operating system identifiers, enabling secure, virtualized protected storage by deriving encryption keys from master secret keys and key modifiers, including an operating system tag, to restrict access and allow direct interaction between guest operating systems and the cryptographic module without hypervisor oversight.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If cryptographic systems store long-term secrets in a single centralized location managed by the hypervisor, then security control is centralized, but performance bottlenecks occur and unauthorized access risks increase

Engineering Contradiction:
Improveaccess speedVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the centralized cryptographic storage into multiple virtualized storage units, each accessible by specific operating systems through unique identifiers. This segmentation allows parallel access by multiple OSes simultaneously, eliminating the performance bottleneck of centralized hypervisor-managed storage while maintaining security through isolated access paths.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces virtualized cryptographic storage as an intermediary layer between the hypervisor and operating systems. This intermediary provides direct access paths for authorized OSes to cryptographic secrets without requiring hypervisor mediation for each access operation, improving performance while the virtualization layer maintains security controls.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple operating systems share access to the same cryptographic secrets, then resource utilization improves, but unauthorized access risk increases

Engineering Contradiction:
Improvemulti-OS supportVSAvoidunauthorized access
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by assigning unique identifiers to different operating systems and using these identifiers to create distinct access paths to cryptographic storage. Each OS has customized access permissions tailored to its specific needs, allowing multiple OSes to share the cryptographic infrastructure while maintaining isolated, authorized access paths that prevent unauthorized cross-OS access.

Inventive Principle:
Principle #3Local quality

3Reliability

If the hypervisor manages all cryptographic operations for guest operating systems, then centralized control is maintained, but performance overhead increases

Engineering Contradiction:
ImprovecontrolVSAvoidperformance overhead
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent enables guest operating systems to directly access and manage their own cryptographic secrets through virtualized storage interfaces without requiring hypervisor intervention for each cryptographic operation. The hypervisor maintains initial control by establishing the virtualized storage structure and access permissions, but individual OSes then self-serve their cryptographic needs, eliminating the performance overhead of continuous hypervisor mediation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8572410B1Virtualized protected storage
Publication Date: 2013.10.29 NXP USA INC
  • US8572410B1 patent drawing
  • US8572410B1 patent drawing
  • US8572410B1 patent drawing

AI summary

Embodiments of an electronic circuit include a cryptographic engine which includes a key derivation function and encryption logic. The key derivation function combines a master secret key with a plurality of key modifiers including at least an operating system tag specific to an operating system, and derives an encryption key from the combined master secret key and plurality of key modifiers. The encryption logic is coupled to the key derivation function and encrypts data using the derived encryption key to generate a cryptographic binary large object (blob) for virtualized protected storage that is accessible only to the operating system specified by the operating system tag.