IP Library Granted Patent US 11,797,683
Granted Patent B2
US 11,797,683 · App. 17/382,333 · Granted Oct 24, 2023

Security chip with resistance to external monitoring attacks

Inventors: Paul C. Kocher (San Francisco, CA); Pankaj Rohatgi (Los Altos, CA); Joshua M. Jaffe (San Francisco, CA)
Assignee: Cryptography Research, Inc.
G06F21/575G06F8/71G06F9/44505G06F12/1408G06F21/556G06F21/602G06F21/76H04L9/003H04L9/0631H04L9/085H04L9/088H04L9/0861H04L9/0894H04L9/16H04L9/3236H04L9/3247H04L9/3271G06F21/755G06F2212/402G06F2221/034G06F2221/2107G06F2221/2125G06F2221/2145H04L9/50H04L63/0428H04L63/0869H04L2209/24H04L2209/56H04L2463/061
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,797,683
App. No.
17/382,333
Granted
Oct 24, 2023
Kind
B2
Abstract

A method for performing a security chip protocol comprises receiving, by processing hardware of a security chip, a message from a first device as part of performing the security chip protocol. The processing hardware retrieves a secret value from secure storage hardware operatively coupled to the processing hardware. The processing hardware determines a path through a key tree based at least in part on the message. The processing hardware derives a validator at least in part from the secret value using a sequence of entropy redistribution operations associated with the path through the key tree. The processing hardware exchanges the validator between the security chip and the first device as part of the security chip protocol in order to authenticate at least one of the security chip or the first device.

Claims (43)

1. A method for performing a security chip protocol, the method comprising:

receiving, by processing hardware of a security chip, a message from a first device as part of performing the security chip protocol;

retrieving, by the processing hardware, a secret value from secure storage hardware operatively coupled to the processing hardware;

determining a path through a key tree based at least in part on the message, wherein the key tree comprises a plurality of nodes and one or more branches connected to each of the plurality of nodes, wherein each of the plurality of nodes are associated with a key and each of the one or more branches are associated with an entropy redistribution operation that, when applied to the key, generates an associated derived key;

deriving, by the processing hardware, a validator at least in part from the secret value using a sequence of entropy redistribution operations and corresponding derived keys associated with the path through the key tree; and

exchanging the validator between the security chip and the first device as part of the security chip protocol in order to authenticate at least one of the security chip or the first device.

2. The method of claim 1 , wherein the message comprises a message identifier, and wherein the path is determined based at least in part on the message identifier.

3. The method of claim 2 , wherein the path comprises a plurality of portions, the method further comprising:

decomposing the message identifier into a plurality of parts; and

determining each portion of the plurality of portions of the path using one of the plurality of parts of the message identifier.

4. The method as in claim 3 , wherein each portion of the plurality of portions of the path is associated with a distinct entropy redistribution operation.

5. The method as in claim 1 , further comprising:

generating an expected response by the first device;

comparing, at the first device, the validator to the expected response;

determining, by the first device, whether the validator matches the expected response; and

verifying at the first device that the security chip is authentic responsive to the validator matching the expected response.

6. The method of claim 1 , wherein the security chip protocol corresponds to performing a secure transaction, and wherein the message comprises transaction data.

7. The method of claim 1 , wherein the first device comprises at least one of a subscriber identity module (SIM) card or a transit pass.

8. The method of claim 1 , wherein the security chip protocol corresponds to at least one of an authentication procedure between a set-top box and the security chip, a verification procedure for a network login, or access to one or more television signals.

9. A security chip, comprising:

secure storage hardware to store a secret value; and

processing hardware operatively coupled to the secure storage hardware, wherein the processing hardware is to:

receive a message from a first device as part of a security chip protocol;

retrieve the secret value from the secure storage hardware;

determine a path through a key tree based at least in part on the message, wherein the key tree comprises a plurality of nodes and one or more branches connected to each of the plurality of nodes, wherein each of the plurality of nodes are associated with a key and each of the one or more branches are associated with an entropy redistribution operation that, when applied to the key, generates an associated derived key;

derive a validator at least in part from the secret value using a sequence of entropy redistribution operations and corresponding derived keys associated with the path through the key tree; and

provide the validator to the first device as part of the security chip protocol in order to authenticate at least one of the security chip or the first device.

10. The security chip of claim 9 , wherein the message comprises a message identifier, and wherein the path comprises a plurality of portions and is determined based at least in part on the message identifier, wherein the processing hardware is further to:

decomposing the message identifier into a plurality of parts; and

determining each portion of the plurality of portions of the path using one of the plurality of parts of the message identifier.

11. The security chip of claim 9 , wherein the security chip protocol corresponds to performing a secure transaction, and wherein the message comprises transaction data.

12. The security chip of claim 9 , wherein the first device comprises at least one of a subscriber identity module (SIM) card or a transit pass.

13. The security chip of claim 9 , wherein the security chip protocol corresponds to at least one of an authentication procedure between a set-top box and the security chip, a verification procedure for a network login, or access to one or more television signals.

14. A system comprising:

a security chip comprising secure storage hardware and processing hardware operatively coupled to the secure storage hardware, wherein the secure storage hardware is to store a secret value and the processing hardware is to:

receive a message from a first device as part of a security chip protocol;

retrieve the secret value from the secure storage hardware;

determine a path through a key tree based at least in part on the message, wherein the key tree comprises a plurality of nodes and one or more branches connected to each of the plurality of nodes, wherein each of the plurality of nodes are associated with a key and each of the one or more branches are associated with an entropy redistribution operation that, when applied to the key, generates an associated derived key;

derive a validator at least in part from the secret value using a sequence of entropy redistribution operations and corresponding derived keys associated with the path through the key tree; and

exchange the validator between the first device security chip and the first device as part of the security chip protocol in order to authenticate at least one of the security chip or the first device.

15. The system of claim 14 , wherein the security chip protocol corresponds to performing a secure transaction, and wherein the message comprises transaction data.

16. The system of claim 14 , wherein the first device comprises at least one of a subscriber identity module (SIM) card or a transit pass.

17. The system of claim 14 , wherein the security chip protocol corresponds to at least one of an authentication procedure between a set-top box and the security chip, a verification procedure for a network login, or access to one or more television signals.

Continuity (8)
Continuation 16240671 · Jan 4, 2019
Continuation 15395809 · Dec 30, 2016
Continuation 14617437 · Feb 9, 2015
Continuation 14201539 · Mar 7, 2014
Continuation 13762703 · Feb 8, 2013
Continuation 12958570 · Dec 2, 2010
Provisional Application 61266948 · Dec 4, 2009
Related Publication 20220083665A1 · Mar 17, 2022
Cited By (1)
US 12,470,369