IP Library Granted Patent US 8,929,544
Granted Patent B2
US 8,929,544 · App. 13/853,880 · Granted Jan 6, 2015

Scalable and secure key management for cryptographic data processing

Inventors: Mark Buer (Payson, AZ); Zheng Qi (San Jose, CA)
Assignee: Broadcom Corporation
H04L9/0822G06F21/602H04L9/083H04L9/3228H04L9/3234
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,929,544
App. No.
13/853,880
Granted
Jan 6, 2015
Kind
B2
Abstract

A method and system for secure and scalable key management for cryptographic processing of data is described herein. In the method, a General Purpose Cryptographic Engine (GPE) receives key material via a secure channel from a key server and stores the received Key encryption keys (KEKs) and/or plain text keys in a secure key cache. When a request is received from a host to cryptographically process a block of data, the requesting entity is authenticated using an authentication tag included in the request. The GPE retrieves a plaintext key or generate a plaintext using a KEK if the authentication is successful, cryptographically processes the data using the plaintext key and transmits the processed data. The system includes a key server that securely provides encrypted keys and/or key handles to a host and key encryption keys and/or plaintext keys to the GPE.

Claims (24)

1. A method of secure key handling and cryptographic processing of data, comprising:

receiving a request in a cryptography engine from an entity to cryptographically process a block of data, the request including a key handle having an authentication tag and an index;

authenticating the requesting entity using the authentication tag;

referencing a key from a plurality of keys using the index if the requesting entity is authenticated successfully;

cryptographically processing the block of data using the key; and

transmitting the processed data.

2. The method of claim 1 wherein authenticating further comprises using a shared secret to authenticate the requesting entity.

3. The method of claim 2 , wherein authenticating further comprises decrypting the key handle using the shared secret.

4. The method of claim 1 , wherein authenticating further comprises using a one-time password to authenticate the requesting entity.

5. The method of claim 1 , further comprising, prior to receiving a request to cryptographically process data, receiving the plurality of keys via a secure communications channel from a key server.

6. The method of claim 5 , further comprising storing the received keys in a secure key cache.

7. The method of claim 1 , wherein the authentication tag is assigned by a server.

8. A general purpose cryptographic engine (GPE) for secure key management and cryptographic processing of data, comprising:

a secure memory configured to store a plurality of keys;

a security processing unit configured to receive a request from a requesting entity to cryptographically process a block of data, the request including a key handle, wherein the key handle includes an authentication tag and an index that enables retrieval of a key from the secure memory; and

a key manager coupled to the security processing unit and configured to authenticate the requesting entity based on the authentication tag and to retrieve the key based on the index if the host is authenticated successfully;

wherein the security processing unit is further configured to cryptographically process the block of data using the retrieved key and to transmit the processed data.

9. The GPE of claim 8 , wherein the GPE and the requesting, entity are on the same device.

10. The GPE of claim 8 , wherein the key manager is configured to authenticate the requesting entity using a shared secret.

11. The GPE of claim 10 , wherein the key manager is configured to decrypt the key handle using the shared secret.

12. The GPE of claim 8 , further comprising a secure key cache coupled to the key manager and configured to store the retrieved key.

13. The GPE of claim 8 , wherein the key manager is configured to use a One-Time Password (OTP) to authorize release of the key and to increment one OTP.

14. The GPE of claim 13 , wherein the stored authentication tag is assigned by a server.

15. The GPE of claim 8 , wherein the key manager is further configured to enforce security policies.

Assignments (7)
CORRECTIVE ASSIGNMENT TO CORRECT THE PATENT NUMBER 9,385,856 TO 9,385,756 PREVIOUSLY RECORDED AT REEL: 47349 FRAME: 001. ASSIGNOR(S) HEREBY CONFIRMS THE MERGER. Recorded Mar 22, 2019
From: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
To: AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE. LIMITED
Reel/Frame 051144/0648 →
CORRECTIVE ASSIGNMENT TO CORRECT THE EFFECTIVE DATE PREVIOUSLY RECORDED ON REEL 047229 FRAME 0408. ASSIGNOR(S) HEREBY CONFIRMS THE THE EFFECTIVE DATE IS 09/05/2018. Recorded Oct 29, 2018
From: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
To: AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE. LIMITED
Reel/Frame 047349/0001 →
MERGER Recorded Oct 4, 2018
From: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
To: AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE. LIMITED
Reel/Frame 047229/0408 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Feb 3, 2017
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: BROADCOM CORPORATION
Reel/Frame 041712/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 1, 2017
From: BROADCOM CORPORATION
To: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
Reel/Frame 041706/0001 →
PATENT SECURITY AGREEMENT Recorded Feb 11, 2016
From: BROADCOM CORPORATION
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 037806/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 9, 2013
From: BUER, MARK; QI, ZHENG
To: BROADCOM CORPORATION
Reel/Frame 030385/0210 →
Continuity (2)
Continuation 12418967 · Apr 6, 2009
Related Publication 20130230165A1 · Sep 5, 2013