Nova Patents
EP2932644B1

Secrets renewability

Abstract

This record has no abstract on file.

EP2932644B1, drawing sheet 1
Sheet 1 of 23

Term

6.8 yearsleft in the term

Expires 10 July 2033.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

13 claims: 5 independent, 8 dependent

  1. 1
    A method for deriving a secondary secret (230) from a root secret (220), the method comprising:a. reserving a memory buffer comprised in an integrated circuit (200), the memory buffer being large enough to contain all of the bits which will comprise the secondary secret (230);b. receiving a plurality of bits from a root secret (220), the root secret (220) being stored in a secure memory of the integrated circuit (200);c. inputting the plurality of bits from the root secret (220) and at least one control bit into a permutation network (300), and thereby producing a multiplicity of output bits, the at least one control bit comprising one of: one bit of a value g;and one bit an output of a function (510) which receives g as an input;d. receiving the multiplicity of output bits from the permutation network (300);e. inputting the multiplicity of output bits from the permutation network (300) into a plurality of logic gates (520), thereby combining the multiplicity of output bits, wherein a fixed number of bits is output from the logic gates (520);f. inputting the fixed number of bits output by the logic gates (520) into an error correcting code module (530), the fixed number of bits output by the logic gates (520) comprising a first group of intermediate output bits (540) and a second group of intermediate output bits (540) and receiving output bits from the error correcting code module (530), the output bits of the error correcting code module (530) comprising the first group of intermediate output bits (540) as changed by the error correcting code module (530), where the change depends on the second group of intermediate output bits (540);g. filling non-filled registers in the reserved memory buffer with the first group of intermediate output bits (540) as changed by the error correcting code module (530);and h. repeating steps b - g until the entire secondary secret (230) is derived, wherein steps b - g are performed in a single clock cycle of the integrated circuit (200).
  2. 4
    The method of any of claims 1 - 3 wherein the error correcting code module (530) comprises one of:a Hamming(7, 4) error correcting code module (530);a Reed-Muller error correction code module;a Reed-Solomon error correction code module;and a Hamming(15, 11) error correction code module.
  3. 6
    The method according to any of claims 1 - 5 wherein the function which receives g as an input comprises a hash function (620), g being input (260) into the hash function (620) prior to being input into the permutation network (300).
  4. 9
    The method of either of claims 6 or 8 wherein additional arbitrarily selected bits comprise additional inputs to both of the error correction module and the hash function (620).
  5. 10
    The method according to any of claims 6 or 8 and further comprising inputting a plurality of arbitrarily selected bits (630) as additional inputs to the hash function (620) and also as additional inputs to the error correcting code module (530).
  6. 13
    A system for deriving a secondary secret (230) from a root secret (220), the system comprising:a. a reserved memory buffer comprised in an integrated circuit (200), the memory buffer being large enough to contain all of the bits which will comprise the secondary secret (230);b. a plurality of bits which are received from a root secret (220), the root secret (220) being stored in a secure memory of the integrated circuit (200);c. a permutation network (300) into which the plurality of bits from the root secret (220) and at least one control bit are input, thereby producing a multiplicity of output bits, the at least one control bit comprising one of: one bit of a value g;and one bit an output of a function (510) which receives g as an input;d. a plurality of logic gates (520) which receive the multiplicity of output bits from the permutation network (300) and into which the multiplicity of output bits from the permutation network (300) are input, thereby combining the multiplicity of output bits, wherein a fixed number of bits is output from the logic gates (520);e. an error correcting code module (530) into which the fixed number of bits output by the logic gates (520) are input, the fixed number of bits output by the logic gates (520) comprising a first group of intermediate output bits (540) and a second group of intermediate output bits (540) and receiving output bits from the error correcting code module (530), the output bits of the error correcting code module (530) comprising the first group of intermediate output bits (540) as changed by the error correcting code module (530), where the change depends on the second group of intermediate output bits (540);f. a plurality of registers in the reserved memory buffer of which non-filled registers are filled with the first group of intermediate output bits (540) as changed by the error correcting code module (530);and g. wherein the apparatus described in b - f is invoked until the entire secondary secret (230) is derived, wherein invoking the apparatus described in b - f is performed in a single clock cycle of the integrated circuit (200).