EP4040717B1

Method and device for secure communications over a network using a hardware security engine

Abstract

This record has no abstract on file.

EP4040717B1, drawing sheet 1
Sheet 1 of 4

Term

5.2 yearsleft in the term

Expires 15 December 2031.

  1. Priority and filed
  2. Granted
  3. Today
  4. Expires

12 claims: 2 independent, 10 dependent

  1. 1
    A system-on-a-chip (112) apparatus comprising:a system-on-a-chip (112) comprising a security engine (110) that is separate from a processor core (118) of the system-on-a-chip (112) and has a secure memory (114) accessible only by the security engine, wherein the secure memory (114) includes a security key (150) that was provisioned in the secure memory (114) during a manufacturing process of the system-on-a-chip (112), the security engine is configured to: generate a random nonce for initiating a request for a secure communication session with a server (104) over a network (106) using the nonce;perform a cryptographic key exchange with the server;generate a symmetric session key, based on the cryptographic key exchange, to encrypt messages sent to the server and decrypt messages received from the server during the secure communication session;encrypt the symmetric session key (150) based on the security key;and store the encrypted symmetric session key in the secure memory, wherein the system-on-a-chip is configured to establish the secure communication session with the server over the network using the symmetric session key.
  2. 9
    A method comprising:generating a random nonce in a security engine (110) of a system-on-a-chip of a client device that is separate from a processor core (118) of the system-on-a-chip of the client device (102);initiating, using the client device (102), a request for a secure communication session with a server (104) over a network (106), the request including the random nonce;performing a cryptographic key exchange, by generating a pre-master key in the security engine, encrypting the pre-master key using the security key (150) of the security engine and sending the encrypted pre-master key to the server using the security engine of the system-on-a-chip;generate a symmetric session key to encrypt messages sent to the server and decrypt messages received from the server during the secure communication session;encrypting, using the security engine of the system-on-a-chip, the symmetric session key based on a security key that was encoded in a secure memory of the security engine during a manufacturing process of the system-on-a-chip;storing the encrypted symmetric session key in the secure memory of the security engine of the system-on-a-chip;and establishing, using the client device, the secure communication session with the server using the symmetric session key.