WO2013089725A1

Method and device for secure communications over a network using a hardware security engine

Abstract

A method, device, and system for establishing a secure communication session with a server includes initiating a request for a secure communication session, such as a Secure Sockets Layer (SLL) communication session with a server using a nonce value generated in a security engine of a system-on-a-chip (SOC) of a client device. Additionally, a cryptographic key exchange is performed between the client and the server to generate a symmetric session key, which is stored in a secure storage of the security engine. The cryptographic key exchange may be, for example, a Rivest-Shamir-Adleman (RSA) key exchange or a Diffie-Hellman key exchange. Private keys and other data generated during the cryptographic key exchange may be generated and/or stored in the security engine.

WO2013089725A1, drawing sheet 1
Sheet 1 of 4

Term

No projected expiry on record.

  1. Priority and filed
  2. Published
  3. Today

47 claims: 5 independent, 42 dependent

  1. 1
    CLAIMS:1. A system-on-a-chip apparatus comprising: a system-on-a-chip comprising a security engine having a secure memory accessible only by the security engine, the security engine to: generate a random nonce for initiating a request for a secure communication session with a server over a network using the nonce;perform a cryptographic key exchange with the server to generate a symmetric session key to encrypt messages sent to the server and decrypt messages received from the server during the secure communication session;store the session key in the secure memory, the system-on-a-chip to establish the secure communication session with the server over the network using the session key.
  2. 16
    A method comprising:generating a random nonce in a security engine of a system-on-a-chip of a client device;initiating, using the client device, a request for a secure communication session with a server over a network, the request including the random nonce;performing a cryptographic key exchange, using the security engine of the system-on-a-chip, with the server to generate a symmetric session key to encrypt messages sent to the server and decrypt messages received from the server during the secure communication session;storing the session key in a secure memory of the security engine of the system- on-a-chip;and establishing, using the client device, the secure communication session with the server using the session key.
  3. 35
    A source device comprising:a system-on-a-chip having a security engine, the system-on-a-chip including a plurality of instructions that when executed results in the system-on-a-chip performing the method of claim 16-34.
  4. 36
    One or more machine readable media comprising a plurality of instructions that in response to being executed by a client device result in the client device performing the method of claims 16-34.
  5. 37
    A method comprising:generating a random nonce in a security engine of a system-on-a-chip of a client device;initiating, using the client device, a request for a Secure Sockets Layer communication session with a server over a network, the request including the random nonce;performing a cryptographic key exchange, using the security engine of the system-on-a-chip, with the server to generate a symmetric session key to encrypt messages sent to the server and decrypt messages received from the server during the Secure Sockets Layer communication session;storing the session key in a secure memory of the security engine of the system- on-a-chip;and generating, in the security engine, a hash code as a function of the session key;and sending a client completion message to the server that includes the hash code to indicate the client has completed an initial handshake procedure.
  6. 46
    A source device comprising:a system-on-a-chip having a security engine, the system-on-a-chip including a plurality of instructions that when executed results in the system-on-a-chip performing the method of claim 37-45.
  7. 47
    One or more machine readable media comprising a plurality of instructions that in response to being executed by a client device result in the client device performing the method of claims 37-45.