US2019312718A1PendingUtilityA1

Using secure key storage to bind a white-box implementation to one platform

Assignee: NXP BVPriority: Jun 27, 2016Filed: Jun 25, 2019Published: Oct 10, 2019
Est. expiryJun 27, 2036(~9.9 yrs left)· nominal 20-yr term from priority
H04L 9/002G06F 21/75H04L 2209/16
55
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method for performing a secure function in a data processing system is provided. In accordance with one embodiment, the method includes generating and encoding an encryption key. The encoded encryption key may be encrypted in a key store in a trusted execution environment (TEE) of the data processing system. The encrypted encryption key may encrypted, stored, and decrypted in the key store in the TEE, but used in a white-box implementation to perform a secure function. The secure function may include encrypting a value in the white-box implementation for securing a monetary value on, for example, a smart card. In one embodiment, each time an encryption key or decryption key is used, it is changed to a new key. The method makes code lifting and rollback attacks more difficult for an attacker because the key is stored separately from, for example, a white-box implementation in secure storage.

Claims

exact text as granted — not AI-modified
1 . (canceled) 
     
     
         2 . (canceled) 
     
     
         3 . (canceled) 
     
     
         4 . (canceled) 
     
     
         5 . (canceled) 
     
     
         6 . (canceled) 
     
     
         7 . (canceled) 
     
     
         8 . (canceled) 
     
     
         9 . (canceled) 
     
     
         10 . A method for performing a secure function using a white-box implementation in a data processing system, the method comprising:
 inputting an encoded encryption key in the white-box implementation;   storing the encoded encryption key in the unsecure execution environment; and   using the encoded encryption key in a trusted execution environment (TEE) to perform the secure function using the white-box implementation.   
     
     
         11 . The method of  claim 10 , wherein encoding the encryption key further comprises encoding the encryption key using one of a fixed mask, a linear function, or an affine function. 
     
     
         12 . The method of  claim 10 , wherein the secure function further comprises encrypting a data value. 
     
     
         13 . The method of  claim 10 , wherein storing the encoded encryption key in the unsecure execution environment further comprises storing the encoded encryption key in a non-volatile memory. 
     
     
         14 . The method of  claim 10 , wherein the encoded encryption key is changed each time it is used to perform the secure function. 
     
     
         15 . The method of  claim 10 , wherein the data processing system is implemented in an integrated circuit. 
     
     
         16 . A method for decrypting a data value in a data processing system, the method comprising:
 generating a decryption key;   encrypting the decryption key in a key store supported by a trusted execution environment (TEE) of the data processing system;   using the encrypted decryption key to decrypt a data value in the key store;   storing the encrypted data value in unsecured memory of the data processing system; and   changing the decryption key to a new decryption key each time it is used to decrypt a data value.   
     
     
         17 . The method of  claim 16 , wherein using the encrypted decryption key to decrypt a data value in the key store further comprises using a software application in the key store to decrypt the data value. 
     
     
         18 . The method of  claim 16 , wherein the data processing system is implemented on an integrated circuit. 
     
     
         19 . The method of  claim 16 , wherein generating a decryption key further comprises generating an encryption/decryption key pair, and wherein changing the decryption key to a new decryption key further comprises changing the encryption/decryption key pair to a new encryption/decryption key pair each time one of the encryption key or decryption key of the pair is used to encrypt or decrypt a data value. 
     
     
         20 . The method of  claim 16 , wherein the data value is further protected using one or more of obfuscation and tamper proofing.

Join the waitlist — get patent alerts

Track US2019312718A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.