IP Library Granted Patent US 10,037,441
Granted Patent B2
US 10,037,441 · App. 14/702,791 · Granted Jul 31, 2018

Bus protection with improved key entropy

Inventors: Uri Kaluzhny (Beit Shemesh, IL); Nir Tasher (Tel Mond, IL)
Assignee: WINBOND ELECTRONICS CORPORATION
G06F21/85G09C1/00H04L9/0861H04L9/0869H04L2209/125
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,037,441
App. No.
14/702,791
Granted
Jul 31, 2018
Kind
B2
Abstract

An apparatus includes a processor and a bus encryption unit. The processor is configured to communicate information over a secured data bus, and to communicate respective addresses over an address bus. The bus encryption unit is configured to generate an encryption key based on multiple addresses that appeared on the address bus, and to encrypt the information communicated between the processor and the secured data bus with the encryption key.

Claims (27)

1. Apparatus, comprising:

a first processor, which is configured to communicate information over a secured data bus, and to communicate respective addresses having respective address values over an address bus; and

logic circuitry, which is coupled to the secured data bus and to the address bus, and which is configured to:

calculate an encryption key whose entropy stems from an amount of randomness conveyed by a sequence of multiple address values that appeared on bus lines of the address bus, by applying a logic operation to the multiple address values in the sequence;

encrypt, using the encryption key, information originating in the first processor and destined to a second processor that is coupled to the secured data bus; and

send the encrypted information to the second processor over the secured data bus.

2. The apparatus according to claim 1 , wherein the first processor is configured to randomly halt execution of instructions therein so as to introduce randomness in the address values appearing on the bus lines of the address bus.

3. The apparatus according to claim 2 , and comprising a Random Number Generator (RNG), which is configured to generate random numbers, wherein the first processor is configured to randomly halt the execution based on the random numbers generated by the RNG.

4. The apparatus according to claim 1 , wherein the logic circuitry comprises a Linear Feedback Shift Register (LFSR) that is configured to apply the logic operation to the multiple address values in the sequence so as to generate the encryption key.

5. The apparatus according to claim 4 , wherein the logic circuitry is configured to initialize the LFSR with a random value.

6. The apparatus according to claim 4 , wherein the logic circuitry is configured to initialize the LFSR with a predefined initial value, and to start encrypting the information using the encryption key only after shifting the shift register a predefined number of positions.

7. The apparatus according to claim 1 , wherein the second processor is coupled to the secured data bus using another logic circuitry, which is configured to calculate a decryption key that matches the encryption key by applying the logic operation to the multiple address values in the sequence, to decrypt the encrypted information using the decryption key, and to deliver the decrypted information to the second processor.

8. The apparatus according to claim 7 , wherein the logic circuitry and the other logic circuitry are configured to generate the encryption and decryption keys in synchronization with one another.

9. The apparatus according to claim 1 , wherein the logic circuitry is configured to update the encryption key so that the information communicated before and after updating is encrypted using respective different encryption keys.

10. A method, comprising:

communicating information by a first hardware processor over a secured data bus, and communicating respective addresses having respective address values over an address bus;

calculating an encryption key whose entropy stems from an amount of randomness conveyed by a sequence of multiple address values that appeared on bus lines of the address bus, by applying a logic operation to the multiple address values in the sequence;

encrypting, using the encryption key, information originating in the first processor and destined to a second processor that is coupled to the secured data bus; and

sending the encrypted information to the second processor over the secured data bus.

11. The method according to claim 10 , wherein calculating the encryption key comprises randomly halting execution of instructions by the first hardware processor so as to introduce randomness in the address values appearing on the bus lines of the address bus.

12. The method according to claim 11 , wherein randomly halting the execution comprises halting the execution based on random numbers generated by a Random Number Generator (RNG).

13. The method according to claim 10 , wherein calculating the encryption key comprises applying the logic operation to the multiple address values in the sequence using a Linear Feedback Shift Register (LFSR).

14. The method according to claim 13 , wherein calculating the encryption key comprises initializing the LFSR with a random value.

15. The method according to claim 13 , wherein calculating the encryption key comprises initializing the LFSR with a predefined initial value, and starting encrypting the information using the encryption key only after shifting the LFSR a predefined number of positions.

16. The method according to claim 10 , wherein the second processor is coupled to the secured data bus using logic circuitry, and comprising calculating, using the logic circuitry, a decryption key that matches the encryption key by applying the logic operation to the multiple address values in the sequence, decrypting the encrypted information using the decryption key, and delivering the decrypted information to the second processor.

17. The method according to claim 16 , wherein calculating the encryption and decryption keys comprises calculating the encryption and decryption keys synchronously.

18. The method according to claim 10 , wherein calculating the encryption key comprises updating the encryption key so that the information communicated before and after updating is encrypted using respective different encryption keys.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 4, 2015
From: KALUZHNY, URI; TASHER, NIR
To: WINBOND ELECTRONICS CORPORATION
Reel/Frame 035552/0235 →
Priority Claims (1)
IL 234956 · Oct 2, 2014 · national
Continuity (1)
Related Publication 20160098580A1 · Apr 7, 2016
Cited By (2)
US 12,452,044 US 12,536,122