IP Library Granted Patent US 11,451,378
Granted Patent B2
US 11,451,378 · App. 17/024,501 · Granted Sep 20, 2022

Device and method for encryption

Inventors: Benjamin Baratte (Montrouge, FR); Laurent Halajko (Palaiseau, FR)
Assignee: STMICROELECTRONICS SA
H04L9/0825H04L9/0822H04L9/0841H04L9/0894H04L9/14
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,451,378
App. No.
17/024,501
Granted
Sep 20, 2022
Kind
B2
Abstract

An embodiment encryption method, implemented by an electronic circuit including a first non-volatile memory, comprises the creation of one or more first pairs of asymmetrical keys, the first pair or each of the first pairs comprising first private and public keys, and, for the or at least one of the first pairs, storing the first public key in the first memory, receiving a second public key during a communication session, and forming a first symmetrical key from the first private key and the second public key, the first public key staying stored in the first memory after the communication session.

Claims (53)

1. An encryption method implemented by an electronic circuit including a first non-volatile memory, the method comprising:

creating a first pair of asymmetrical keys including a first private key and a first public key;

storing the first public key in the first non-volatile memory;

receiving a second public key during a communication session;

forming a first symmetrical key from the first private key and the second public key during the communication session;

erasing the first private key after forming the first symmetrical key and before the communication session ends; and

ending the communication session, the first public key remaining stored in the first non-volatile memory after the communication session ends.

2. The method according to claim 1 , further comprising forming at least one second symmetrical key from the first private key and the second public key.

3. The method according to claim 2 , further comprising forming the first and second symmetrical keys from a seed formed from the first private key and the second public key.

4. The method according to claim 3 , further comprising storing, in the first non-volatile memory, the seed and the first symmetrical key.

5. The method according to claim 4 , further comprising encrypting the stored seed and first symmetrical keys with an internal key internal to the electronic circuit.

6. The method according to claim 2 , further comprising storing the first symmetrical key in another memory that is volatile and/or configured to be erased in response to an attack being detected.

7. The method according to claim 1 , further comprising storing data, encrypted by the first symmetrical key, in a second nonvolatile memory.

8. The method according to claim 1 , further comprising encrypting communications internal to the electronic circuit with an additional symmetrical key.

9. The method according to claim 8 , further comprising:

encrypting the additional symmetrical key with the first private key; and

storing the encrypted additional symmetrical key in the first non-volatile memory.

10. The method according to claim 8 , wherein the first non-volatile memory is readable only by a holder of the additional symmetrical key and/or an administrator.

11. The method according to claim 10 , wherein the first non-volatile memory is readable by the administrator using a third private key.

12. The method according to claim 1 , further comprising storing, by the electronic circuit, the first public key in signed form.

13. The method according to claim 1 , wherein the second public key is from a second pair of asymmetrical keys comprising a second private key, and the first symmetrical key is deduce-able from the second private key and the first public key.

14. The method according to claim 13 , further comprising obtaining the first and second pairs of asymmetrical keys using a Diffie-Hellman algorithm.

15. The method according to claim 13 , further comprising:

reading, by an administrator having a third private key, the first public key of the first pair of asymmetrical keys;

sending the first public key of the first pair of asymmetrical keys to a holder of the second private key; and

deducing the first symmetrical key from the first public key and the second private key.

16. An electronic circuit comprising:

a first non-volatile memory; and

a data processing circuit coupled to the first non-volatile memory, the data processing circuit configured to:

create a first pair of asymmetrical keys including a first private key and a first public key;

store the first public key in the first non-volatile memory;

receive a second public key during a communication session;

form a first symmetrical key from the first private key and the second public key during the communication session;

erase the first private key after forming the first symmetrical key and before the communication session ends; and

end the communication session, wherein the first public key remains stored in the first non-volatile memory after the communication session ends.

17. The electronic circuit according to claim 16 , wherein the data processing circuit is configured to form at least one second symmetrical key from the first private key and the second public key.

18. The electronic circuit according to claim 17 , wherein the data processing circuit is further configured to form the first and second symmetrical keys from a seed formed from the first private key and the second public key.

19. The electronic circuit according to claim 16 , wherein the data processing circuit is configured to encrypt communications internal to the electronic circuit with an additional symmetrical key.

20. The electronic circuit according to claim 16 , further comprising another memory that is volatile and/or configured to be erased in response to an attack being detected;

wherein the data processing circuit is further configured to store the first symmetrical key in the another memory.

21. The electronic circuit according to claim 16 , further comprising a second nonvolatile memory;

wherein the data processing circuit is further configured to store data, encrypted by the first symmetrical key, in the second nonvolatile memory.

22. A system comprising:

an electronic circuit comprising:

a first non-volatile memory; and

a data processing circuit coupled to the first non-volatile memory, the data processing circuit configured to:

create a first pair of asymmetrical keys including a first private key and a first public key;

store the first public key in the first non-volatile memory;

receive a second public key during a communication session;

form a first symmetrical key from the first private key and the second public key, wherein the first public key remains stored in the first non-volatile memory after the communication session, wherein the second public key is from a second pair of asymmetrical keys comprising a second private key, and wherein the first symmetrical key is deduce-able from the second private key and the first public key;

reading, by an administrator having a third private key, the first public key of the first pair of asymmetrical keys;

sending the first public key of the first pair of asymmetrical keys to a holder of the second private key; and

deducing the first symmetrical key from the first public key and the second private key.

Assignments (2)
CHANGE OF NAME Recorded Dec 8, 2023
From: STMICROELECTRONICS SA
To: STMICROELECTRONICS FRANCE
Reel/Frame 065835/0159 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 17, 2020
From: BARATTE, BENJAMIN; HALAJKO, LAURENT
To: STMICROELECTRONICS SA
Reel/Frame 053811/0928 →
Priority Claims (1)
FR 1910785 · Sep 30, 2019 · national
Continuity (1)
Related Publication 20210099291A1 · Apr 1, 2021
Cited By (2)
US 12,353,588 US 12,626,249