IP Library Granted Patent US 7,542,567
Granted Patent B2
US 7,542,567 · App. 10/865,267 · Granted Jun 2, 2009

Method and apparatus for providing security in a data processing system

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,542,567
App. No.
10/865,267
Granted
Jun 2, 2009
Kind
B2
Abstract

One embodiment relates to a data processing system having a cryptographic unit. The cryptographic unit includes cryptographic circuitry which performs a first cryptographic function to provide security for a portion of the cryptographic unit, and which performs a second cryptographic function to provide security for a portion of the data processing system external to the cryptographic unit. The cryptographic unit may therefore operate in a normal operating mode and in a secure operating mode. During a first secure operating mode a first key is used to decrypt first security configuration information which includes a second key. During a second secure operating mode, the second key is used to decrypt second security configuration information. The cryptographic unit may include a secure internal memory such that during the secure operating modes, the cryptographic unit may only process descriptors provided from this secure internal memory.

Claims (39)

1. A data processing system having a cryptographic unit, wherein the cryptographic unit comprises:

cryptographic circuitry which performs a first cryptographic function to provide security for a portion of the cryptographic unit, and which performs a second cryptographic function to provide security for a portion of the data processing system external to the cryptographic unit, wherein the first cryptographic function is performed during secure cryptographic operation, and wherein the second cryptographic function is performed during normal cryptographic operation.

2. A data processing system as in claim 1 , wherein the cryptographic unit further comprises:

control circuitry which controls transitioning between normal cryptographic operation and secure cryptographic operation, wherein the control circuitry is couples to the cryptographic circuitry.

3. A data processing system as in claim 2 , wherein the control circuitry comprises a user programmable register bit which initiates a transition between normal cryptographic operation and secure cryptographic operation.

4. A data processing system as in claim 2 , wherein the control circuitry comprises a state machine.

5. A data processing system as in claim 1 , wherein the cryptographic unit further comprises:

first storage circuitry which stores a first key, wherein the first key is stored in non-encrypted form.

6. A data processing system as in claim 5 , wherein the first storage circuitry is one-time writable storage circuitry.

7. A data processing system as in claim 5 , wherein the cryptographic unit further comprises:

second storage circuitry which stores a second key, wherein the second key is decrypted using the first key.

8. A data processing system as in claim 7 , wherein the second storage circuitry stores first configuration information which is decrypted using the first key and wherein the second storage circuitry stores second configuration information which is decrypted using the second key.

9. A data processing system as in claim 8 , wherein once the second configuration information is stored in the second storage circuitry, the first key is no longer used to perform decryption without first exiting secure cryptographic operation.

10. A data processing system as in claim 8 , wherein the first configuration information and the second configuration information are used during secure cryptographic operation and are not used during normal cryptographic operation.

11. A method for providing security in a data processing system having a cryptographic unit, the method comprising:

operating in a normal operating mode of the cryptographic unit;

entering a first secure operating mode of the cryptographic unit;

in the first secure operating mode of the cryptographic unit, using a first key to decrypt first security configuration information, wherein the first security configuration information includes a second key;

entering a second secure operating mode of the cryptographic unit; and

in the second security operating mode of the cryptographic unit, using the second key to decrypt second security configuration information.

12. A method as in claim 11 , further comprising:

performing configuration of the cryptographic unit in at least one of the first and second secure operating modes.

13. A method as in claim 11 , further comprising:

returning to the normal operating mode of the cryptographic unit from at least one of the first and second secure operating modes.

14. A method as in claim 11 , further comprising:

in the second security operating mode of the cryptographic unit, using at least one descriptor from the second security configuration information to define a security function; and

performing the security function.

15. A method as in claim 14 , wherein the step of performing the security function comprises:

providing data external to the data processing system.

16. A method as in claim 14 , wherein the step of performing the security function comprises:

retrieving third security configuration information;

decrypting the third security configuration information using the second key; and

storing the decrypted third security configuration information in the cryptographic unit.

17. A data processing system having a cryptographic unit, wherein the cryptographic unit comprises:

first storage circuitry for storing a first key;

second storage circuitry for storing a second key, first configuration information, and second configuration information; and

cryptographic circuitry for performing a first cryptographic function to provide security for a portion of the cryptographic unit, wherein the first cryptographic function uses at least one of the first and second keys, said cryptographic circuitry performing a second cryptographic function to provide security for a portion of the data processing system external to the cryptographic unit, wherein the second cryptographic function uses at least one of the first and second keys, and wherein said cryptographic circuitry decrypts the first configuration information using the first key and decrypts the second configuration information using the second key.

18. A data processing system as in claim 17 , wherein the first key cannot be changed.

19. A data processing system as in claim 17 , wherein the second key is decrypted using the first key.

Assignments (20)
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 11759915 AND REPLACE IT WITH APPLICATION 11759935 PREVIOUSLY RECORDED ON REEL 040925 FRAME 0001. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Feb 17, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NXP, B.V. F/K/A FREESCALE SEMICONDUCTOR, INC.
Reel/Frame 052917/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 11759915 AND REPLACE IT WITH APPLICATION 11759935 PREVIOUSLY RECORDED ON REEL 040928 FRAME 0001. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Jan 17, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NXP B.V.
Reel/Frame 052915/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 11759915 AND REPLACE IT WITH APPLICATION 11759935 PREVIOUSLY RECORDED ON REEL 037486 FRAME 0517. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT AND ASSUMPTION OF SECURITY INTEREST IN PATENTS. Recorded Dec 10, 2019
From: CITIBANK, N.A.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 053547/0421 →
CORRECTIVE ASSIGNMENT TO CORRECT THE TO CORRECT THE APPLICATION NO. FROM 13,883,290 TO 13,833,290 PREVIOUSLY RECORDED ON REEL 041703 FRAME 0536. ASSIGNOR(S) HEREBY CONFIRMS THE THE ASSIGNMENT AND ASSUMPTION OF SECURITY INTEREST IN PATENTS.. Recorded Feb 20, 2019
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: SHENZHEN XINGUODU TECHNOLOGY CO., LTD.
Reel/Frame 048734/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENTS 8108266 AND 8062324 AND REPLACE THEM WITH 6108266 AND 8060324 PREVIOUSLY RECORDED ON REEL 037518 FRAME 0292. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT AND ASSUMPTION OF SECURITY INTEREST IN PATENTS. Recorded Feb 1, 2017
From: CITIBANK, N.A.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 041703/0536 →
RELEASE OF SECURITY INTEREST Recorded Nov 7, 2016
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NXP B.V.
Reel/Frame 040928/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 21, 2016
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NXP, B.V., F/K/A FREESCALE SEMICONDUCTOR, INC.
Reel/Frame 040925/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 4, 2016
From: FREESCALE SEMICONDUCTOR, INC.
To: NORTH STAR INNOVATIONS INC.
Reel/Frame 037694/0264 →
ASSIGNMENT AND ASSUMPTION OF SECURITY INTEREST IN PATENTS Recorded Jan 13, 2016
From: CITIBANK, N.A.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 037518/0292 →
ASSIGNMENT AND ASSUMPTION OF SECURITY INTEREST IN PATENTS Recorded Jan 12, 2016
From: CITIBANK, N.A.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 037486/0517 →
PATENT RELEASE Recorded Dec 21, 2015
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: FREESCALE SEMICONDUCTOR, INC.
Reel/Frame 037354/0225 →
PATENT RELEASE Recorded Dec 21, 2015
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: FREESCALE SEMICONDUCTOR, INC.
Reel/Frame 037354/0823 →
PATENT RELEASE Recorded Dec 21, 2015
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: FREESCALE SEMICONDUCTOR, INC.
Reel/Frame 037356/0143 →
PATENT RELEASE Recorded Dec 21, 2015
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: FREESCALE SEMICONDUCTOR, INC.
Reel/Frame 037356/0553 →
SECURITY AGREEMENT Recorded Nov 6, 2013
From: FREESCALE SEMICONDUCTOR, INC.
To: CITIBANK, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 031591/0266 →
SECURITY AGREEMENT Recorded Jun 18, 2013
From: FREESCALE SEMICONDUCTOR, INC.
To: CITIBANK, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 030633/0424 →
SECURITY AGREEMENT Recorded May 13, 2010
From: FREESCALE SEMICONDUCTOR, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 024397/0001 →
SECURITY AGREEMENT Recorded Sep 23, 2009
From: FREESCALE SEMICONDUCTOR, INC.
To: CITIBANK, N.A.
Reel/Frame 023273/0099 →
SECURITY AGREEMENT Recorded Feb 2, 2007
From: FREESCALE SEMICONDUCTOR, INC.; FREESCALE ACQUISITION CORPORATION; FREESCALE ACQUISITION HOLDINGS CORP.; FREESCALE HOLDINGS (BERMUDA) III, LTD.
To: CITIBANK, N.A. AS COLLATERAL AGENT
Reel/Frame 018855/0129 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 10, 2004
From: TORLA, MICHAEL J.; TKACIK, THOMAS E.
To: FREESCALE SEMICONDUCTOR, INC.
Reel/Frame 015512/0971 →