-
公开(公告)号:US20230388290A1
公开(公告)日:2023-11-30
申请号:US18216093
申请日:2023-06-29
Applicant: Cryptography Research Inc
Inventor: Paul Carl Kocher , Benjamin Chen-Min Jun , Andrew John Leiserson
IPC: H04L9/40 , H04L9/08 , H04L9/14 , H04L9/32 , G06F21/54 , G06F21/71 , H04W12/04 , H04W12/041 , G06F21/64 , G06F21/57
CPC classification number: H04L63/0823 , H04L9/083 , H04L9/0897 , H04L9/14 , H04L9/3247 , G06F21/54 , G06F21/71 , H04W12/04 , H04W12/041 , G06F21/64 , G06F21/57 , H04L63/061 , H04L63/083 , G06F2221/2101
Abstract: A mechanism for providing secure feature and key management in integrated circuits is described. An example integrated circuit includes a secure memory to store a secret key, and a security manager core, coupled to the secure memory, to receive a digitally signed command, verify a signature associated with the command using the secret key, and configure operation of the integrated circuit using the command.
-
公开(公告)号:US11386236B2
公开(公告)日:2022-07-12
申请号:US16427636
申请日:2019-05-31
Applicant: Cryptography Research, Inc.
Inventor: Andrew John Leiserson , Mark Evan Marson , Megan Anneke Wachs
Abstract: A method of and system for gate-level masking of secret data during a cryptographic process is described. A mask share is determined, wherein a first portion of the mask share includes a first number of zero-values and a second number of one-values, and a second portion of the mask share includes the first number of one-values and the second number of zero-values. Masked data values and the first portion of the mask share are input into a first portion of masked gate logic, and the masked data values and the second portion of the mask share are input into a second portion of the masked gate logic. A first output from the first portion of the masked gate logic and a second output from the second portion of the masked gate logic are identified, wherein either the first output or the second output is a zero-value.
-
公开(公告)号:US10666641B2
公开(公告)日:2020-05-26
申请号:US16138105
申请日:2018-09-21
Applicant: Cryptography Research Inc.
Inventor: Paul Carl Kocher , Benjamin Che-Ming Jun , Andrew John Leiserson
Abstract: A mechanism for providing secure feature and key management in integrated circuits is described. An example method includes receiving, by a root authority system, data identifying a command that affects operation of an integrated circuit, singing, by the root authority system, the command using a root authority key to create a root signed block (RSB), and providing the RSB to a security manager of the integrated circuit.
-
公开(公告)号:US09436848B2
公开(公告)日:2016-09-06
申请号:US14289274
申请日:2014-05-28
Applicant: Cryptography Research, Inc.
Inventor: Daniel Beitel , Lauren Gao , Christopher Gori , Paul Carl Kocher , Ambuj Kumar , Andrew John Leiserson
CPC classification number: G06F21/76 , G06F21/572
Abstract: A computing device receives a feature name or key name for an integrated circuit comprising a security manager core and an additional component. At least one of a) the additional component is associated with the key name or b) a feature provided by the additional component is associated with the feature name. The computing device receives a specified number of bits associated with the feature name or the key name, and maps the feature name to a feature address space or the key name to a key interface of the security manager core based at on the specified number of bits. The computing device generates at least one hardware description logic (HDL) module based on the mapping, wherein the at least one HDL module is usable to configure the security manager core for delivery of payloads associated with the feature name or the key name to the additional component.
Abstract translation: 计算设备接收包括安全管理器核心和附加组件的集成电路的功能名称或密钥名称。 a)附加组件中的至少一个与密钥名称相关联,或者b)由附加组件提供的特征与特征名称相关联。 计算设备接收与特征名称或密钥名称相关联的指定数量的位,并且基于指定的位数将特征名称映射到特征地址空间或密钥名称到安全管理器核心的密钥接口 。 所述计算设备基于所述映射生成至少一个硬件描述逻辑(HDL)模块,其中所述至少一个HDL模块可用于配置所述安全管理器核心,用于将与所述特征名称或所述密钥名称相关联的有效载荷传递到所述附加 零件。
-
公开(公告)号:US20150169904A1
公开(公告)日:2015-06-18
申请号:US14565821
申请日:2014-12-10
Applicant: CRYPTOGRAPHY RESEARCH, INC.
Inventor: Andrew John Leiserson , Mark Evan Marson , Megan Anneke Wachs
CPC classification number: G06F21/72 , G06F21/71 , G06F21/755 , H04L9/003 , H04L2209/04 , H04L2209/12 , H04L2209/16
Abstract: A method of and system for gate-level masking of secret data during a cryptographic process is described. A mask share is determined, wherein a first portion of the mask share includes a first number of zero-values and a second number of one-values, and a second portion of the mask share includes the first number of one-values and the second number of zero-values. Masked data values and the first portion of the mask share are input into a first portion of masked gate logic, and the masked data values and the second portion of the mask share are input into a second portion of the masked gate logic. A first output from the first portion of the masked gate logic and a second output from the second portion of the masked gate logic are identified, wherein either the first output or the second output is a zero-value.
Abstract translation: 描述在密码处理期间秘密数据的门级掩蔽的方法和系统。 确定掩模共享,其中掩模共享的第一部分包括第一数量的零值和第二数量的一值,并且掩模共享的第二部分包括第一数量的一值,第二部分包括第二数量的一值 零值数。 掩蔽数据值和掩模共享的第一部分被输入到屏蔽门逻辑的第一部分中,并且掩蔽的数据值和掩模共享的第二部分被输入到被掩蔽的门逻辑的第二部分。 识别来自屏蔽门逻辑的第一部分的第一输出和来自屏蔽门逻辑的第二部分的第二输出,其中第一输出或第二输出都是零值。
-
公开(公告)号:US11861051B2
公开(公告)日:2024-01-02
申请号:US16922205
申请日:2020-07-07
Applicant: Cryptography Research, Inc
Inventor: Andrew John Leiserson , Mark Evan Marson
CPC classification number: G06F21/755 , G06F21/78 , G09C1/00 , H04L9/003 , H04L9/0618 , H04L2209/08
Abstract: A cryptographic accelerator (processor) retrieves data blocks for processing from a memory. These data blocks arrive and are stored in an input buffer in the order they were stored in memory (or other known order)—typically sequentially according to memory address (i.e., in-order.) The processor waits until a certain number of data blocks are available in the input buffer and then randomly selects blocks from the input buffer for processing. This randomizes the processing order of the data blocks. The processing order of data blocks may be randomized within sets of data blocks associated with a single read transaction, or across sets of data blocks associated with multiple read transactions.
-
公开(公告)号:US11861047B2
公开(公告)日:2024-01-02
申请号:US17862134
申请日:2022-07-11
Applicant: Cryptography Research, Inc.
Inventor: Andrew John Leiserson , Mark Evan Marson , Megan Anneke Wachs
CPC classification number: G06F21/72 , G06F21/71 , G06F21/755 , H04L9/003 , H04L2209/04 , H04L2209/12 , H04L2209/16
Abstract: A method of and system for gate-level masking of secret data during a cryptographic process is described. A mask share is determined, wherein a first portion of the mask share includes a first number of zero-values and a second number of one-values, and a second portion of the mask share includes the first number of one-values and the second number of zero-values. Masked data values and the first portion of the mask share are input into a first portion of masked gate logic, and the masked data values and the second portion of the mask share are input into a second portion of the masked gate logic. A first output from the first portion of the masked gate logic and a second output from the second portion of the masked gate logic are identified, wherein either the first output or the second output is a zero-value.
-
公开(公告)号:US10747907B2
公开(公告)日:2020-08-18
申请号:US14955269
申请日:2015-12-01
Applicant: Cryptography Research, Inc
Inventor: Andrew John Leiserson , Mark Evan Marson
Abstract: A cryptographic accelerator (processor) retrieves data blocks for processing from a memory. These data blocks arrive and are stored in an input buffer in the order they were stored in memory (or other known order)—typically sequentially according to memory address (i.e., in-order.) The processor waits until a certain number of data blocks are available in the input buffer and then randomly selects blocks from the input buffer for processing. This randomizes the processing order of the data blocks. The processing order of data blocks may be randomized within sets of data blocks associated with a single read transaction, or across sets of data blocks associated with multiple read transactions.
-
公开(公告)号:US10084771B2
公开(公告)日:2018-09-25
申请号:US14871951
申请日:2015-09-30
Applicant: Cryptography Research, Inc.
Inventor: Paul Carl Kocher , Benjamin Che-Ming Jun , Andrew John Leiserson
CPC classification number: H04L63/0823 , G06F21/54 , G06F21/71 , G06F2221/2101 , H04L9/083 , H04L9/0897 , H04L9/14 , H04L9/3247 , H04L63/061 , H04L63/083
Abstract: A mechanism for providing secure feature and key management in integrated circuits is described. An example method includes receiving, by a root authority system, data identifying a command that affects operation of an integrated circuit, singing, by the root authority system, the command using a root authority key to create a root signed block (RSB), and providing the RSB to a security manager of the integrated circuit.
-
公开(公告)号:US12113786B2
公开(公告)日:2024-10-08
申请号:US18216093
申请日:2023-06-29
Applicant: Cryptography Research Inc
Inventor: Paul Carl Kocher , Benjamin Chen-Min Jun , Andrew John Leiserson
IPC: G06F21/71 , G06F21/54 , G06F21/57 , G06F21/64 , H04L9/08 , H04L9/14 , H04L9/32 , H04L9/40 , H04W12/04 , H04W12/041
CPC classification number: H04L63/0823 , G06F21/54 , G06F21/57 , G06F21/64 , G06F21/71 , H04L9/083 , H04L9/0897 , H04L9/14 , H04L9/3247 , H04L63/061 , H04L63/083 , H04W12/04 , H04W12/041 , G06F2221/2101
Abstract: A mechanism for providing secure feature and key management in integrated circuits is described. An example integrated circuit includes a secure memory to store a secret key, and a security manager core, coupled to the secure memory, to receive a digitally signed command, verify a signature associated with the command using the secret key, and configure operation of the integrated circuit using the command.
-
-
-
-
-
-
-
-
-