Memory address obfuscation
    1.
    发明授权
    Memory address obfuscation 有权
    内存地址混淆

    公开(公告)号:US08719588B2

    公开(公告)日:2014-05-06

    申请号:US12165550

    申请日:2008-06-30

    IPC分类号: G06F12/14 G06F21/14 G06F21/12

    摘要: Apparatus, systems, and methods may operate to provide, to a memory device, an obfuscated clear-page address derived from a clear-page address that is not the same as a key-page address and/or providing, to the memory device, an obfuscated key-page address derived from the key-page address when the obfuscated clear-page address is the same as the key-page address. Additional apparatus, systems, and methods are disclosed.

    摘要翻译: 设备,系统和方法可以操作以向存储器设备提供从清除页地址导出的与密钥页地址不同的和/或向存储器设备提供的混淆清除页地址, 当混淆的清除页面地址与密钥页地址相同时,从密钥页地址导出的模糊的密钥页地址。 公开了附加装置,系统和方法。

    MEMORY ADDRESS OBFUSCATION
    2.
    发明申请
    MEMORY ADDRESS OBFUSCATION 有权
    内存地址欺骗

    公开(公告)号:US20090327709A1

    公开(公告)日:2009-12-31

    申请号:US12165550

    申请日:2008-06-30

    IPC分类号: H04L9/00

    摘要: Apparatus, systems, and methods may operate to provide, to a memory device, an obfuscated clear-page address derived from a clear-page address that is not the same as a key-page address and/or providing, to the memory device, an obfuscated key-page address derived from the key-page address when the obfuscated clear-page address is the same as the key-page address. Additional apparatus, systems, and methods are disclosed.

    摘要翻译: 设备,系统和方法可以操作以向存储器设备提供从清除页地址导出的与密钥页地址不同的和/或向存储器设备提供的混淆清除页地址, 当混淆的清除页面地址与密钥页地址相同时,从密钥页地址导出的模糊的密钥页地址。 公开了附加装置,系统和方法。

    Secure Storage and Signature
    3.
    发明申请
    Secure Storage and Signature 有权
    安全存储和签名

    公开(公告)号:US20140025944A1

    公开(公告)日:2014-01-23

    申请号:US13553388

    申请日:2012-07-19

    IPC分类号: H04L9/00

    摘要: An integrated circuit device comprises a processor and a secure protection zone with security properties that can be verified by a remote device communicating with the integrated circuit device. The secure protection zone includes a persistent storage that is configured for storing cryptographic keys and data. The secure protection zone also includes instructions that are configured for causing the processor to perform cryptographic operations using the cryptographic keys. In addition, the secure protection zone includes an ephemeral memory that is configured for storing information associated with the cryptographic operations. The instructions are configured for causing the processor to perform the cryptographic operations on the data stored in the persistent storage and the information in the ephemeral memory as part of a secure communication exchange with the remote device.

    摘要翻译: 集成电路设备包括处理器和具有安全属性的安全保护区域,其可以由与集成电路设备通信的远程设备进行验证。 安全保护区包括被配置用于存储加密密钥和数据的持久存储器。 安全保护区还包括配置用于使处理器使用密码密钥执行密码操作的指令。 此外,安全保护区域包括临时存储器,其被配置用于存储与密码操作相关联的信息。 指令被配置为使得处理器对存储在永久存储器中的数据和临时存储器中的信息执行密码操作,作为与远程设备的安全通信交换的一部分。

    Generating signatures using a secure device
    4.
    发明授权
    Generating signatures using a secure device 有权
    使用安全设备生成签名

    公开(公告)号:US09323950B2

    公开(公告)日:2016-04-26

    申请号:US13553388

    申请日:2012-07-19

    摘要: An integrated circuit device comprises a processor and a secure protection zone with security properties that can be verified by a remote device communicating with the integrated circuit device. The secure protection zone includes a persistent storage that is configured for storing cryptographic keys and data. The secure protection zone also includes instructions that are configured for causing the processor to perform cryptographic operations using the cryptographic keys. In addition, the secure protection zone includes an ephemeral memory that is configured for storing information associated with the cryptographic operations. The instructions are configured for causing the processor to perform the cryptographic operations on the data stored in the persistent storage and the information in the ephemeral memory as part of a secure communication exchange with the remote device.

    摘要翻译: 集成电路设备包括处理器和具有安全属性的安全保护区域,其可以由与集成电路设备通信的远程设备进行验证。 安全保护区包括被配置用于存储加密密钥和数据的持久存储器。 安全保护区还包括配置用于使处理器使用密码密钥执行密码操作的指令。 此外,安全保护区域包括临时存储器,其被配置用于存储与密码操作相关联的信息。 指令被配置为使得处理器对存储在永久存储器中的数据和临时存储器中的信息执行密码操作,作为与远程设备的安全通信交换的一部分。

    Stored public key validity registers for cryptographic devices and systems
    5.
    发明授权
    Stored public key validity registers for cryptographic devices and systems 有权
    存储加密设备和系统的公钥有效性寄存器

    公开(公告)号:US08909929B2

    公开(公告)日:2014-12-09

    申请号:US13485678

    申请日:2012-05-31

    IPC分类号: H04L9/32 H04K1/00 H04L9/30

    摘要: Systems and techniques for performing cryptographic operations based on public key validity registers are described. A described system includes a controller and a memory structure to store one or more public keys. The memory structure includes one or more validity registers that respectively correspond to the one or more public keys. The controller has exclusive write access to the validity register. The controller can be configured to perform an authentication of a public key, write an authentication status value to the corresponding validity register based on a result of the authentication, and perform one or more cryptographic operations using the public key that are conditional on the validity register indicating an authenticated status for the public key.

    摘要翻译: 描述了基于公钥有效性寄存器执行加密操作的系统和技术。 所描述的系统包括控制器和用于存储一个或多个公共密钥的存储器结构。 存储器结构包括分别对应于一个或多个公钥的一个或多个有效性寄存器。 控制器具有对有效性寄存器的独占写访问权限。 控制器可以被配置为执行公开密钥的认证,基于认证的结果将认证状态值写入对应的有效性寄存器,并且使用以有效寄存器为条件的公开密钥来执行一个或多个密码操作 指示公钥的认证状态。

    UNIQUE CODE IN MESSAGE FOR SIGNATURE GENERATION IN ASYMMETRIC CRYPTOGRAPHIC DEVICE
    6.
    发明申请
    UNIQUE CODE IN MESSAGE FOR SIGNATURE GENERATION IN ASYMMETRIC CRYPTOGRAPHIC DEVICE 审中-公开
    消息中的不正确代码用于不对称CRYPTOGRAPHIC设备中的签名生成

    公开(公告)号:US20140089670A1

    公开(公告)日:2014-03-27

    申请号:US13628946

    申请日:2012-09-27

    IPC分类号: H04L9/32

    CPC分类号: H04L9/3226 H04L9/3252

    摘要: Methods and systems are disclosed for verifying the use of a client device by a host device in a secure system. In one aspect, a method for authenticating a client device includes receiving, by the client device, a message from a host device, accessing, by the client device, a private key and a unique code stored on the client device, where the unique code is different than the private key, generating, by the client device, a digital signature for the message using the private key and the unique code, and providing, by the client device, the digital signature to the host device for verification of the use of the client device by the host device.

    摘要翻译: 公开了用于在安全系统中验证由主机设备使用客户端设备的方法和系统。 一方面,用于认证客户端设备的方法包括:由客户端设备从主机设备接收消息,由客户端设备访问存储在客户端设备上的专用密钥和唯一代码,其中唯一代码 与私钥不同,由客户端设备使用专用密钥和唯一代码生成消息的数字签名,并且由客户端设备向主机设备提供数字签名以验证使用 客户端设备由主机设备。