Secure key exchange using key-associated attributes
A method for secure key exchange. The method comprises receiving a request to certify a key from a communication partner at an interface between an access and tamper resistant circuit block and exposed circuitry. Within the access and tamper resistant circuit block, a first random private key is generated. A corresponding public key of the first random private key is derived, and a cryptographic digest of the public key and attributes associated with the first random private key is generated. The generated cryptographic digest is signed using a second random private key that has been designated for signing by one or more associated attributes. The public key and the signature are then sent to the communication partner via the interface.
1 . A method for a hardware enforced key register, comprising:
at an interface between an access and tamper resistant circuit block and exposed circuitry, receiving, from an external server, a request for a combined authorization key; and
within the access and tamper resistant circuit block:
based on the received request, retrieving two or more keys from key portions of the hardware enforced key register, each retrieved key generated within the access and tamper resistant circuit block, and retrieving associated key attributes for each retrieved key from attribute portions of the hardware enforced key register, each key attribute encoding one or more designated operations that can be performed on the retrieved key associated with the key attribute, wherein contents of the key portions of the hardware enforced key register are not readable in unencrypted form, and wherein contents of the attribute portions of the hardware enforced key register are readable in unencrypted form;
using a mixing algorithm, combining the two or more retrieved keys with attributes for the combined authorization key to generate the combined authorization key, wherein the associated key attributes for each key provide permission to combine using the mixing algorithm; and
storing the combined authorization key and associated key attributes for the combined authorization key in the hardware enforced key register.
2 . The method of claim 1 , wherein the mixing algorithm is a National Institute of Standards and Technology (NIST) compliant key derivation function.
3 . The method of claim 2 , wherein the mixing algorithm is applied to two retrieved keys to generate an intermediate authorization key, and wherein the mixing algorithm is applied to the intermediate authorization key and a third retrieved key to generate the combined authorization key.
4 . The method of claim 1 , wherein at least one of the two or more retrieved keys is provisioned based on a valid subscription to a subscription based service.
5 . The method of claim 1 wherein the received request is generated in response to a request to certify multi-authorization from different external entities associated with each key.
6 . The method of claim 1 , wherein the associated key attributes for the combined authorization key are based at least in part on the associated key attributes for one or more of the two or more retrieved keys.
7 . The method of claim 1 , wherein the associated key attributes for the combined authorization key are specific to the combined authorization key.
8 . A system comprising:
a processor;
memory storing instructions that, when executed, cause operations comprising:
receiving, from an external server and at an interface between an access and tamper resistant circuit block and exposed circuitry, a request for a combined authorization key; and
within the access and tamper resistant circuit block:
based on the received request, retrieving two or more keys from key portions of a hardware enforced key register, each retrieved key generated within the access and tamper resistant circuit block, and retrieving associated key attributes for each retrieved key from attribute portions of the hardware enforced key register, each key attribute encoding one or more designated operations that can be performed on the retrieved key associated with the key attribute, wherein contents of the key portions of the hardware enforced key register are not readable in unencrypted form, and wherein contents of the attribute portions of the hardware enforced key register are readable in unencrypted form;
using a mixing algorithm, combining the two or more retrieved keys with attributes for the combined authorization key to generate the combined authorization key, wherein the associated key attributes for each key provide permission to combine using the mixing algorithm; and
storing the combined authorization key and associated key attributes for the combined authorization key in the hardware enforced key register.
9 . The system of claim 8 , wherein the mixing algorithm is a National Institute of Standards and Technology (NIST) compliant key derivation function.
10 . The system of claim 9 , wherein the mixing algorithm is applied to two retrieved keys to generate an intermediate authorization key, and wherein the mixing algorithm is applied to the intermediate authorization key and a third retrieved key to generate the combined authorization key.
11 . The system of claim 8 , wherein at least one of the two or more retrieved keys is provisioned based on a valid subscription to a subscription based service.
12 . The system of claim 8 , wherein the received request is generated in response to a request to certify multi-authorization from different external entities associated with each key.
13 . The system of claim 8 , wherein the associated key attributes for the combined authorization key are based at least in part on the associated key attributes for one or more of the two or more retrieved keys.
14 . The system of claim 8 , wherein the associated key attributes for the combined authorization key are specific to the combined authorization key.
15 . A device comprising:
an interface between an access and tamper resistant circuit block and exposed circuitry; and
memory storing instructions that, when executed, cause operations comprising:
receiving, at the interface and from an external server, a request for a combined authorization key; and
within the access and tamper resistant circuit block:
based on the received request, retrieving two or more keys from key portions of a hardware enforced key register, each retrieved key generated within the access and tamper resistant circuit block, and retrieving associated key attributes for each retrieved key from attribute portions of the hardware enforced key register, each key attribute encoding one or more designated operations that can be performed on the retrieved key associated with the key attribute, wherein contents of the key portions of the hardware enforced key register are not readable in unencrypted form, and wherein contents of the attribute portions of the hardware enforced key register are readable in unencrypted form;
using a mixing algorithm, combining the two or more retrieved keys with attributes for the combined authorization key to generate the combined authorization key, wherein the associated key attributes for each key provide permission to combine using the mixing algorithm; and
storing the combined authorization key and associated key attributes for the combined authorization key in the hardware enforced key register.
16 . The device of claim 15 , wherein the mixing algorithm is a National Institute of Standards and Technology (NIST) compliant key derivation function.
17 . The device of claim 16 , wherein the mixing algorithm is applied to two retrieved keys to generate an intermediate authorization key, and wherein the mixing algorithm is applied to the intermediate authorization key and a third retrieved key to generate the combined authorization key.
18 . The device of claim 15 , wherein at least one of the two or more retrieved keys is provisioned based on a valid subscription to a subscription based service.
19 . The device of claim 15 , wherein the received request is generated in response to a request to certify multi-authorization from different external entities associated with each key.
20 . The device of claim 15 , wherein the associated key attributes for the combined authorization key are based at least in part on the associated key attributes for one or more of the two or more retrieved keys.