EP4040717A1

Method and device for secure communications over a network using a hardware security engine

Abstract

A system-on-a-chip (112) apparatus comprising a system-on-a-chip (112) comprising a security engine (110) that is separate from a processor core (118) of the system-on-a-chip (112) and has a secure memory (114) accessible only by the security engine, wherein the secure memory (114) includes a security key (150) that was encoded in the secure memory (114) during a manufacturing process of the system-on-a-chip (112), the security engine to generate a random nonce for initiating a request for a secure communication session with a remote server (104) over a network (106) using the nonce; perform a cryptographic key exchange with the remote server; generate a symmetric session key, based on the cryptographic key exchange, to encrypt messages sent to the remote server and decrypt messages received from the remote server during the secure communication session; encrypt the symmetric session key (150) based on the security key; and store the encrypted session key in the secure memory, the system-on-a-chip to establish the secure communication session with the remote server over the network using the session key.

EP4040717A1, drawing sheet 1
Sheet 1 of 5

Term

5.2 yearsto projected expiry

Projected expiry 15 December 2031, counted from filing; an application has no term until it is granted.

  1. Priority and filed
  2. Published
  3. Today
  4. Projected expiry

12 claims: 2 independent, 10 dependent

  1. 1
    A system-on-a-chip (112) apparatus comprising:a system-on-a-chip (112) comprising a security engine (110) that is separate from a processor core (118) of the system-on-a-chip (112) and has a secure memory (114) accessible only by the security engine, wherein the secure memory (114) includes a security key (150) that was encoded in the secure memory (114) during a manufacturing process of the system-on-a-chip (112), the security engine to: generate a random nonce for initiating a request for a secure communication session with a remote server (104) over a network (106) using the nonce;perform a cryptographic key exchange with the remote server;generate a symmetric session key, based on the cryptographic key exchange, to encrypt messages sent to the remote server and decrypt messages received from the remote server during the secure communication session;encrypt the symmetric session key (150) based on the security key;and store the encrypted session key in the secure memory, the system-on-a-chip to establish the secure communication session with the remote server over the network using the session key.
  2. 9
    A method comprising:generating a random nonce in a security engine (110) that is separate from a processor core (118) of a system-on-a-chip of a client device (102);initiating, using the client device (102), a request for a secure communication session with a remote server (104) over a network (106), the request including the random nonce;performing a cryptographic key exchange, by generating a pre-master key in the security engine, encrypting the pre-master key using the security key (150) of the security engine and sending the encrypted pre-master key to the remote server using the security engine of the system-on-a-chip;generate a symmetric session key to encrypt messages sent to the remote server and decrypt messages received from the remote server during the secure communication session;encrypting the session key based on a security key that was encoded in a secure memory of the security engine during a manufacturing process of the system-on-a-chip;storing the encrypted session key in the secure memory of the security engine of the system-on-a-chip;and establishing, using the client device, the secure communication session with the remote server using the session key.