TWI600307B

Method and device for secure communications over a network using a hardware security engine

Abstract

A method, device, and system for establishing a secure communication dialog with a server includes initiating a secure communication dialog request, such as temporary generated by using a system-on-chip (SOC) security engine in a client device. The value communicates with the secure socket layer (SLL) of the server. In addition, the cryptographic key exchange is performed between the client and the server to generate a symmetric session key, which is stored in the secure storage of the security engine. The cryptographic key exchange can be, for example, Rivest-Shamir-Adleman (RSA) key exchange or Diffie-Hellman key exchange. The private key and other data generated during the cryptographic key exchange can be generated and/or stored in the security engine.

TWI600307B, drawing sheet 1
Sheet 1 of 4

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Granted
  4. Today

47 claims: 27 independent, 20 dependent

  1. 1
    A system-on-chip device includes:a system-on-chip including a security engine, the security engine having a secure memory that can only be accessed by the security engine, wherein the secure memory is included in the system-on-chip A security key is encoded in the security memory during a manufacturing process of a chip. The security engine is used to: generate a random nonce, which is used to activate information about using the security on the network. Random temporary number and a request for a secure communication dialog with a remote server;perform a cryptographic key exchange with the remote server;during the secure communication dialog, generate a symmetrical dialog based on the cryptographic key exchange Key to encrypt the message sent to the remote server and decrypt the message received from the remote server;encrypt the symmetric conversation key based on the security key;store the encrypted symmetric conversation key in the In the secure memory, the system single chip uses the symmetric session key to establish the secure communication session with the remote server on the network. 一種系統單晶片設備,其包括:一系統單晶片,該系統單晶片包括一保全引擎,該保全引擎具有僅可由該保全引擎存取的一安全記憶體,其中該安全記憶體包括在該系統單晶片之一製造程序期間於該安全記憶體中所編碼之一安全金鑰,該保全引擎用以進行:產生一隨機臨時數(random nonce),該隨機臨時數用於起動關於在網路上使用該隨機臨時數與一遠端伺服器的一安全通訊對話的一請求;執行與該遠端伺服器的一密碼金鑰交換;在該安全通訊對話期間,基於該密碼金鑰交換產生一對稱對話金鑰,以加密發送至該遠端伺服器之訊息及解密從該遠端伺服器所接收之訊息;基於該安全金鑰加密該對稱對話金鑰;將經加密之該對稱對話金鑰儲存於該安全記憶體中,該系統單晶片使用該對稱對話金鑰在該網路上建立與該遠端伺服器之該安全通訊對話。
  2. 2
    For example, the system-on-chip device of the first item in the scope of patent application, wherein the system-on-chip uses the symmetrical session key to establish a secure sockets layer (Secure Sockets Layer) communication session with the remote server on the network. 如申請專利範圍第1項之系統單晶片設備,其中該系統單晶片使用該對稱對話金鑰在該網路上與該遠端伺服器建立一安全套接層(Secure Sockets Layer)通訊對話。
  3. 3
    For example, the system-on-a-chip device of the first patent application, wherein the security engine is further used to receive a server temporary data from the remote server in a response message to the request for the secure communication dialog, the The response message includes a server temporary data and storing the server temporary data in the secure memory. 如申請專利範圍第1項之系統單晶片設備,其中該保全引擎係進一步用以在對關於該安全通訊對話之該請求之一響應訊息中從該遠端伺服器接收一伺服器臨時數,該響應訊息包括一伺服器臨時數及將該伺服器臨時數儲存於該安全記憶體中。
  4. 4
    For example, the system-on-chip device of the first item of the patent application, wherein the security engine is further used to receive a server certificate from the remote server and store the server certificate in the secure memory. 如申請專利範圍第1項之系統單晶片設備,其中該保全引擎係進一步用以從該遠端伺服器接收一伺服器證書及將該伺服器證書儲存於該安全記憶體中。
  5. 5
    For example, the system-on-chip device in the scope of patent application 1, wherein the security engine is further used to perform a Rivest-Shamir-Adleman key exchange with the remote server to generate the symmetrical session key. 如申請專利範圍第1項之系統單晶片設備,其中該保全引擎係進一步用以執行與該遠端伺服器的一Rivest-Shamir-Adleman金鑰交換來產生該對稱對話金鑰。
  6. 6
    For example, the system-on-a-chip device of item 5 of the scope of patent application, wherein the security engine is further used to generate a former master key, use the security key of the security engine to encrypt the former master key and the encrypted front The master key is sent to the remote server. 如申請專利範圍第5項之系統單晶片設備,其中該保全引擎係進一步用以產生一前主金鑰,使用該保全引擎之該保全金鑰加密該前主金鑰及將該經加密的前主金鑰發送至該遠端伺服器。
  7. 7
    For example, the system-on-a-chip device in the scope of patent application, in which the security engine is further used to package the former master key with a server public key and store the packaged former master key in the secure memory middle. 如申請專利範圍第6項之系統單晶片設備,其中該保全引擎係進一步用以使用一伺服器公開金鑰包裝該前主金鑰及將該經包裝的前主金鑰儲存於該安全記憶體中。
  8. 8
    For example, the system-on-chip device of the sixth patent application, wherein the security engine is further used to generate the symmetric conversation key as a function of the former master key. 如申請專利範圍第6項之系統單晶片設備,其中該保全引擎係進一步用以產生作為該前主金鑰的一函式之該對稱對話金鑰。
  9. 9
    For example, the system-on-a-chip device of item 8 of the scope of patent application, wherein the security engine is further used to calculate a hash function, and the hash function is used as the random temporary number generated by the security engine and from the remote server A function that receives a temporary number. 如申請專利範圍第8項之系統單晶片設備,其中該保全引擎係進一步用以計算一雜湊函式,該雜湊函式作為由該保全引擎所產生之該隨機臨時數及從該遠端伺服器所接收之一臨時數的一函式之。
  10. 10
    For example, the system-on-a-chip device of item 5 of the scope of patent application, wherein the security engine is further used to receive a public Rivest-Shamir-Adleman server key from the remote server and the public Rivest-Shamir-Adleman server The key is stored in the secure memory. 如申請專利範圍第5項之系統單晶片設備,其中該保全引擎係進一步用以從該遠端伺服器接收一公開Rivest-Shamir-Adleman伺服器金鑰及將該公開Rivest-Shamir-Adleman伺服器金鑰儲存於該安全記憶體中。
  11. 11
    For example, the system-on-chip device of the first patent application, wherein the security engine is further used to perform a Diffie-Hellman key exchange with the remote server to generate the symmetric conversation key. 如申請專利範圍第1項之系統單晶片設備,其中該保全引擎係進一步用以執行與該遠端伺服器的一Diffie-Hellman金鑰交換以產生該對稱對話金鑰。
  12. 12
    For example, the system-on-chip device of the 11th patent application, in which the security engine is further used to generate a public Diffie-Hellman client key and a private Diffie-Hellman client key, and use the security money of the security engine The key signs the public Diffie-Hellman client key and sends the signed public Diffie-Hellman key to the remote server. 如申請專利範圍第11項之系統單晶片設備,其中該保全引擎係進一步用以產生一公開Diffie-Hellman客戶端金鑰及一私有Diffie-Hellman客戶端金鑰,使用該保全引擎的該保全金鑰簽名該公開Diffie-Hellman客戶端金鑰及將該簽名的公開Diffie-Hellman金鑰發送至該遠端伺服器。
  13. 13
    For example, the system-on-chip device of the 12th patent application, wherein the security engine is further used to receive a public Diffie-Hellman server key from the remote server and generate it as the private Diffie-Hellman client key and The symmetric conversation key of a function of the public Diffie-Hellman server key. 如申請專利範圍第12項之系統單晶片設備,其中該保全引擎係進一步用以從該遠端伺服器接收一公開Diffie-Hellman伺服器金鑰及產生作為該私有Diffie-Hellman客戶端金鑰及該公開Diffie-Hellman伺服器金鑰的一函式之該對稱對話金鑰。
  14. 14
    For example, the system-on-chip device of the 13th patent application, wherein the security engine is further used to use the symmetric session key to encrypt a subsequent message sent from the client device to the remote server. 如申請專利範圍第13項之系統單晶片設備,其中該保全引擎係進一步用以使用該對稱對話金鑰來加密自該客戶端裝置所發送至該遠端伺服器的一後續訊息。
  15. 15
    For example, the system-on-chip device of the 11th patent application, wherein the security engine is further used to receive the Diffie-Hellman global value and a public Diffie-Hellman server key from the remote server, and the Diffie-Hellman At least one of the global value and the public Diffie-Hellman server key is stored in the secure memory. 如申請專利範圍第11項之系統單晶片設備,其中該保全引擎係進一步用以從該遠端伺服器接收Diffie-Hellman全域值及一公開Diffie-Hellman伺服器金鑰,並且將該Diffie-Hellman全域值及該公開Diffie-Hellman伺服器金鑰中至少一者儲存於該安全記憶體中。
  16. 16
    A method for secure communication, comprising:generating a random temporary number in a security engine of a system-on-chip of a client device;using the client device to activate a security with a remote server on the network A request for a communication session, the request includes the random temporary number;the security engine of the system-on-chip is used to perform a cryptographic key exchange with the remote server;a symmetrical session key is generated during the secure communication session Encrypt the message sent to the remote server and decrypt the message received from the remote server;encrypt the symmetric session key based on a security key that is during a manufacturing process of the system-on-a-chip Is encoded in a secure memory;the encrypted symmetric session key is stored in the secure memory of the security engine of the system-on-chip;and using the client device, the symmetric session key is used to establish and The secure communication session of the remote server. 一種用於安全通訊之方法,其包含:在一客戶端裝置的一系統單晶片的一保全引擎中產生一隨機臨時數;使用該客戶端裝置在網路上起動與一遠端伺服器的一安全通訊對話的一請求,該請求包含該隨機臨時數;使用該系統單晶片之該保全引擎執行與該遠端伺服器的一密碼金鑰交換;在該安全通訊對話期間產生一對稱對話金鑰來加密發送至該遠端伺服器之訊息及解密從該遠端伺服器所接收之訊息;基於一安全金鑰加密該對稱對話金鑰,該安全金鑰係在該系統單晶片之一製造程序期間於一安全記憶體中所編碼;將經加密之該對稱對話金鑰儲存於該系統單晶片之該保全引擎的該安全記憶體中;以及使用該客戶端裝置,使用該對稱對話金鑰建立與該遠端伺服器之該安全通訊對話。
  17. 35
    An arithmetic device, comprising:a system-on-chip with a security engine, the system-on-chip contains a plurality of instructions, and when the instructions are executed, the system-on-chip executes any of the 16 to 34 patent applications One method. 一種運算裝置,其包括:具有一保全引擎的一系統單晶片,該系統單晶片包含複數個指令,當該等指令被執行時導致該系統單晶片執行如申請專利範圍第16至34項之任一項之方法。
  18. 36
    A machine-readable medium containing one or more of a plurality of instructions, in response to the plurality of instructions being executed by a client device, causing the client device to execute a method such as any one of the scope of the patent application 16 to 34 . 一種包含複數個指令之一或多個機器可讀媒體,響應於該等複數個指令由一客戶端裝置所執行導致該客戶端裝置執行如申請專利範圍第16至34項之任一項之方法。
  19. 37
    A method for secure communication, comprising:generating a random temporary number in a security engine of a system-on-chip of a client device;using the client device to activate a condom with a remote server on the network A request for an interface communication session, the request including the random temporary number;the security engine of the system-on-a-chip is used to perform a cryptographic key exchange with the remote server to generate a security socket layer communication session during the secure socket layer communication session. A symmetric session key to encrypt messages sent to the remote server and decrypt messages received from the server;store the symmetric session key in a secure memory of the security engine of the system-on-chip;and Generate a hash code of a function as the key of the symmetric session in the security engine;and send a client completion message containing the hash code to the remote server to indicate that the client has completed an initial handshake Process. 一種用於安全通訊之方法,其包含:在一客戶端裝置的一系統單晶片的一保全引擎中產生一隨機臨時數;使用該客戶端裝置在網路上起動與一遠端伺服器的一安全套接層通訊對話的一請求,該請求包括該隨機臨時數;使用該系統單晶片之該保全引擎執行與該遠端伺服器的一密碼金鑰交換,以在該安全套接層通訊對話期間產生一對稱對話金鑰來加密發送至該遠端伺服器之訊息及解密從該伺服器所接收之訊息;將該對稱對話金鑰儲存於該系統單晶片之該保全引擎的一安全記憶體中;以及在該保全引擎中產生作為該對稱對話金鑰的一函式之一雜湊碼;以及將包含該雜湊碼的一客戶端完成訊息發送至該遠端伺服器以指示該客戶端已完成一初始握手過程。
  20. 38
    Such as the method of item 37 of the scope of patent application, wherein performing the cryptographic key exchange with the remote server includes using the security engine of the system-on-a-chip to perform a Rivest-Shamir-Adleman gold exchange with the remote server Key exchange. 如申請專利範圍第37項之方法,其中執行與該遠端伺服器之該密碼金鑰交換包括使用該系統單晶片之該保全引擎來執行與該遠端伺服器的一Rivest-Shamir-Adleman金鑰交換。
  21. 39
    For example, the 38th method in the scope of the patent application, wherein performing the Rivest-Shamir-Adleman key exchange with the remote server includes:generating a previous master key in the security engine;using a security key of the security engine Encrypting the former master key;and sending the encrypted former master key to the remote server. 如申請專利範圍第38項方法,其中執行與該遠端伺服器之該Rivest-Shamir-Adleman金鑰交換包括:在該保全引擎中產生一前主金鑰;使用該保全引擎的一保全金鑰加密該前主金鑰;以及將該加密的前主金鑰發送至該遠端伺服器。
  22. 40
    For example, the method of item 39 of the scope of patent application further includes:packaging the former master key in the security engine using a server public key, and storing the packaged former master key in the system-on-chip Secure the engine in this secure storage. 如申請專利範圍第39項之方法,進一步包括:使用一伺服器公開金鑰將該前主金鑰包裝在該保全引擎中,以及將該包裝的前主金鑰儲存於該系統單晶片之該保全引擎的該安全儲存體中。
  23. 41
    For example, the method of item 39 of the scope of patent application, wherein performing the Rivest-Shamir-Adleman key exchange with the remote server includes generating a function as the former master key in the security engine of the system-on-a-chip The symmetrical conversation key. 如申請專利範圍第39項之方法,其中執行與該遠端伺服器之該Rivest-Shamir-Adleman金鑰交換包括在該系統單晶片之該保全引擎中產生作為該前主金鑰的一函式之該對稱對話金鑰。
  24. 43
    Such as the method of item 37 of the scope of patent application, wherein performing the cryptographic key exchange with the remote server includes using the security engine of the system-on-a-chip to perform a Diffie-Hellman key exchange with the remote server . 如申請專利範圍第37項之方法,其中執行與該遠端伺服器之該密碼金鑰交換包括使用該系統單晶片之該保全引擎來執行與該遠端伺服器的一Diffie-Hellman金鑰交換。
  25. 45
    For example, the method of item 44 of the scope of patent application, wherein performing a Diffie-Hellman key exchange with one of the remote servers includes:receiving a public Diffie-Hellman server key from the remote server;The security engine generates the conversation key as a function of the private Diffie-Hellman client key and the public Diffie-Hellman server key. 如申請專利範圍第44項之方法,其中執行與該遠端伺服器之一Diffie-Hellman金鑰交換包括:從該遠端伺服器接收一公開Diffie-Hellman伺服器金鑰;在該系統單晶片之該保全引擎中產生作為該私有Diffie-Hellman客戶端金鑰及該公開Diffie-Hellman伺服器金鑰的一函式之該對話金鑰。
  26. 46
    An arithmetic device, comprising:a system-on-chip with a security engine, the system-on-chip includes a plurality of instructions, and when the instructions are executed, the system-on-chip executes any of the 37 to 45 of the scope of the patent application One method. 一種運算裝置,其包括:具有一保全引擎的一系統單晶片,該系統單晶片包含複數個指令,當該等指令被執行時導致該系統單晶片執行如申請專利範圍第37至45項之任一項之方法。
  27. 47
    A machine-readable medium containing one or more of a plurality of instructions, in response to the plurality of instructions being executed by a client device, causes the client device to execute a method such as any one of items 37 to 45 in the scope of the patent application . 一種包含複數個指令之一或多個機器可讀媒體,響應於該等複數個指令由一客戶端裝置執行時導致該客戶端裝置執行如申請專利範圍第37至45項之任一項之方法。
Independent claims27