Securely transferring key materials between processors in a multi-processor device

A multi-processor device includes a first processor implemented with a secured key derivation and storage component and a second processor implemented without a secured key derivation and storage component. In operation, the second processor is configured to execute an initial boot process by loadin...

Ausführliche Beschreibung

Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Shahaf, Mark, Ong, Hean Kuang, Wealleans, Mark
Format: Patent
Sprache:eng
Schlagworte:
Online-Zugang:Volltext bestellen
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
Beschreibung
Zusammenfassung:A multi-processor device includes a first processor implemented with a secured key derivation and storage component and a second processor implemented without a secured key derivation and storage component. In operation, the second processor is configured to execute an initial boot process by loading a limited functionality boot image when the multi-processor device is powered on. During the execution of the initial boot process, the second processor provisions a secure storage container to hold a key material and sends a request to the first processor for a key material. In response, the second processor receives a key material derived at the first processor. The second processor then stores the key material in a volatile memory portion of the secure storage container. The second processor executes a main boot process only after erasing instances of the key material temporarily stored outside of the secure storage container.