US2007113103A1PendingUtilityA1

Method and central processing unit for processing encrypted software

Assignee: IBMPriority: Jul 27, 2005Filed: Jul 26, 2006Published: May 17, 2007
Est. expiryJul 27, 2025(expired)· nominal 20-yr term from priority
G06F 12/1408G06F 12/1009G06F 21/10G06F 21/125G06F 21/72H04L 9/0894
47
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

The present invention provides a central processing unit for processing at least one encrypted software. The encrypted software comprises at least one encrypted software section. The encrypted software section is encrypted with a management key MK, and the MK being encrypted with a device key DK as a encrypted MK. The central processing unit comprises processing and cache unit, and cryptographic unit. The cryptographic unit comprises device key storage unit for storing the DK, a plurality of management key storage units for storing MKs, wherein each management key storage unit corresponding to a management key index MKI, and decryption unit. The decryption unit decrypts a encrypted MK with the DK to obtain a MK, stores the MK to a management key storage unit, and output a MKI corresponding to the management key storage unit, thus the MKI is used to correspond to the encrypted software section. Wherein, the decryption unit invokes corresponding MK according to the MKI and decrypts the encrypted software section, and directly transfers the decrypted software code and/or data to the processing and cache unit.

Claims

exact text as granted — not AI-modified
1 . A central processing unit for processing at least one encrypted software, wherein the encrypted software comprising at least one encrypted software section, the encrypted software section being encrypted with a management key MK, the MK being encrypted with a device key DK as an encrypted MK, the central processing unit comprising: 
 processing and cache unit;    cryptographic unit, comprising:    device key storage unit for storing the DK;    a plurality of management key storage units for storing MKs, wherein each management key storage unit corresponding to a management key index MKI;    decryption unit for decrypting an encrypted MK with the DK to obtain a MK, storing the MK to a management key storage unit, and outputting a MKI corresponding to the management key storage unit, the MKI being used to correspond to the encrypted software section;    wherein, the decryption unit invoking corresponding MK according to the MKI and decrypting the encrypted software section, and directly transferring the decrypted software code and/or data to the processing and cache unit.    
   
   
       2 . The central processing unit according to  claim 1 , wherein the decryption unit directly transfers the decrypted software code and/or data together with corresponding MKI to the processing and cache unit, the processing and cache unit processes the decrypted software code and/or data according to the MKI.  
   
   
       3 . The central processing unit according to  claim 2 , wherein the processing and cache unit further transfers the processed software code and/or data together with corresponding MKI to the cryptographic unit; the cryptographic unit further comprises an encryption unit for invoking the corresponding MK according to the MKI to encrypt the processed software code and/or data, and output the encrypted software code and/or data together with the corresponding MKI.  
   
   
       4 . The central processing unit according to  claim 1 , for processing a plurality of encrypted software, each encrypted software is encrypted with a different MK, different MKs are encrypted with the DK respectively, the decryption unit is further configured to decrypt the encrypted MKs to obtain MKs, store the MKs to the management key storage units and output MKIs corresponding to the management key storage units, thus the MKIs associate to the plurality of encrypted software respectively.  
   
   
       5 . The central processing unit according to  claim 4 , wherein the decryption unit allocates management key storage units and MKIs to MKs based on a predetermined strategy, the processing and cache unit processes the decrypted software code and/or data based on a predetermined strategy.  
   
   
       6 . The central processing unit according to  claim 5 , wherein the predetermined strategy comprises: code and/or data associated with a MKI can only be accessed by code with same MKI; or code and/or data associated with a MKI can only be accessed by code with certain MKI according to the strategy.  
   
   
       7 . The central processing unit according to  claim 5 , wherein the processing and cache unit further comprises a secret register set, the predetermined strategy comprises: code and/or data stored in the secret register set and associated with a MKI could only be accessed by code with same MKI; or code and/or data stored in the secret register set and associated with a MKI could only be accessed by code with certain MKI according to the strategy.  
   
   
       8 . A method for processing at least one encrypted software with a central processing unit, wherein the central processing unit comprising a processing and cache unit, and a cryptographic unit, the cryptographic unit comprising decryption unit, device key storage unit for storing a DK, and a plurality of management key storage units for storing MKs, wherein each management key storage unit corresponding to a management key index MKI, the encrypted software being encrypted with a management key MK, the MK being encrypted with a device key DK as an encrypted MK, the method comprising: 
 storing the encrypted MK corresponding to the encrypted software into the cryptographic unit;    using a decryption unit for decrypting an encrypted MK with the DK to obtain a MK;    storing the MK in a management key storage unit, and obtaining a MKI corresponding to the management key storage unit;    associating the MKI with the encrypted software;    invoking corresponding MK according to the MKI and decrypting the encrypted software with the MK in the cryptographic unit; and    directly transferring the decrypted software code and/or data to the processing and cache unit, and processing the decrypted software with the processing and cache unit.    
   
   
       9 . The method according to  claim 8 , wherein the decryption unit directly transfers the decrypted software code and/or data together with corresponding MKI to the processing and cache unit, the processing and cache unit processes the decrypted software code and/or data according to the MKI.  
   
   
       10 . The method according to  claim 9 , wherein the processing and cache unit further transfers the processed software code and/or data together with corresponding MKI to the cryptographic unit; the cryptographic unit further comprises: 
 an encryption unit for invoking the corresponding MK according to the MKI to encrypt the processed software code and/or data, and outputting the encrypted software code and/or data together with the corresponding MKI.    
   
   
       11 . The method according to  claim 8 , for processing a plurality of encrypted software, each encrypted software is encrypted with a different MK, different MKs are encrypted with the DK respectively, the method further comprises: 
 using the decryption unit to decrypt the encrypted MKs with the DK to obtain MKs, stores the MKs to the management key storage units and output MKIs corresponding to the management key storage units, thus the MKIs associates to the plurality of encrypted software respectively.    
   
   
       12 . The method according to  claim 11 , wherein the decryption unit allocates management key storage unit and MKIs to MKs based on a predetermined strategy, the processing and cache unit processes the decrypted software code and/or data based on a predetermined strategy.  
   
   
       13 . The method according to  claim 12 , wherein the predetermined strategy comprises: code and/or data associated with a MKI can only be accessed by code with same MKI; or code and/or data associated with a MKI can only be accessed by code with certain MKI according to the strategy.  
   
   
       14 . The method according to  claim 8 , wherein the processing and cache unit further comprises a secret register set, the predetermined strategy comprises: code and/or data stored in the secret register set and associated with a MKI can only be accessed by code with same MKI; or code and/or data stored in the secret register set and associated with a MKI can only be accessed by code with certain MKI according to the strategy.

Join the waitlist — get patent alerts

Track US2007113103A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.