IP Library Granted Patent US 8,379,846
Granted Patent B2
US 8,379,846 · App. 12/469,868 · Granted Feb 19, 2013

Encryption apparatus and method therefor

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,379,846
App. No.
12/469,868
Filed
May 21, 2009
Granted
Feb 19, 2013
Kind
B2
Art Unit
2615
USPC
380/44
Abstract

An encryption apparatus ( 14 ) includes an integrated circuit ( 34 ) having a secure processing section ( 30 ). A plaintext reset epoch key ( 154 ) is stored in the secure processing section ( 30 ) and configured to have a short life. A plaintext master key ( 160 ) is stored in the secure processing section ( 30 ) and configured to have a long life. A multiplicity of active keys ( 172 ) are generated, encrypted using a weaker but faster cryptographic algorithm ( 68 ) and the reset epoch key ( 154 ), then stored in a high-capacity key magazine ( 86 ) portion of unsecured memory ( 16, 18, 28 ). Some keys and data are also encrypted using a stronger but slower cryptographic algorithm ( 70 ) and the master key ( 160 ), then stored in unsecured memory ( 16, 18, 28 ). Keys ( 272, 372 ) may be converted between weaker, faster encryption and stronger, slower encryption.

Claims (55)

1. An encryption apparatus having a reset port at which a reset signal is applied, said apparatus comprising:

a memory for storing a first ciphertext key;

a first key register, configured as a volatile register, for storing a first plaintext key;

a second key register for storing a second plaintext key;

a third key register, configured as a non-volatile register, for storing a third plaintext key;

an encryption processor coupled to said first, second, and third key registers;

a random number generator coupled to said first key register; and

a controller coupled to said random number generator, said memory, and said encryption processor, said encryption processor and said controller being configured to cause said first plaintext key to be formed using said random number generator and stored in said first key register in response to activation of said reset signal, configured to cause said second plaintext key to be generated by said encryption processor from said first ciphertext key using said first plaintext key and to be stored in said second key register, configured to apply first and second cryptographic algorithms, wherein said first cryptographic algorithm requires more processing time than said second cryptographic algorithm, said first cryptographic algorithm being applied using said third plaintext key, and said second cryptographic algorithm being applied using said first plaintext key, and configured to convert said first ciphertext key into a second ciphertext key using said second then said first cryptographic algorithms to allow said second plaintext key to be recoverable after said activation of said reset signal.

2. An encryption apparatus as claimed in claim 1 wherein said second cryptographic algorithm and said first plaintext key are applied to said first ciphertext key to generate said second plaintext key.

3. An encryption apparatus as claimed in claim 1 wherein said second cryptographic algorithm includes an encryption process and a decryption process which is complimentary to said encryption process, said decryption process being configured to execute in the same or less processing time than said encryption process.

4. An encryption apparatus having a reset port at which a reset signal is applied, said apparatus comprising:

a memory for storing a first ciphertext key;

a first key register, configured as a volatile register, for storing a first plaintext key;

a second key register for storing a second plaintext key;

a third key register, configured as a non-volatile register, for storing a third plaintext key;

an encryption processor coupled to said first and second key registers;

a random number generator coupled to said first key register; and

a controller coupled to said random number generator, said memory, and said encryption processor, said encryption processor and said controller being configured to cause said first plaintext key to be formed using said random number generator and stored in said first key register in response to activation of said reset signal, configured to cause said second plaintext key to be generated by said encryption processor from said first ciphertext key using said first plaintext key and to be stored in said second key register, configured to apply first and second cryptographic algorithms, wherein said first cryptographic algorithm requires more processing time than said second cryptographic algorithm, said first cryptographic algorithm being applied using said third plaintext key, and said second cryptographic algorithm being applied using said first plaintext key, configured to form a second ciphertext key using said first cryptographic algorithm, and configured to convert said first ciphertext key into said second plaintext key using said second cryptographic algorithm.

5. An encryption apparatus as claimed in claim 1 additionally comprising a tamper detection circuit coupled to said first key register and configured to destroy said first plaintext key upon the detection of a tamper event.

6. An encryption apparatus as claimed in claim 1 wherein:

said first key register, said second key register, said random number generator, and said controller reside within an integrated circuit; and

said memory resides outside said integrated circuit.

7. An encryption apparatus as claimed in claim 1 wherein:

said first key register, said second key register, said encryption processor, and said random number generator are located in a secure processing section of said encryption apparatus; and

said memory resides outside said secure processing section.

8. An encryption apparatus as claimed in claim 1 wherein said controller is further configured to:

generate, after said first plaintext key is stored in said first key register, an original second plaintext key;

encrypt said original second plaintext key using said first plaintext key to form said first ciphertext key; and

store said first ciphertext key in said memory.

9. An encryption apparatus as claimed in claim 1 wherein said first key register is configured so that said first plaintext key is destroyed in response to a power-off event.

10. An encryption apparatus as claimed in claim 1 wherein said first key register is configured so that said first plaintext key is destroyed in response to a reset event.

11. An encryption apparatus as claimed in claim 1 wherein said first key register is configured so that said first plaintext key is destroyed in response one of a power-off event, a reset event, and a temper event.

12. An encryption apparatus having a reset port at which a reset signal is applied, said apparatus comprising:

a memory for storing a ciphertext key;

a first key register, configured as a volatile register, for storing a first plaintext key;

a second key register for storing a second plaintext key;

a third key register, configured as a non-volatile register, for storing a third plaintext key;

an encryption processor coupled to said first and second key registers;

a random number generator coupled to said first key register; and

a controller coupled to said random number generator, said memory, and said encryption processor, said encryption processor and said controller being configured to cause said first plaintext key to be formed using said random number generator and stored in said first key register in response to activation of said reset signal, configured to cause said second plaintext key to be generated by said encryption processor from said ciphertext key using said first plaintext key and to be stored in said second key register, configured to apply first and second cryptographic algorithms, wherein said first cryptographic algorithm requires more processing time than said second cryptographic algorithm, said first cryptographic algorithm being applied using said third plaintext key, and said second cryptographic algorithm being applied using said first plaintext key, configured to encrypt said second plaintext key using said first cryptographic algorithm and said third plaintext key to form an alternate ciphertext key, and configured to store said alternate ciphertext key in said memory to allow said second plaintext key to be recoverable after a reset.

13. An encryption apparatus having a reset port at which a reset signal is applied, said apparatus comprising:

a memory for storing a first ciphertext key;

a first key register, configured as a volatile register, for storing a first plaintext key;

a second key register for storing a second plaintext key;

a third key register, configured as a non-volatile register, for storing a third plaintext key;

an encryption processor coupled to said first and second key registers;

a random number generator coupled to said first key register; and

a controller coupled to said random number generator, said memory, and said encryption processor, said encryption processor and said controller being configured to cause said first plaintext key to be formed using said random number generator and stored in said first key register in response to activation of said reset signal, configured to cause said second plaintext key to be generated by said encryption processor from said first ciphertext key using said first plaintext key and to be stored in said second key register, configured to apply first and second cryptographic algorithms, wherein said first cryptographic algorithm requires more processing time than said second cryptographic algorithm, said first cryptographic algorithm being applied using said third plaintext key, and said second cryptographic algorithm being applied using said first plaintext key, configured to generate, before said first plaintext key is stored in said first key register, an original second plaintext key, configured to encrypt

said original second plaintext key using said first cryptographic algorithm and said third plaintext key to form an alternate ciphertext key, configured to store said alternate ciphertext key in said memory, and configured to convert, after said first plaintext key is stored in said first key register, said alternate ciphertext key into said second ciphertext key using said first cryptographic algorithm and said third plaintext key then said second cryptographic algorithm and said first plaintext key.

14. An encryption apparatus as claimed in claim 12 wherein said second cryptographic algorithm is also applied to said ciphertext key.

15. An encryption apparatus as claimed in claim 1 wherein said first ciphertext key is one of a multiplicity of ciphertext keys stored in a key magazine formed in said memory.

16. An encryption apparatus as claimed in claim 4 wherein said first key register is configured so that said first plaintext key is destroyed in response one of a power-off event, a reset event, and a temper event.

17. An encryption apparatus as claimed in claim 13 wherein said second cryptographic algorithm and said first plaintext key are applied to said first ciphertext key to generate said second plaintext key.

18. An encryption apparatus as claimed in claim 12 wherein said second cryptographic algorithm and said first plaintext key are applied to said ciphertext key to generate said second plaintext key.

19. An encryption apparatus as claimed in claim 12 wherein said first key register is configured so that said first plaintext key is destroyed in response one of a power-off event, a reset event, and a temper event.

Assignments (14)
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 11759915 AND REPLACE IT WITH APPLICATION 11759935 PREVIOUSLY RECORDED ON REEL 040925 FRAME 0001. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Feb 17, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NXP, B.V. F/K/A FREESCALE SEMICONDUCTOR, INC.
Reel/Frame 052917/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 11759915 AND REPLACE IT WITH APPLICATION 11759935 PREVIOUSLY RECORDED ON REEL 040928 FRAME 0001. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Jan 17, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NXP B.V.
Reel/Frame 052915/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 11759915 AND REPLACE IT WITH APPLICATION 11759935 PREVIOUSLY RECORDED ON REEL 037486 FRAME 0517. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT AND ASSUMPTION OF SECURITY INTEREST IN PATENTS. Recorded Dec 10, 2019
From: CITIBANK, N.A.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 053547/0421 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12298143 PREVIOUSLY RECORDED ON REEL 038017 FRAME 0058. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded Oct 22, 2019
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 051030/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12298143 PREVIOUSLY RECORDED ON REEL 042985 FRAME 0001. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded Oct 22, 2019
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 051029/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12298143 PREVIOUSLY RECORDED ON REEL 039361 FRAME 0212. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded Oct 22, 2019
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 051029/0387 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12298143 PREVIOUSLY RECORDED ON REEL 042762 FRAME 0145. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded Oct 22, 2019
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 051145/0184 →
RELEASE OF SECURITY INTEREST Recorded Sep 10, 2019
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NXP B.V.
Reel/Frame 050745/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 10, 2019
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NXP B.V.
Reel/Frame 050744/0097 →
CORRECTIVE ASSIGNMENT TO CORRECT THE TO CORRECT THE APPLICATION NO. FROM 13,883,290 TO 13,833,290 PREVIOUSLY RECORDED ON REEL 041703 FRAME 0536. ASSIGNOR(S) HEREBY CONFIRMS THE THE ASSIGNMENT AND ASSUMPTION OF SECURITY INTEREST IN PATENTS.. Recorded Feb 20, 2019
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: SHENZHEN XINGUODU TECHNOLOGY CO., LTD.
Reel/Frame 048734/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE NATURE OF CONVEYANCE PREVIOUSLY RECORDED AT REEL: 040652 FRAME: 0241. ASSIGNOR(S) HEREBY CONFIRMS THE MERGER AND CHANGE OF NAME. Recorded Jan 5, 2017
From: FREESCALE SEMICONDUCTOR, INC.
To: NXP USA, INC.
Reel/Frame 041260/0850 →
MERGER Recorded Nov 8, 2016
From: FREESCALE SEMICONDUCTOR, INC.
To: NXP USA, INC.
Reel/Frame 040652/0241 →
RELEASE OF SECURITY INTEREST Recorded Nov 7, 2016
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NXP B.V.
Reel/Frame 040928/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 21, 2016
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NXP, B.V., F/K/A FREESCALE SEMICONDUCTOR, INC.
Reel/Frame 040925/0001 →