IP Library Granted Patent US 11,416,625
Granted Patent B2
US 11,416,625 · App. 16/963,724 · Granted Aug 16, 2022

Protecting cryptographic keys stored in non-volatile memory

Inventors: Mark Evan Marson (Carlsbad, CA); Michael A. Hamburg (San Francisco, CA)
Assignee: CRYPTOGRAPHY RESEARCH, INC.
G06F21/602G06F1/24G06F12/1408G06F21/79H04L9/0822H04L9/0894
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,416,625
App. No.
16/963,724
Granted
Aug 16, 2022
Kind
B2
Abstract

Systems and methods for protecting cryptographic keys stored in a non-volatile memory. An example method may comprise: storing a device root key in a non-volatile memory; storing a volatile key in a volatile memory; storing a masked cryptographic key in the non-volatile memory, wherein the masked cryptographic key is produced by combining a cryptographic key and the device root key; storing a masked device root key in the non-volatile memory, wherein the masked root key is produced by combining the device root key and the volatile key; and erasing the device root key from the non-volatile memory.

Claims (69)

1. A method, comprising:

storing a device root key in a non-volatile memory;

storing a volatile key in a volatile memory;

storing a masked cryptographic key in the non-volatile memory, wherein the masked cryptographic key is produced by combining a cryptographic key and the device root key;

storing a masked device root key in the non-volatile memory, wherein the masked device root key is produced by combining the device root key and the volatile key; and

erasing the device root key from the non-volatile memory.

2. The method of claim 1 , further comprising:

responsive to detecting a tampering event, erasing the volatile key from the volatile memory.

3. The method of claim 2 , wherein erasing the volatile key from the volatile memory further comprises at least one of:

sending a reset signal to the volatile memory or interrupting power supply to the volatile memory.

4. The method of claim 1 , further comprising:

restoring the device root key by combining the masked device root key and the volatile key;

restoring the cryptographic key by combining the masked cryptographic key and the device root key; and

utilizing the cryptographic key for performing a cryptographic data processing operation.

5. The method of claim 1 , wherein combining the cryptographic key and the device root key further comprises:

performing an exclusive disjunction operation of the cryptographic key and the device root key.

6. The method of claim 1 , wherein combining the device root key and the volatile key further comprises:

performing an exclusive disjunction operation of the device root key and the volatile key.

7. The method of claim 1 , further comprising:

receiving, from an external source, at least one of: the device root key, the volatile key, or the cryptographic key.

8. The method of claim 1 , further comprising:

generating at least one of: the device root key; the volatile key, or the cryptographic key.

9. A system comprising:

a non-volatile memory;

a volatile memory;

a voltage control circuit configured to interrupt power supply to the volatile memory responsive to receiving a signal indicating a tampering event; and

a processor configured to:

store a device root key in the non-volatile memory;

store a volatile key in the volatile memory;

store a masked cryptographic key in the non-volatile memory, wherein the masked cryptographic key is produced by combining a cryptographic key and the device root key;

store a masked device root key in the non-volatile memory, wherein the masked device root key is produced by combining the device root key and the volatile key; and

erase the device root key from the non-volatile memory.

10. The system of claim 9 , wherein the processor is further configured to:

restore the device root key by combining the masked device root key and the volatile key;

restore the cryptographic key by combining the masked cryptographic key and the device root key; and

utilize the cryptographic key for performing a cryptographic data processing operation.

11. The system of claim 9 , wherein combining the cryptographic key and the device root key further comprises:

performing an exclusive disjunction operation of the cryptographic key and the device root key.

12. A method, comprising:

storing a device root key in a non-volatile memory;

storing a masked cryptographic key in the non-volatile memory, wherein the masked cryptographic key is produced by combining a cryptographic key and the device root key;

storing the device root key in a volatile memory;

erasing the device root key from the non-volatile memory; and

responsive to detecting a tampering event, erasing the device root key from the volatile memory.

13. The method of claim 12 , wherein erasing the device root key from the volatile memory further comprises:

sending a reset signal to the volatile memory or interrupting power supply to the volatile memory.

14. The method of claim 12 , further comprising:

restoring the cryptographic key by combining the masked cryptographic key and the device root key; and

utilizing the cryptographic key for performing a cryptographic data processing operation.

15. The method of claim 12 , wherein combining the cryptographic key and the device root key further comprises:

performing an exclusive disjunction operation of the cryptographic key and the device root key.

16. The method of claim 12 , further comprising:

receiving, from an external source, at least one of: the device root key or the cryptographic key.

17. The method of claim 12 , further comprising:

generating at least one of: the device root key or the cryptographic key.

18. A system comprising:

a non-volatile memory;

a volatile memory;

a voltage control circuit configured to interrupt power supply to the volatile memory responsive to receiving a signal indicating a tampering event; and

a processor configured to:

store a device root key in the non-volatile memory;

store a masked cryptographic key in the non-volatile memory, wherein the masked cryptographic key is produced by combining a cryptographic key and the device root key;

store the device root key in the volatile memory; and

erase the device root key from the non-volatile memory.

19. The system of claim 18 , wherein the processor is further configured to:

restore the cryptographic key by combining the masked cryptographic key and the device root key; and

utilize the cryptographic key for performing a cryptographic data processing operation.

20. The system of claim 18 , wherein combining the cryptographic key and the device root key further comprises:

performing an exclusive disjunction operation of the cryptographic key and the device root key.

Continuity (3)
Provisional Application 62679317 · Jun 1, 2018
Provisional Application 62624694 · Jan 31, 2018
Related Publication 20210081547A1 · Mar 18, 2021