Cryptography Research, Inc.

United States of America

Back to Profile

1-100 of 322 for Cryptography Research, Inc. Sort by
Query
Aggregations
IP Type
        Patent 312
        Trademark 10
Jurisdiction
        United States 238
        World 81
        Europe 3
Date
New (last 4 weeks) 3
2026 July 3
2026 June 1
2026 May 1
2026 April 2
See more
IPC Class
H04L 9/00 - Arrangements for secret or secure communicationsNetwork security protocols 96
H04L 9/08 - Key distribution 76
H04L 9/32 - Arrangements for secret or secure communicationsNetwork security protocols including means for verifying the identity or authority of a user of the system 75
H04L 9/06 - Arrangements for secret or secure communicationsNetwork security protocols the encryption apparatus using shift registers or memories for blockwise coding, e.g. D.E.S. systems 60
H04L 29/06 - Communication control; Communication processing characterised by a protocol 45
See more
NICE Class
42 - Scientific, technological and industrial services, research and design 8
09 - Scientific and electric apparatus and instruments 4
41 - Education, entertainment, sporting and cultural services 2
45 - Legal and security services; personal services for individuals. 2
A - Certification of Goods 2
See more
Status
Pending 31
Registered / In Force 291
  1     2     3     4        Next Page

1.

LOW-LATENCY MULTI-KEY ENCRYPTION AND DECRYPTION ENGINE AND TECHNIQUES

      
Application Number 19427572
Status Pending
Filing Date 2025-12-19
First Publication Date 2026-07-30
Owner Cryptography Research, Inc. (USA)
Inventor
  • Hamburg, Michael Alexander
  • Erickson, Evan Lawrence
  • Handschuh, Helena
  • Marson, Mark Evan

Abstract

Disclosed systems and techniques involve low-latency multi-key encryption processing in which block keys are precomputed based on multiple cryptographic keys, stored, and then selected for encryption or decryption of data during run-time cryptographic operations. The block keys may be precomputed, for each cryptographic key, in such quantities that allow uninterrupted flow of encryption or decryption operations. Replacement block keys may be concurrently generated to replace the blocks being consumed and authentication values may be computed or updated. Various described techniques allow parallel processing for efficient low-latency block key generation and cryptographic operations.

IPC Classes  ?

2.

NETWORK INTERFACE WITH DATA PROTECTION

      
Application Number US2026011441
Publication Number 2026/161281
Status In Force
Filing Date 2026-01-15
Publication Date 2026-07-30
Owner CRYPTOGRAPHY RESEARCH, INC. (USA)
Inventor Demchenko, Maksym

Abstract

Technologies for optimizing area and latency for network interfaces with data protection are described. One system includes a Media Access Control (MAC)unit coupled to a physical coding sublayer (PCS) through a media-independent interface (MII bus) and a MACsec engine located between the MAC unit and the PCS. The MAC unit provides MII signals with packet data on the MII bus, provides extra MII signals on the MII bus to eliminate MII bus decoding by the MACsec engine, and provides early packet signals to the MACsec engine. The early packet signals allow the MACsec engine to perform classification and transformation ahead of receiving the MII signals with the packet data on the MII bus. The MACsec engine modifies the packet data with substantially zero egress latency.

IPC Classes  ?

  • H04W 80/02 - Data link layer protocols
  • H04L 9/40 - Network security protocols
  • H04L 43/026 - Capturing of monitoring data using flow identification
  • H04L 49/351 - Switches specially adapted for specific applications for local area network [LAN], e.g. Ethernet switches
  • H04L 69/324 - Intralayer communication protocols among peer entities or protocol data unit [PDU] definitions in the data link layer [OSI layer 2], e.g. HDLC

3.

PROTECTION OF COMPARISON OPERATIONS AGAINST SIDE-CHANNEL ATTACKS IN CRYPTOGRAPHIC APPLICATIONS

      
Application Number 19446679
Status Pending
Filing Date 2026-01-12
First Publication Date 2026-07-16
Owner Cryptography Research, Inc. (USA)
Inventor
  • Xiao, Qinglai
  • Hamburg, Michael Alexander

Abstract

Disclosed aspects and implementations are directed to systems and techniques for efficient randomization-protected comparison operations deploying linear transformations and or matrix multiplications in the context of processing an input into the cryptographic operation. The disclosed techniques include obtaining a masked representation of a first vector and a second vector, the masked representation including shares of the first vector and the second vector or shares of a difference of the first vector and the second vector. The techniques further include transforming, using a matrix-based randomization operation, the masked representation to a transformed representation and obtaining, using the transformed representation, a determination whether the first vector is equal to the second vector. The techniques further include computing, using the determination, an output of the cryptographic operation associated with the input into the cryptographic operation.

IPC Classes  ?

  • G06F 21/54 - Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems during program execution, e.g. stack integrity, buffer overflow or preventing unwanted data erasure by adding security routines or objects to programs
  • G06F 17/16 - Matrix or vector computation
  • G06F 21/60 - Protecting data

4.

PHYSICALLY UNCLONABLE FUNCTION DIVERSIFICATION

      
Application Number 19411724
Status Pending
Filing Date 2025-12-08
First Publication Date 2026-06-18
Owner Cryptography Research, Inc. (USA)
Inventor
  • Orzen, Matthew E.
  • Wittenauer, Joel

Abstract

Helper data and/or physically unclonable function (PUF) output data may be analyzed to determine which bits of the raw PUF output are stable. A first subset of the stable PUF output bits are selected (e.g., randomly) to generate a first stable PUF output value to be used as a first device unique value. To change the device unique value (a.k.a., digital fingerprint or fingerprint) of the integrated circuit generated by the PUF circuitry, new subsets (which may be generated off-chip) with different stable PUF output bits may be provided to the integrated circuit (i.e., provisioned) from time to time (e.g., with a new firmware/software update, after some arbitrary period of time—e.g., one year—etc.). Each new and different subset of stable bits used by the integrated circuit causes the integrated circuit to generate new, and different, device unique values.

IPC Classes  ?

  • H04L 9/32 - Arrangements for secret or secure communicationsNetwork security protocols including means for verifying the identity or authority of a user of the system
  • H04L 9/08 - Key distribution

5.

PROTECTION OF POLYNOMIAL CRYPTOGRAPHIC OPERATIONS AGAINST SIDE-CHANNEL ATTACKS WITH CHANGE-OF-VARIABLE TRANSFORMATIONS

      
Application Number 19122157
Status Pending
Filing Date 2023-10-18
First Publication Date 2026-05-28
Owner Cryptography Research, Inc. (USA)
Inventor
  • Marson, Mark Evan
  • Handschuh, Helena
  • Hamburg, Michael Alexander

Abstract

Disclosed aspects and implementations are directed to systems and techniques for protecting cryptographic operations using change-of-variable transformation, from a first variable to a second variable, of a first polynomial obtained using an input into a cryptographic operation and a second polynomial obtained using a cryptographic key for the cryptographic operation, performing a joint operation using the transformed first polynomial and the transformed second polynomial, and computing an output of the cryptographic operation using an output of the joint operation.

IPC Classes  ?

  • H04L 9/00 - Arrangements for secret or secure communicationsNetwork security protocols
  • H04L 9/06 - Arrangements for secret or secure communicationsNetwork security protocols the encryption apparatus using shift registers or memories for blockwise coding, e.g. D.E.S. systems
  • H04L 9/30 - Public key, i.e. encryption algorithm being computationally infeasible to invert and users' encryption keys not requiring secrecy

6.

INTEGRITY-PROTECTION AUTHENTICATION THROUGH INTERMEDIATE STATES

      
Application Number 19119218
Status Pending
Filing Date 2023-10-10
First Publication Date 2026-04-16
Owner CRYPTOGRAPHY RESEARCH, INC. (USA)
Inventor
  • Kapoor, Ajay
  • Wedig Reinbrecht, Cezar Rodolfo

Abstract

Technologies for protecting data integrity of an authentication algorithm using intermediate states are described. One inline memory encryption (IME) engine performs an authentication algorithm that uses a hash function to compute an authentication tag. The IME engine includes integrity-protection logic to store an intermediate state of a tag computation and incoming data segments. In the event of an error in the computation, the integrity-protection logic can compute the intermediate state again using a last intermediate state and the last data segment.

IPC Classes  ?

  • H04L 9/06 - Arrangements for secret or secure communicationsNetwork security protocols the encryption apparatus using shift registers or memories for blockwise coding, e.g. D.E.S. systems
  • G06F 21/64 - Protecting data integrity, e.g. using checksums, certificates or signatures
  • H04L 9/32 - Arrangements for secret or secure communicationsNetwork security protocols including means for verifying the identity or authority of a user of the system

7.

MULTI-COUNTER MEMORY ENCRYPTION SYSTEMS AND TECHNIQUES FOR TARGETED ACCESS OF INDIVIDUAL MEMORY BLOCKS

      
Application Number 19333068
Status Pending
Filing Date 2025-09-18
First Publication Date 2026-04-02
Owner Cryptography Research, Inc. (USA)
Inventor
  • Silveira, Marco Aurelio Lisboa
  • Reinbrecht, Cezar Rodolfo Wedig
  • Kapoor, Ajay

Abstract

Disclosed aspects and implementations are directed to systems and techniques for multi-counter memory encryption with targeted access of individual memory blocks. In one example, replacing a stored block in a memory device includes encrypting a replacement block using a first initialization vector (IV) having a block counter associated with a number of times the stored block has been previously replaced, replacing the stored block with the encrypted replacement block in the memory device, encrypting a second IV to obtain a tag encryption vector, the second IV including a tag counter associated with a number of times an authentication tag for a plurality of blocks has been previously updated, and updating, using the encrypted second IV, the authentication tag for the plurality of blocks.

IPC Classes  ?

  • G06F 3/06 - Digital input from, or digital output to, record carriers

8.

PROTECTION OF NEURAL NETWORKS BY OBFUSCATION OF NEURAL NETWORK OPERATIONS AND ARCHITECTURE

      
Application Number 19303671
Status Pending
Filing Date 2025-08-19
First Publication Date 2026-02-26
Owner CRYPTOGRAPHY RESEARCH, INC. (USA)
Inventor
  • Marson, Mark Evan
  • Hamburg, Michael Alexander
  • Handschuh, Helena

Abstract

Aspects of the present disclosure involve implementations that may be used to protect neural network models against adversarial attacks by obfuscating neural network operations and architecture. Obfuscation techniques include obfuscating weights and biases of neural network nodes, obfuscating activation functions used by neural networks, as well as obfuscating neural network architecture by introducing dummy operations, dummy nodes, and dummy layers into the neural networks.

IPC Classes  ?

  • G06F 21/55 - Detecting local intrusion or implementing counter-measures
  • G06F 21/14 - Protecting executable software against software analysis or reverse engineering, e.g. by obfuscation

9.

MODIFYING THE PERMISSIONS OF A SECURITY CONTEXT BASED ON THE DEVICE STATE

      
Application Number 18640829
Status Pending
Filing Date 2024-04-19
First Publication Date 2026-01-22
Owner CRYPTOGRAPHY RESEARCH, INC. (USA)
Inventor
  • Orzen, Matthew E.
  • Wittenauer, Joel

Abstract

A computing device receives a request to run an application. The application is associated with a security context. The computing device obtains one or more permissions associated with the security context and modifies the one or more permissions based on a state of the computing device. The application is run based on the modified one or more permissions.

IPC Classes  ?

  • G06F 21/60 - Protecting data
  • G06F 21/72 - Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information in cryptographic circuits

10.

REVERSE DECOMPOSITION OF INTERMEDIATE VALUES IN CRYPTOGRAPHIC APPLICATIONS

      
Application Number 19213297
Status Pending
Filing Date 2025-05-20
First Publication Date 2025-11-27
Owner Cryptography Research, Inc. (USA)
Inventor Hamburg, Michael Alexander

Abstract

Disclosed aspects and implementations are directed to systems and techniques for efficient execution of post-quantum cryptographic applications and protection of cryptographic computations against side-channel attacks. In one example, techniques for performing a cryptographic operation include generating a first value and computing, by the processing device, a second value. A low part of the second value is mapped to a high part of a product of a public value and the first value and a high part of the second value is mapped to a low part of the product of the public value and the first value. The techniques further include computing, using the second value, an output of the cryptographic operation that includes a digital signature for an input into the cryptographic operation or a ciphertext encrypting the input into the cryptographic operation.

IPC Classes  ?

  • H04L 9/06 - Arrangements for secret or secure communicationsNetwork security protocols the encryption apparatus using shift registers or memories for blockwise coding, e.g. D.E.S. systems

11.

IN-LINE MEMORY ENCRYPTION WITH POWER AWARE CACHE SYSTEM

      
Application Number 19192836
Status Pending
Filing Date 2025-04-29
First Publication Date 2025-11-13
Owner CRYPTOGRAPHY RESEARCH, INC. (USA)
Inventor
  • Petters Guse, Walter Nestor
  • Wedig Reinbrecht, Cezar Rodolfo
  • Kapoor, Ajay

Abstract

Technologies for in-line memory encryption with a power-aware cache system (IME-PACS) are described. One memory encryption circuit includes cryptographic circuitry and control circuitry. Control circuitry, in a power-off process, causes the cryptographic circuitry to encrypt the plaintext data of one or more cache entries having the first persistent valid flag set to obtain ciphertext data, and stores the ciphertext data in a memory system. The control circuitry, in a power-on process, loads the ciphertext data from the memory system for the cache entries having the first persistent valid flag set, causes the cryptographic circuitry to decrypt the ciphertext data to obtain the plaintext data, and stores the plaintext data in the one or more cache entries of the first cache.

IPC Classes  ?

  • G06F 21/72 - Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information in cryptographic circuits
  • G06F 21/64 - Protecting data integrity, e.g. using checksums, certificates or signatures
  • G06F 21/78 - Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure storage of data

12.

IN-LINE MEMORY ENCRYPTION WITH FRAGMENTED MEMORY INITIALIZATION

      
Application Number US2025027369
Publication Number 2025/235297
Status In Force
Filing Date 2025-05-01
Publication Date 2025-11-13
Owner CRYPTOGRAPHY RESEARCH, INC. (USA)
Inventor
  • Wedig Reinbrecht, Cezar Rodolfo
  • Petters Guse, Walter Nestor
  • Kapoor, Ajay

Abstract

Technologies for in-line memory encryption with fragmented memory sanitization (IME-FMS) are described. One method splits a secure memory space into a plurality of subspaces and automatically initializes a first subspace of the plurality of subspaces to start a program. The method initializes a second subspace of the plurality of subspaces in response to a request for secure memory. The method creates back-pressure in response to a request for more secure memory when there are no initialized subspaces available.

IPC Classes  ?

  • G06F 12/14 - Protection against unauthorised use of memory
  • G06F 21/78 - Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure storage of data
  • G06F 9/50 - Allocation of resources, e.g. of the central processing unit [CPU]
  • G06F 21/60 - Protecting data
  • G06F 12/00 - Accessing, addressing or allocating within memory systems or architectures

13.

LOW-LATENCY MULTI-KEY ENCRYPTION AND DECRYPTION ENGINE AND TECHNIQUES

      
Application Number 18702315
Status Pending
Filing Date 2022-10-18
First Publication Date 2025-08-14
Owner Cryptography Research, Inc. (USA)
Inventor
  • Hamburg, Michael Alexander
  • Erickson, Evan Lawrence
  • Handschuh, Helena
  • Marson, Mark Evan

Abstract

Disclosed systems and techniques involve low-latency multi-key encryption processing in which block keys are precomputed based on multiple cryptographic keys, stored, and then selected for encryption or decryption of data during run-time cryptographic operations. The block keys may be precomputed, for each cryptographic key, in such quantities that allow uninterrupted flow of encryption or decryption operations. Replacement block keys may be concurrently generated to replace the blocks being consumed and authentication values may be computed or updated. Various described techniques allow parallel processing for efficient low-latency block key generation and cryptographic operations.

IPC Classes  ?

14.

TAMPER DETECTION

      
Application Number US2024060388
Publication Number 2025/136885
Status In Force
Filing Date 2024-12-16
Publication Date 2025-06-26
Owner CRYPTOGRAPHY RESEARCH, INC. (USA)
Inventor Best, Scott, C.

Abstract

A strong-type physically unclonable function (PUF) is enrolled by storing challenges and responses to those challenges. The system iteratively challenges the PUF multiple times for each of the stored challenges and uses the responses by the PUF as a search key for a CAM function. If a response is found in the populated CAM function, the key portion or key portion indicator associated with that CAM entry is used to provide part of a larger cryptographic key. If all of the challenges result in at least one response that is a CAM "hit", then the complete cryptographic key can be assembled. If any one of the challenges does not result in a CAM "hit", the cryptographic key will be incomplete thereby preventing any functions that depend upon the cryptographic key from being accessed and/or performed.

IPC Classes  ?

  • H04L 9/32 - Arrangements for secret or secure communicationsNetwork security protocols including means for verifying the identity or authority of a user of the system
  • G09C 1/00 - Apparatus or methods whereby a given sequence of signs, e.g. an intelligible text, is transformed into an unintelligible sequence of signs by transposing the signs or groups of signs or by replacing them by others according to a predetermined system
  • G11C 11/16 - Digital stores characterised by the use of particular electric or magnetic storage elementsStorage elements therefor using magnetic elements using elements in which the storage effect is based on magnetic spin effect
  • H04L 9/08 - Key distribution

15.

MEASURING DISCRETE COMPONENT PROPERTIES TO ESTABLISH A PRINTED CIRCUIT BOARD FINGERPRINT

      
Application Number 18974508
Status Pending
Filing Date 2024-12-09
First Publication Date 2025-06-19
Owner Cryptography Research, Inc. (USA)
Inventor
  • Wittenauer, Joel
  • Orzen, Matthew E.
  • Goodwill, Gilbert

Abstract

A method for measuring discrete component properties to establish a printed circuit board (PCB) fingerprint includes determining a physical measurement of an electronic device of the PCB; comparing the determined physical measurement to a predefined range for the physical measurement of the electronic device; and responsive to the determined physical measurement being within the predefined range, generating a digital certificate. The digital certificate includes the determined physical measurement. The determined physical measurement is capable of being extracted from the digital certificate to verify whether the electronic device is authentic or is failing.

IPC Classes  ?

  • H04L 9/32 - Arrangements for secret or secure communicationsNetwork security protocols including means for verifying the identity or authority of a user of the system

16.

DEVICE-BOUND, REPLAY-PROTECTED APPLICATIONS FOR A ROOT OF TRUST

      
Application Number 18954869
Status Pending
Filing Date 2024-11-21
First Publication Date 2025-05-29
Owner Cryptography Research, Inc. (USA)
Inventor
  • Wittenauer, Joel
  • Orzen, Matthew E.

Abstract

A method for provisioning a device-bound, replay-protected software image may include obtaining, from a provisioning system, a software image and a digital signature associated with the software image. The method may include applying a hash function to the software image and a hash message authentication code (HMAC) to generate a hash of the software image. The HMAC may include an authentication code derived from first data provided by a root of trust (RoT). The first data may include a nonce generated by the RoT or system information associated with the RoT. The method may include verifying, using a public key of the provisioning system, the digital signature. The method may include, responsive to the verification of the digital signature, causing the software image to execute.

IPC Classes  ?

  • H04L 9/32 - Arrangements for secret or secure communicationsNetwork security protocols including means for verifying the identity or authority of a user of the system
  • H04L 9/08 - Key distribution

17.

TECHNIQUES AND DEVICES FOR CONFIGURABLE MEMORY ENCRYPTION AND AUTHENTICATION

      
Application Number 18839408
Status Pending
Filing Date 2023-02-24
First Publication Date 2025-05-22
Owner Cryptography Research, Inc. (USA)
Inventor
  • Kapoor, Ajay
  • Van Loon, Marcel

Abstract

Disclosed systems and techniques involve flexible encryption, decryption, retrieval, and authentication of data. The systems may include a cryptographic processor that, in a first selectable mode of operation is configured to identify plaintext blocks, generate encrypted ciphertext blocks, process sequentially the ciphertext blocks to obtain an authentication value, encrypt the authentication value, and store the ciphertext blocks and an authentication tag, obtained based on the encrypted authentication value. In a second selectable mode, the cryptographic processor may perform ciphertext block encryption but forgo obtaining the authentication value.

IPC Classes  ?

  • G06F 12/14 - Protection against unauthorised use of memory
  • G06F 11/10 - Adding special bits or symbols to the coded information, e.g. parity check, casting out nines or elevens
  • H04L 9/06 - Arrangements for secret or secure communicationsNetwork security protocols the encryption apparatus using shift registers or memories for blockwise coding, e.g. D.E.S. systems

18.

PROTECTION OF ADDITIVE FAST FOURIER TRANSFORMS AGAINST SIDE-CHANNEL ATTACKS IN CRYPTOGRAPHIC OPERATIONS

      
Application Number US2023033629
Publication Number 2025/080241
Status In Force
Filing Date 2023-09-25
Publication Date 2025-04-17
Owner CRYPTOGRAPHY RESEARCH, INC. (USA)
Inventor
  • Marson, Mark Evan
  • Handschuh, Helena
  • Hamburg, Michael Alexander

Abstract

Aspects and implementations disclosed are directed to systems and techniques protecting cryptographic operations that involve computing a discrete transform (DT) of a polynomial by randomizing basis vectors of a finite field, identifying a first auxiliary polynomial and a second auxiliary polynomial, computing the DT of the polynomial using the randomized basis vectors, the DT of the first auxiliary polynomial, and the DT of the second auxiliary polynomial, and computing a plaintext output corresponding to the ciphertext input using the DT of the polynomial. Further protection techniques include masking the polynomial and computing the DT of the polynomial using the DT of the masked polynomial.

IPC Classes  ?

  • H04L 9/30 - Public key, i.e. encryption algorithm being computationally infeasible to invert and users' encryption keys not requiring secrecy
  • H04L 9/08 - Key distribution
  • H04L 9/06 - Arrangements for secret or secure communicationsNetwork security protocols the encryption apparatus using shift registers or memories for blockwise coding, e.g. D.E.S. systems

19.

MULTI-LANE CRYPTOGRAPHIC ENGINE AND OPERATIONS THEREOF

      
Application Number 18291010
Status Pending
Filing Date 2022-07-13
First Publication Date 2025-03-27
Owner CRYPTOGRAPHY RESEARCH, INC. (USA)
Inventor
  • Hamburg, Michael Alexander
  • Singh, Arvind
  • De Meyer, Lauren

Abstract

Aspects of the present disclosure involve a cryptographic processor that includes four or more multiplication circuits, two or more addition circuits, and two or more memory circuits. The cryptographic engine is configured to perform a variety of operations, including modular multiplication, modular inversion, matrix multiplication, Montgomery multiplication, computations of Jacobi symbols, and the like. The cryptographic engine support streaming computations where at least some of the multiplication circuits operate on multipliers and/or multiplicands that are also used during other cycles of computations.

IPC Classes  ?

  • H04L 9/30 - Public key, i.e. encryption algorithm being computationally infeasible to invert and users' encryption keys not requiring secrecy
  • G06F 17/16 - Matrix or vector computation

20.

Multiple host memory controller

      
Application Number 18902102
Grant Number 12656978
Status In Force
Filing Date 2024-09-30
First Publication Date 2025-03-20
Grant Date 2026-06-16
Owner Cryptography Research, Inc. (USA)
Inventor
  • Thatcher, Thomas J.
  • Wang, Bryan Jason

Abstract

Multiple (e.g., two) hosts access a single memory channel (and/or device) via a memory controller. The single memory channel/device can support at most one access at a time. To reduce contention between the multiple hosts, the memory controller comprises multiple (e.g., two), independent, host ports. Each host port is associated with a write buffer(s) in the memory controller that stores write data at least until the memory controller writes the data to the memory channel. Data stored in a write buffer may be used to respond to memory access commands (e.g., reads or writes) on the ports without accessing the memory channel. In this manner, the hosts do not directly contend with each other for the single memory channel or the memory controller.

IPC Classes  ?

  • G06F 3/06 - Digital input from, or digital output to, record carriers

21.

Low-latency multi-domain masking

      
Application Number 18716504
Grant Number 12554894
Status In Force
Filing Date 2022-11-28
First Publication Date 2025-01-30
Grant Date 2026-02-17
Owner CRYPTOGRAPHY RESEARCH, INC. (USA)
Inventor
  • Hutter, Michael
  • Abril, Victor Manuel Arribas

Abstract

A multi-domain masked AND gate includes inner-domain calculations, re-sharing, register stage, cross-domain calculations, and compression. The inner-domain multiplication and the re-sharing are calculated prior to storing the re-shared variables in the register stage. Thus, the inputs to the cross-domain multiplication and the compression are performed on variables that have been refreshed by additional randomness. This AND gate does not need statistically independent inputs, is secure in the probing model even in the presence of glitches, also known as the robust probing model. A two-domain input and two domain output AND gate can be implemented using six (6) registers, four (4) two input logical AND gates, and eight (8) exclusive-OR (XOR) gates. The AND gate may also be used to implement an AES S-box that has two (2) register stages and takes two (2) clock cycles per computation.

IPC Classes  ?

  • G06F 21/75 - Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information by inhibiting the analysis of circuitry or operation, e.g. to counteract reverse engineering
  • G06F 9/30 - Arrangements for executing machine instructions, e.g. instruction decode

22.

MASKING WITH EFFICIENT UNMASKING VIA DOMAIN EMBEDDING IN CRYPTOGRAPHIC DEVICES AND APPLICATIONS

      
Application Number 18784550
Status Pending
Filing Date 2024-07-25
First Publication Date 2025-01-30
Owner CRYPTOGRAPHY RESEARCH, INC. (USA)
Inventor
  • Marson, Mark Evan
  • Hamburg, Michael Alexander
  • Handschuh, Helena

Abstract

Disclosed aspects and implementations are directed to systems and techniques for protecting cryptographic operations against side-channel attacks. In one example, polynomials associated with secret data and public data defined on a working domain having a first dimension are mapped to an auxiliary domain having a larger second dimension. The mapped polynomials are masked using masking polynomials associated with a kernel of a homomorphism transformation from the auxiliary domain to the working domain. One or more computations are then performed on the masked polynomials in the auxiliary domain and an output is transformed from the auxiliary domain to the working domain.

IPC Classes  ?

  • H04L 9/30 - Public key, i.e. encryption algorithm being computationally infeasible to invert and users' encryption keys not requiring secrecy
  • H04L 9/00 - Arrangements for secret or secure communicationsNetwork security protocols

23.

PROTECTION OF NEURAL NETWORKS BY OBFUSCATION OF NEURAL NETWORK ARCHITECTURE

      
Application Number 18794631
Status Pending
Filing Date 2024-08-05
First Publication Date 2025-01-30
Owner CRYPTOGRAPHY RESEARCH, INC. (USA)
Inventor
  • Marson, Mark Evan
  • Hamburg, Michael Alexander
  • Handschuh, Helena

Abstract

Aspects of the present disclosure involve implementations that may be used to protect neural network models against adversarial attacks by obfuscating neural network operations and architecture. Obfuscation techniques include obfuscating weights and biases of neural network nodes, obfuscating activation functions used by neural networks, as well as obfuscating neural network architecture by introducing dummy operations, dummy nodes, and dummy layers into the neural networks.

IPC Classes  ?

  • G06F 21/14 - Protecting executable software against software analysis or reverse engineering, e.g. by obfuscation
  • G06N 3/02 - Neural networks

24.

Secure asset management infrastructure for enforcing access control policies

      
Application Number 18702638
Grant Number 12665904
Status In Force
Filing Date 2022-10-18
First Publication Date 2025-01-16
Grant Date 2026-06-23
Owner Cryptography Research, Inc. (USA)
Inventor
  • Chamaraj, Sangeetha
  • Orzen, Matthew E.
  • Pochuev, Denis Alexandrovich

Abstract

An application executing at a first platform receives, from a tester device, a first request to generate a secure data asset. Responsive to authenticating the client, the application sends, to a second platform, a second request to determine whether the client has access to the secure data asset. Responsive to receiving an indication, from the second platform, that the client has access to the secure data asset, the application performs one or more operations to generate the secure data asset. The application sends, to the tester device, the generated secure data asset.

IPC Classes  ?

  • H04L 29/00 - Arrangements, apparatus, circuits or systems, not covered by a single one of groups
  • H04L 9/40 - Network security protocols

25.

SUPPLY CHAIN SECURITY MANAGER

      
Application Number 18739831
Status Pending
Filing Date 2024-06-11
First Publication Date 2024-12-26
Owner CRYPTOGRAPHY RESEARCH, INC. (USA)
Inventor
  • Orzen, Matthew E.
  • Wittenauer, Joel

Abstract

A system receives, from a first provisioning entity, a request for first secure device data related to a semiconductor device. The first secure device data is associated with one or more provisioning operations performed, on the semiconductor device, by a second provisioning entity. Based on determining that the first provisioning entity has permission to access the first secure device data, the first secure device data is provided to the first provisioning entity. Second secure device data associated with one or more provisioning operations performed by the first provisioning entity on the semiconductor device is received from the first provisioning entity.

IPC Classes  ?

  • G06F 21/62 - Protecting access to data via a platform, e.g. using keys or access control rules
  • G06F 21/44 - Program or device authentication

26.

PROTECTION OF NEURAL NETWORKS BY OBFUSCATION OF ACTIVATION FUNCTIONS

      
Application Number 18818336
Status Pending
Filing Date 2024-08-28
First Publication Date 2024-12-19
Owner Cryptography Research, Inc. (USA)
Inventor
  • Marson, Mark Evan
  • Hamburg, Michael Alexander
  • Handschuh, Helena

Abstract

Aspects of the present disclosure involve implementations that may be used to protect neural network models against adversarial attacks by obfuscating neural network operations and architecture. Obfuscation techniques include obfuscating weights and biases of neural network nodes, obfuscating activation functions used by neural networks, as well as obfuscating neural network architecture by introducing dummy operations, dummy nodes, and dummy layers into the neural networks.

IPC Classes  ?

  • G06F 21/62 - Protecting access to data via a platform, e.g. using keys or access control rules
  • G06F 21/14 - Protecting executable software against software analysis or reverse engineering, e.g. by obfuscation
  • G06N 3/02 - Neural networks
  • G06N 3/048 - Activation functions
  • G06V 10/82 - Arrangements for image or video recognition or understanding using pattern recognition or machine learning using neural networks

27.

PROTECTION OF HOMOMORPHIC ENCRYPTION COMPUTATIONS BY MASKING WITHOUT UNMASKING

      
Application Number 18732270
Status Pending
Filing Date 2024-06-03
First Publication Date 2024-12-12
Owner Cryptography Research, Inc. (USA)
Inventor
  • Marson, Mark Evan
  • Hamburg, Michael Alexander
  • Handschuh, Helena

Abstract

Aspects and implementations are directed to systems and techniques for protecting cryptographic operations against side-channel attacks by masking a ciphertext data using one or more masks randomly sampled from a null space associated with a tensor representation of a secret data and generating a plaintext data using the masked ciphertext data.

IPC Classes  ?

  • H04L 9/00 - Arrangements for secret or secure communicationsNetwork security protocols
  • H04L 9/06 - Arrangements for secret or secure communicationsNetwork security protocols the encryption apparatus using shift registers or memories for blockwise coding, e.g. D.E.S. systems

28.

RECONFIGURABLE PROCESSING UNITS FOR EFFICIENT SUPPORT OF MULTIPLE POST-QUANTUM CRYPTOGRAPHIC ALGORITHMS

      
Application Number US2024032633
Publication Number 2024/254198
Status In Force
Filing Date 2024-06-05
Publication Date 2024-12-12
Owner CRYPTOGRAPHY RESEARCH, INC. (USA)
Inventor
  • Hamburg, Michael Alexander
  • Singh, Arvind
  • De Meyer, Lauren Kristin
  • Hoerder, Simon

Abstract

Disclosed aspects and implementations are directed to devices and techniques for performing cryptographic operations using post-quantum algorithms. Reconfigurable processing devices supports multiple algorithms that deploy various integer and polynomial arithmetic operations including Number Theoretic Transforms, inverse Number Theoretic Transforms, pointwise polynomial multiplications, pairwise polynomial multiplications, pointwise-pairwise polynomial multiplications, Karatsuba multiplications, and/or other operations. The reconfigurable processing device(s) may be integrated into a streaming pipeline that includes a hash value generator and a sampler with matching throughputs for efficient utilization of computational and memory resources.

IPC Classes  ?

  • G06F 17/10 - Complex mathematical operations
  • G06F 21/72 - Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information in cryptographic circuits
  • G06F 7/544 - Methods or arrangements for performing computations using exclusively denominational number representation, e.g. using binary, ternary, decimal representation using non-contact-making devices, e.g. tube, solid state deviceMethods or arrangements for performing computations using exclusively denominational number representation, e.g. using binary, ternary, decimal representation using unspecified devices for evaluating functions by calculation
  • H04L 9/00 - Arrangements for secret or secure communicationsNetwork security protocols

29.

FUNCTIONS WITH A PRE-CHARGE OPERATION AND AN EVALUATION OPERATION

      
Application Number 18670037
Status Pending
Filing Date 2024-05-21
First Publication Date 2024-11-28
Owner Cryptography Research, Inc. (USA)
Inventor
  • Sasdrich, Pascal
  • Bilgin, Begül
  • Hutter, Michael

Abstract

An input data may be received. A portion of a cryptographic operation may be performed with the received input data at a first function component. During the performance of the cryptographic operation at the first function component, a pre-charge operation may be performed at a second function component. Furthermore, the second function component may be used to perform another portion of the cryptographic operation with a result of the portion of the cryptographic operation performed at the first function component.

IPC Classes  ?

  • H04L 9/06 - Arrangements for secret or secure communicationsNetwork security protocols the encryption apparatus using shift registers or memories for blockwise coding, e.g. D.E.S. systems
  • H04L 9/00 - Arrangements for secret or secure communicationsNetwork security protocols

30.

Low latency metadata decryption using hash and pseudorandom functions

      
Application Number 18659987
Grant Number 12634118
Status In Force
Filing Date 2024-05-09
First Publication Date 2024-11-21
Grant Date 2026-05-19
Owner Cryptography Research, Inc. (USA)
Inventor
  • Hamburg, Michael Alexander
  • Erickson, Evan Lawrence
  • Kapoor, Ajay

Abstract

Systems and techniques for cryptographically protecting data in a computer memory are disclosed. The techniques include dividing the data into a first portion and a second portion, encrypting the first portion of the data to create a first stored form of the data, encrypting the second portion of the data, and storing, in the computer memory, the first stored form of the data and a second stored form of the data. The techniques include, to encrypt the second portion, calculating a hash based on the first stored form of the data, applying a first pseudorandom function to the hash to obtain a bit sequence, and combining the bit sequence with the second portion of the data to obtain the second stored form of the data.

IPC Classes  ?

  • H04L 9/06 - Arrangements for secret or secure communicationsNetwork security protocols the encryption apparatus using shift registers or memories for blockwise coding, e.g. D.E.S. systems

31.

MULTI-LANE CRYPTOGRAPHIC ENGINES WITH SYSTOLIC ARCHITECTURE AND OPERATIONS THEREOF

      
Application Number 18290720
Status Pending
Filing Date 2022-07-14
First Publication Date 2024-11-07
Owner CRYPTOGRAPHY RESEARCH, INC. (USA)
Inventor
  • Hamburg, Michael Alexander
  • Singh, Arvind

Abstract

Aspects of the present disclosure involve a cryptographic processor that includes a systolic array having a plurality of processing lanes (PLs), each PL including a systolic sub-array of two or more processing elements (PEs), each PE being configured to multiply two numbers to obtain and store a multiplication product. The cryptographic processor is configured to efficiently perform a variety of operations, including multiplication of large numbers, modular reduction, Montgomery reduction, and the like.

IPC Classes  ?

  • G06F 7/544 - Methods or arrangements for performing computations using exclusively denominational number representation, e.g. using binary, ternary, decimal representation using non-contact-making devices, e.g. tube, solid state deviceMethods or arrangements for performing computations using exclusively denominational number representation, e.g. using binary, ternary, decimal representation using unspecified devices for evaluating functions by calculation
  • G06F 5/06 - Methods or arrangements for data conversion without changing the order or content of the data handled for changing the speed of data flow, i.e. speed regularising
  • G06F 7/72 - Methods or arrangements for performing computations using a digital non-denominational number representation, i.e. number representation without radixComputing devices using combinations of denominational and non-denominational quantity representations using residue arithmetic

32.

PROVISIONING A VOLATILE SECURITY CONTEXT IN A ROOT OF TRUST

      
Application Number 18641965
Status Pending
Filing Date 2024-04-22
First Publication Date 2024-10-31
Owner CRYPTOGRAPHY RESEARCH, INC. (USA)
Inventor
  • Wittenauer, Joel
  • Orzen, Matthew E.

Abstract

A first device receives, from a second device, a request to provision a security context for the second device. The first device transmits a nonce value to the second device and receives, from the second device, a data structure encoding the security context and a cryptographically signed digest of a combination of the data structure, the nonce value, and a public key. The first device determines a first digest using the nonce value and cryptographically signed digest, and a second digest using the data structure, the nonce value, and the public key. Responsive to determining that the first digest matches the second digest, the first device provisions the security context for the second device by storing the security context on the volatile memory.

IPC Classes  ?

  • H04L 9/32 - Arrangements for secret or secure communicationsNetwork security protocols including means for verifying the identity or authority of a user of the system
  • H04L 9/08 - Key distribution

33.

Protection of secret data using unprotected data path

      
Application Number 18646554
Grant Number 12665741
Status In Force
Filing Date 2024-04-25
First Publication Date 2024-10-31
Grant Date 2026-06-23
Owner CRYPTOGRAPHY RESEARCH, INC. (USA)
Inventor
  • Hamburg, Michael Alexander
  • Bilgin, Begül

Abstract

Disclosed systems and techniques include a cryptographic processor for processing of both unprotected data and protected data using an unprotected data path. In one implementation, the cryptographic processor includes a processing unit, and a control unit to selectively cause the processing unit to operate in a public mode or a secure mode. In the public mode, the processing unit performs a computational operation to compute a nonlinear function of a public data. In the secure mode, the processing unit computes, over a plurality of iterations, a plurality of shares of the nonlinear function of a secure data. At each iteration, the processing unit performs multiple instances of the computational operation to compute a respective share of the nonlinear function of the secure data.

IPC Classes  ?

  • H04L 9/06 - Arrangements for secret or secure communicationsNetwork security protocols the encryption apparatus using shift registers or memories for blockwise coding, e.g. D.E.S. systems

34.

Generating a target data based on a function associated with a physical variation of a device

      
Application Number 18644084
Grant Number 12417141
Status In Force
Filing Date 2024-04-23
First Publication Date 2024-10-17
Grant Date 2025-09-16
Owner Cryptography Research, Inc. (USA)
Inventor
  • Marson, Mark Evan
  • Best, Scott C.
  • Handschuh, Helena
  • Wu, Winthrop John

Abstract

A value corresponding to a physical variation of a device may be received. Furthermore, helper data associated with the physical variation of the device may be received. A result data may be generated based on a combination of the value corresponding to the physical variation of the device and the helper data. An error correction operation may be performed on the result data to identify one or more code words associated with the error correction operation. Subsequently, a target data may be generated based on the one or more code words.

IPC Classes  ?

  • G06F 11/10 - Adding special bits or symbols to the coded information, e.g. parity check, casting out nines or elevens
  • H04L 9/08 - Key distribution
  • H04L 9/32 - Arrangements for secret or secure communicationsNetwork security protocols including means for verifying the identity or authority of a user of the system

35.

CRYPTOGRAPHIC KEY USAGE MANAGEMENT

      
Application Number US2024018775
Publication Number 2024/191715
Status In Force
Filing Date 2024-03-07
Publication Date 2024-09-19
Owner CRYPTOGRAPHY RESEARCH, INC. (USA)
Inventor
  • Wu, Winthrop, John
  • Wang, Bryan, Jason

Abstract

A system limits the use (e.g., number of encryptions and/or decryptions using that key value) of cryptographic key values. When a key value's usage count exceeds the limit, that value is "retired", and a new key value is selected. Key identifiers and a key versions are associated with each encrypted data block. The key identifiers are also associated with current key values, a current version indicators, and usage indicators. Key identifiers may also be associated with one or more previous (i.e., 'retired') version indicators and corresponding previous key values. When an encrypted data block associated with a given key identifier is accessed, the key version indicator associated with that block, and the key version indicators associated with the current and previous keys, are used to select the proper key from either the current key value or one of the previous key values.

IPC Classes  ?

  • G06F 21/60 - Protecting data
  • H04L 9/00 - Arrangements for secret or secure communicationsNetwork security protocols
  • G06F 8/70 - Software maintenance or management

36.

Determining a physically unclonable function (PUF) selection vector

      
Application Number 18591554
Grant Number 12562925
Status In Force
Filing Date 2024-02-29
First Publication Date 2024-09-19
Grant Date 2026-02-24
Owner CRYPTOGRAPHY RESEARCH, INC. (USA)
Inventor Best, Scott C.

Abstract

Technologies for generating an M-bit selection vector for a selector circuit that receives as input M binary values from a set of entropy-generation elements and outputs N binary values responsive to the M-bit selection vector are described. N bits in the M-bit selection vector are set to a first logic state, and M-N bits of the M-bit selection vector are set to a second logic state. A determination of which N bits in the M-bit selection vector are set to the first logic state is determined by a process. The process includes determining an accumulated Hamming weight value for M bit positions of the M-bit selection vector using K samples and identifying N bit positions in the M-bit selection vector using the accumulated Hamming weight values. The process sets the N bits corresponding to the N bit positions in the M-bit selection vector to the first logic state.

IPC Classes  ?

  • H04L 9/32 - Arrangements for secret or secure communicationsNetwork security protocols including means for verifying the identity or authority of a user of the system
  • H04L 9/08 - Key distribution

37.

INTEGRITY TREE ARCHITECTURE FOR DATA AUTHENTICATION

      
Application Number US2024012829
Publication Number 2024/158947
Status In Force
Filing Date 2024-01-24
Publication Date 2024-08-02
Owner CRYPTOGRAPHY RESEARCH, INC. (USA)
Inventor
  • Kapoor, Ajay
  • Best, Scott C.
  • Wedig Reinbrecht, Cezar Rodolfo

Abstract

Technologies for providing an integrity tree architecture that reduces the number of memory accesses and verification operations needed to perform a read operation. One inline memory encryption (IME) engine performs operations that include receiving a read command for data stored at a data block. The operations further include obtaining a first authentication tag associated with the data block, a first counter value used to generate the first authentication tag; a root counter value, and an intermediate tag. The operations further include generating a second authentication tag based on the intermediate tag, the first counter value, the root counter value, and the data from the data block, and responsive to determining that a value of the first authentication tag matches a value of the second authentication tag, sending, to the host system, the data stored at the data block.

IPC Classes  ?

  • H04L 9/40 - Network security protocols
  • H04L 9/32 - Arrangements for secret or secure communicationsNetwork security protocols including means for verifying the identity or authority of a user of the system
  • H04L 9/06 - Arrangements for secret or secure communicationsNetwork security protocols the encryption apparatus using shift registers or memories for blockwise coding, e.g. D.E.S. systems
  • H04L 9/00 - Arrangements for secret or secure communicationsNetwork security protocols

38.

Obfuscation of data in a memory

      
Application Number 18531350
Grant Number 12423026
Status In Force
Filing Date 2023-12-06
First Publication Date 2024-06-27
Grant Date 2025-09-23
Owner Cryptography Research, Inc. (USA)
Inventor
  • Wu, Winthrop John
  • Wang, Bryan
  • Kaniz, Marufa
  • Ozari De Almeida, Guilherme
  • Best, Scott C.

Abstract

A request to perform a memory operation addressed to a first address corresponding to a first logical unit of logical units of a memory is received. Address mask data that corresponds to the logical units is identified. Multiple transformed addresses are determined using the first address and the address mask data. The transformed addresses can include a target address corresponding to the first logical unit and additional addresses corresponding to other logical units. The memory operation is performed at the target address corresponding to the first logical unit and dummy memory operations are performed at the additional addresses corresponding to the additional logical units.

IPC Classes  ?

  • G06F 3/06 - Digital input from, or digital output to, record carriers

39.

STRUCTURAL CONTROL FLOW INTEGRITY FOR PROTECTION AGAINST CODE REUSE ATTACKS

      
Application Number US2023083641
Publication Number 2024/137289
Status In Force
Filing Date 2023-12-12
Publication Date 2024-06-27
Owner CRYPTOGRAPHY RESEARCH, INC. (USA)
Inventor
  • Wu, Winthrop John
  • Wittenauer, Joel
  • Aho, Tero
  • Pasztory, Akos
  • Singh, Arvind
  • De Meyer, Lauren Kristin

Abstract

Systems and techniques for secure execution of a computing code and protection against code reuse attacks are disclosed. The techniques include fetching, by a processor, a first instruction of the computing code, determining a first verification value, wherein the first verification value is based, at least in part, on one or more attributes of the first instruction, accessing a first stored verification value, and evaluating, using the first verification value and the first stored verification value, execution integrity of the computing code.

IPC Classes  ?

  • G06F 21/56 - Computer malware detection or handling, e.g. anti-virus arrangements
  • G06F 21/52 - Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems during program execution, e.g. stack integrity, buffer overflow or preventing unwanted data erasure
  • G06F 12/14 - Protection against unauthorised use of memory
  • G06F 21/57 - Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
  • G06F 21/00 - Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity

40.

Unlimited reprovisionable hardware root of trust

      
Application Number 18516605
Grant Number 12645807
Status In Force
Filing Date 2023-11-21
First Publication Date 2024-05-30
Grant Date 2026-06-02
Owner Cryptography Research, Inc. (USA)
Inventor Wu, Winthrop John

Abstract

Technologies for protecting a secure context in a hardware root of trust (ROT) are described. One hardware ROT includes key generation logic and a cryptographic circuit. The key generation logic generates a first key from a value, corresponding to a physical variation of the hardware ROT, and first helper data associated with the physical variation of the hardware ROT. The key generation logic generates a second key from the value and second helper data associated with the physical variation of the hardware ROT. The cryptographic circuit receives a first encrypted secure context from off-chip storage and decrypts the first encrypted secure context using the first key to obtain a secure context. The cryptographic circuit encrypts the secure context using the second key to obtain a second encrypted secure context and stores the second encrypted secure context in the off-chip storage.

IPC Classes  ?

  • G06F 21/60 - Protecting data
  • G06F 21/72 - Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information in cryptographic circuits
  • H04L 9/14 - Arrangements for secret or secure communicationsNetwork security protocols using a plurality of keys or algorithms

41.

PERFORMING VERIFIED RESTORE OF DATA ASSETS IN A CRYPTOGRAPHIC DEVICE

      
Application Number 18520068
Status Pending
Filing Date 2023-11-27
First Publication Date 2024-05-30
Owner CRYPTOGRAPHY RESEARCH, INC. (USA)
Inventor Orzen, Matthew E.

Abstract

A first platform receives a request to generate a verification package for restoring a backup image at a second platform. The first platform generates a first data asset. The first platform generates a second data asset based on the first data asset and an asset list associated with the backup image. The first platform generates a third data asset based on the asset list. The first platform sends a response that includes the verification package comprising the first data asset, the second data asset, and the third data asset.

IPC Classes  ?

  • H04L 9/32 - Arrangements for secret or secure communicationsNetwork security protocols including means for verifying the identity or authority of a user of the system
  • H04L 9/08 - Key distribution

42.

Split counters with dynamic epoch tracking for cryptographic protection of secure data

      
Application Number 18500975
Grant Number 12579320
Status In Force
Filing Date 2023-11-02
First Publication Date 2024-05-09
Grant Date 2026-03-17
Owner Cryptography Research, Inc (USA)
Inventor Hamburg, Michael Alexander

Abstract

Aspects and implementations include systems and techniques for efficient protection of secret data against replay attacks, including updating a unit of data of a plurality of units of data, updating an individual portion of a counter for the unit of data, the counter including an individual portion and a common portion, accessing a pointer value that distinguishes counters corresponding to a first epoch from counters corresponding to a second epoch, selecting, based on at least the pointer value and a value of the individual portion of the counter, an update value, and modifying the pointer value using the update value.

IPC Classes  ?

  • G06F 21/64 - Protecting data integrity, e.g. using checksums, certificates or signatures
  • G06F 21/60 - Protecting data
  • G06F 21/78 - Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure storage of data

43.

INTEGRITY-PROTECTION AUTHENTICATION THROUGH INTERMEDIATE STATES

      
Application Number US2023034845
Publication Number 2024/086043
Status In Force
Filing Date 2023-10-10
Publication Date 2024-04-25
Owner CRYPTOGRAPHY RESEARCH, INC. (USA)
Inventor
  • Kapoor, Ajay
  • Wedig Reinbrecht, Cezar Rodolfo

Abstract

Technologies for protecting data integrity of an authentication algorithm using intermediate states are described. One inline memory encryption (IME) engine performs an authentication algorithm that uses a hash function to compute an authentication tag. The IME engine includes integrity-protection logic to store an intermediate state of a tag computation and incoming data segments. In the event of an error in the computation, the integrity-protection logic can compute the intermediate state again using a last intermediate state and the last data segment.

IPC Classes  ?

  • G06F 21/00 - Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
  • H04L 9/32 - Arrangements for secret or secure communicationsNetwork security protocols including means for verifying the identity or authority of a user of the system
  • G06F 17/00 - Digital computing or data processing equipment or methods, specially adapted for specific functions

44.

PROTECTION OF POLYNOMIAL CRYPTOGRAPHIC OPERATIONS AGAINST SIDE-CHANNEL ATTACKS WITH CHANGE-OF-VARIABLE TRANSFORMATIONS

      
Application Number US2023035437
Publication Number 2024/086243
Status In Force
Filing Date 2023-10-18
Publication Date 2024-04-25
Owner CRYPTOGRAPHY RESEARCH, INC. (USA)
Inventor
  • Marson, Mark Evan
  • Handschuh, Helena
  • Hamburg, Michael Alexander

Abstract

Disclosed aspects and implementations are directed to systems and techniques for protecting cryptographic operations using change-of-variable transformation, from a first variable to a second variable, of a first polynomial obtained using an input into a cryptographic operation and a second polynomial obtained using a cryptographic key for the cryptographic operation, performing a joint operation using the transformed first polynomial and the transformed second polynomial, and computing an output of the cryptographic operation using an output of the joint operation.

IPC Classes  ?

  • H04L 9/00 - Arrangements for secret or secure communicationsNetwork security protocols
  • G06F 9/30 - Arrangements for executing machine instructions, e.g. instruction decode

45.

Protection of neural networks by obfuscation of neural network operations and architecture

      
Application Number 18267773
Grant Number 12393679
Status In Force
Filing Date 2021-12-16
First Publication Date 2024-03-07
Grant Date 2025-08-19
Owner CRYPTOGRAPHY RESEARCH, INC. (USA)
Inventor
  • Marson, Mark Evan
  • Hamburg, Michael Alexander
  • Handschuh, Helena

Abstract

Aspects of the present disclosure involve implementations that may be used to protect neural network models against adversarial attacks by obfuscating neural network operations and architecture. Obfuscation techniques include obfuscating weights and biases of neural network nodes, obfuscating activation functions used by neural networks, as well as obfuscating neural network architecture by introducing dummy operations, dummy nodes, and dummy layers into the neural networks.

IPC Classes  ?

  • G06F 21/55 - Detecting local intrusion or implementing counter-measures
  • G06F 21/14 - Protecting executable software against software analysis or reverse engineering, e.g. by obfuscation

46.

Encrypted physically unclonable function circuit helper data

      
Application Number 17766414
Grant Number 12683811
Status In Force
Filing Date 2020-09-28
First Publication Date 2024-02-15
Grant Date 2026-07-14
Owner Cryptography Research, Inc. (USA)
Inventor
  • Best, Scott C.
  • Wittenauer, Joel

Abstract

Multiple helper data solutions (a.k.a., helper data blocks), and therefore multiple possible PUF output values, are generated for a given integrated circuit die. These helper data blocks are encrypted and stored in a nonvolatile memory on the integrated circuit die. Each helper data block is encrypted such that each helper data block can only be decrypted by a decryption key that is different from the other encrypted helper data blocks stored on that integrated circuit die. The keys to decrypt the multiple helper data blocks are released one at a time and spread over time. Because the helper data is encrypted, each PUF output value is only discoverable when its associated key is released. Accordingly, counterfeit systems or integrated circuits will need to be re-reverse engineered each time a new key is released.

IPC Classes  ?

  • H04L 9/32 - Arrangements for secret or secure communicationsNetwork security protocols including means for verifying the identity or authority of a user of the system
  • H04L 9/08 - Key distribution

47.

VERIFIABLE REMOTE RESOURCE MANAGEMENT FOR CRYPTOGRAPHIC DEVICES

      
Application Number 18229328
Status Pending
Filing Date 2023-08-02
First Publication Date 2024-02-15
Owner Cryptography Research, Inc. (USA)
Inventor
  • Marson, Mark Evan
  • Nguyen, Thi
  • Orzen, Matthew Evan

Abstract

Aspects of the present disclosure involve a method, a system and a computer readable memory to perform a secure update of a target device, including communicating an update instruction to the target device, generating one or more data values using the update instruction, generating a first authentication value using the data value(s), receiving a second authentication value from the target device, wherein the second authentication value is generated by the target device in response to the update instruction, and determining whether the secure update has been successful based on a comparison of the first authentication value and the second authentication value.

IPC Classes  ?

48.

Securely provisioning a secure data asset to a target device using an authorization token

      
Application Number 18221247
Grant Number 12506609
Status In Force
Filing Date 2023-07-12
First Publication Date 2024-01-18
Grant Date 2025-12-23
Owner Cryptography Research, Inc. (USA)
Inventor Orzen, Matthew Evan

Abstract

A request, from a tester device, to generate a secure data asset to be securely provisioned to a target device is received by an appliance cluster. The request includes an authorization token. Responsive to receiving the request, one or more verification operations to determine whether the tester device is authorized to request the generation of the secure data asset is performed based on the authorization token. Responsive to determining that the tester device is authorized to request the generation of the secure data asset, a generation of the secure data asset by a hardware security module (HSM) is caused. The generated secure data asset is sent to the tester device in response to the request to generate the secure data asset.

IPC Classes  ?

  • H04L 9/32 - Arrangements for secret or secure communicationsNetwork security protocols including means for verifying the identity or authority of a user of the system
  • H04L 9/08 - Key distribution

49.

Encryption of error correction data using symbol-level ciphers

      
Application Number 18204694
Grant Number 12580731
Status In Force
Filing Date 2023-06-01
First Publication Date 2023-12-07
Grant Date 2026-03-17
Owner CRYPTOGRAPHY RESEARCH, INC. (USA)
Inventor Hamburg, Michael Alexander

Abstract

Aspects and implementations include systems and techniques for encryption and decryption of error-corrected codewords for combined protection against corruption of data and adversarial attacks, including obtaining a block of data that has a first plurality of symbols, generating, based on the first plurality of symbols, a second plurality of symbols, wherein the second plurality of symbols includes one or more error correction symbols for the first plurality of symbols, encrypting the second plurality of symbols using a set of symbol-level ciphers (SLCs) to obtain an encrypted plurality of symbols, and using the encrypted plurality of symbols in a computer operation.

IPC Classes  ?

  • H04L 9/06 - Arrangements for secret or secure communicationsNetwork security protocols the encryption apparatus using shift registers or memories for blockwise coding, e.g. D.E.S. systems
  • G06F 11/10 - Adding special bits or symbols to the coded information, e.g. parity check, casting out nines or elevens
  • H03M 13/03 - Error detection or forward error correction by redundancy in data representation, i.e. code words containing more digits than the source words

50.

Secure feature and key management in integrated circuits

      
Application Number 18216093
Grant Number 12113786
Status In Force
Filing Date 2023-06-29
First Publication Date 2023-11-30
Grant Date 2024-10-08
Owner Cryptography Research, Inc. (USA)
Inventor
  • Kocher, Paul Carl
  • Jun, Benjamin Chen-Min
  • Leiserson, Andrew John

Abstract

A mechanism for providing secure feature and key management in integrated circuits is described. An example integrated circuit includes a secure memory to store a secret key, and a security manager core, coupled to the secure memory, to receive a digitally signed command, verify a signature associated with the command using the secret key, and configure operation of the integrated circuit using the command.

IPC Classes  ?

  • G06F 21/71 - Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information
  • G06F 21/54 - Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems during program execution, e.g. stack integrity, buffer overflow or preventing unwanted data erasure by adding security routines or objects to programs
  • G06F 21/57 - Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
  • G06F 21/64 - Protecting data integrity, e.g. using checksums, certificates or signatures
  • H04L 9/08 - Key distribution
  • H04L 9/14 - Arrangements for secret or secure communicationsNetwork security protocols using a plurality of keys or algorithms
  • H04L 9/32 - Arrangements for secret or secure communicationsNetwork security protocols including means for verifying the identity or authority of a user of the system
  • H04L 9/40 - Network security protocols
  • H04W 12/04 - Key management, e.g. using generic bootstrapping architecture [GBA]
  • H04W 12/041 - Key generation or derivation

51.

MULTIPLICATIVE MASKING FOR CRYPTOGRAPHIC OPERATIONS

      
Application Number 18131086
Status Pending
Filing Date 2023-04-05
First Publication Date 2023-11-23
Owner CRYPTOGRAPHY RESEARCH, INC (USA)
Inventor
  • Tunstall, Michael
  • Durvaux, Francois

Abstract

A value corresponding to an input for a cryptographic operation may be received. The value may be masked by multiplying the value with a first number modulo a prime number. The cryptographic operation may subsequently be performed on the masked value.

IPC Classes  ?

  • H04L 9/00 - Arrangements for secret or secure communicationsNetwork security protocols
  • G06F 21/71 - Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information

52.

Providing access to a hardware resource based on a canary value

      
Application Number 18202474
Grant Number 12101393
Status In Force
Filing Date 2023-05-26
First Publication Date 2023-11-02
Grant Date 2024-09-24
Owner Cryptography Research, Inc. (USA)
Inventor
  • Hamburg, Michael A.
  • Wachs, Megan Anneke

Abstract

A container corresponding to executable code may be received. In response receiving the container, an assertion value may be stored in an assertion register. A final canary value may be generated based on a cycles combining a prior canary value and a mix value. A determination may be made as to whether the final canary value matches with the assertion value stored in the assertion register. In response to determining that the final canary value matches with the assertion value, one or more privilege registers may be programmed to provide access to hardware resources for the container corresponding to the executable user code.

IPC Classes  ?

  • H04L 9/00 - Arrangements for secret or secure communicationsNetwork security protocols
  • G06F 21/44 - Program or device authentication
  • G06F 21/51 - Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems at application loading time, e.g. accepting, rejecting, starting or inhibiting executable software based on integrity or source reliability
  • G06F 21/64 - Protecting data integrity, e.g. using checksums, certificates or signatures
  • H04L 9/32 - Arrangements for secret or secure communicationsNetwork security protocols including means for verifying the identity or authority of a user of the system

53.

TECHNIQUES AND DEVICES FOR CONFIGURABLE MEMORY ENCRYPTION AND AUTHENTICATION

      
Application Number US2023013874
Publication Number 2023/164167
Status In Force
Filing Date 2023-02-24
Publication Date 2023-08-31
Owner CRYPTOGRAPHY RESEARCH, INC. (USA)
Inventor
  • Kapoor, Ajay
  • Van Loon, Marcel

Abstract

Disclosed systems and techniques involve flexible encryption, decryption, retrieval, and authentication of data. The systems may include a cryptographic processor that, in a first selectable mode of operation is configured to identify plaintext blocks, generate encrypted ciphertext blocks, process sequentially the ciphertext blocks to obtain an authentication value, encrypt the authentication value, and store the ciphertext blocks and an authentication tag, obtained based on the encrypted authentication value. In a second selectable mode, the cryptographic processor may perform ciphertext block encryption but forgo obtaining the authentication value.

IPC Classes  ?

  • H04L 9/32 - Arrangements for secret or secure communicationsNetwork security protocols including means for verifying the identity or authority of a user of the system
  • G06F 12/14 - Protection against unauthorised use of memory
  • H04L 9/08 - Key distribution
  • G06F 12/06 - Addressing a physical block of locations, e.g. base addressing, module addressing, address space extension, memory dedication
  • H04L 9/14 - Arrangements for secret or secure communicationsNetwork security protocols using a plurality of keys or algorithms
  • H04L 9/16 - Arrangements for secret or secure communicationsNetwork security protocols using a plurality of keys or algorithms the keys or algorithms being changed during operation

54.

System and method to improve efficiency in multiplication_ladder-based cryptographic operations

      
Application Number 17916979
Grant Number 12166878
Status In Force
Filing Date 2021-04-14
First Publication Date 2023-08-10
Grant Date 2024-12-10
Owner Cryptography Research, Inc. (USA)
Inventor Hamburg, Michael Alexander

Abstract

Aspects of the present disclosure involve a method to perform a cryptographic operation using a plurality of iterations, each of the plurality of iterations comprising: loading a first number corresponding to a difference between a first component of a first input working point on an elliptic curve and a first component of a second input working point on the elliptic curve, loading a second number corresponding to a difference between the first component of the first input working point and a first component of a third input working point on the elliptic curve, and determining a third number corresponding to a difference between a first component of a first output working point on the elliptic curve and the first component of the second input working point, wherein determining the third number comprises squaring a product of the first number and a first function of the second number.

IPC Classes  ?

  • H04L 9/30 - Public key, i.e. encryption algorithm being computationally infeasible to invert and users' encryption keys not requiring secrecy

55.

Protection of transformations by intermediate randomization in cryptographic operations

      
Application Number 18008602
Grant Number 12335365
Status In Force
Filing Date 2021-06-04
First Publication Date 2023-08-10
Grant Date 2025-06-17
Owner CRYPTOGRAPHY RESEARCH, INC. (USA)
Inventor
  • Hamburg, Michael Alexander
  • Handschuh, Helena
  • Marson, Mark Evan

Abstract

Aspects of the present disclosure involve a method and a system to perform a cryptographic operation that involves a number theoretic transformation of a first vector to a second vector by obtaining components of the first vector, performing a plurality of iterations that each include determining a plurality of output values, wherein each of the plurality of output values is a linear combination of two or more input values, the input values into a first iteration being the components of the first vector and the output values of the last iteration being representative of components of the second vector, and wherein one or more of the output values of at least one iteration are randomized by multiplying at least one input value by a random number, and determining, based on the output values of the last of the plurality of iterations, the components of the second vector.

IPC Classes  ?

  • H04L 9/06 - Arrangements for secret or secure communicationsNetwork security protocols the encryption apparatus using shift registers or memories for blockwise coding, e.g. D.E.S. systems
  • G06F 17/14 - Fourier, Walsh or analogous domain transformations

56.

MULTI-PLATFORM USE CASE IMPLEMENTATIONS TO SECURELY PROVISION A SECURE DATA ASSET TO A TARGET DEVICE

      
Application Number 18085477
Status Pending
Filing Date 2022-12-20
First Publication Date 2023-06-29
Owner Cryptography Research, Inc. (USA)
Inventor
  • Orzen, Matthew Evan
  • Pochuev, Denis Alexandrovich

Abstract

An application executing at a first platform receives, from a tester device, a first request to generate a secure data asset to be securely provisioned to a target device. Responsive to receiving the first request, the application performs one or more operations related to the generation of the secure data asset. Subsequent to performing the one or more operations related to the generation of the secure data asset, the application sends, to a second secure platform, a second request to generate the secure data asset. The application receives, from the second secure platform, the generated secure data asset.

IPC Classes  ?

  • G06F 21/62 - Protecting access to data via a platform, e.g. using keys or access control rules

57.

Batch transfer of commands and data in a secure computer system

      
Application Number 18063984
Grant Number 11861374
Status In Force
Filing Date 2022-12-09
First Publication Date 2023-06-22
Grant Date 2024-01-02
Owner Cryptography Research, Inc. (USA)
Inventor
  • Raj, Ashish
  • Wittenauer, Joel
  • Wu, Winthrop John
  • Xiao, Qinglai
  • Gummalla, Samatha
  • Wang, Bryan Jason

Abstract

A computing system includes a host device and a root of trust (RoT) device for performing batch encryption and decryption operations facilitated by a direct memory access (DMA) engine. The host device generates a command table for batch processing of a set of address tables that each describe a set of data blocks of a file to be encrypted or decrypted. The DMA engine facilitates a DMA transfer of the command table from the host memory to an RoT memory of the RoT device. The RoT device then performs batch processing of the address tables referenced in the command table. For each address table, the DMA engine copies a set of data blocks from the host memory to the RoT memory, a cryptographic engine encrypts or decrypts the data blocks, and the DMA engine copies the transformed data blocks back to the host memory.

IPC Classes  ?

58.

Pipelined hardware error classification and handling

      
Application Number 18077943
Grant Number 12332732
Status In Force
Filing Date 2022-12-08
First Publication Date 2023-06-22
Grant Date 2025-06-17
Owner Cryptography Research, Inc. (USA)
Inventor
  • Wang, Bryan Jason
  • Gummalla, Samatha

Abstract

Technologies for detecting and classifying errors detected in pipelined hardware are described. One device includes a hardware pipeline with a set of pipeline stages. Error detection logic can detect an error in the hardware pipeline, and control logic can classify the error in one of the multiple categories based on a type of the error, a position of the first data in a data stream that triggered the error, and a position of a pipeline stage in which the error is detected. The control logic can perform an error-response action based on the error classification of the error.

IPC Classes  ?

  • G06F 11/00 - Error detectionError correctionMonitoring
  • G06F 11/07 - Responding to the occurrence of a fault, e.g. fault tolerance

59.

Masking of key generation operations with random matrices in cryptographic applications

      
Application Number 18082837
Grant Number 12219056
Status In Force
Filing Date 2022-12-16
First Publication Date 2023-06-22
Grant Date 2025-02-04
Owner Cryptography Research, Inc. (USA)
Inventor Hamburg, Michael Alexander

Abstract

Disclosed are systems and techniques for enhanced protection of cryptographic key generation in cryptographic applications. In particular, described is a method and a system that performs the method of obtaining input numbers associated with a cryptographic application, generating masking matrix based on at least one random value, obtaining masked numbers using a matrix product of the MM and the input numbers, determining a greatest common divisor (GCD) of the masked numbers, identifying a GCD of the input numbers, and using the identified GCD to generate a cryptographic key.

IPC Classes  ?

60.

CORRECTING THE ALMOST BINARY EXTENDED GREATEST COMMON DENOMINATOR (GCD)

      
Application Number 17864230
Status Pending
Filing Date 2021-01-20
First Publication Date 2023-06-22
Owner Cryptography Research, Inc. (USA)
Inventor Tunstall, Michael

Abstract

Computing devices, methods, and systems for corrections to the “almost” binary extended GCD in a cryptographic operation of a cryptographic process are disclosed. Exemplary implementations may: receive, from a cryptographic process, a command to compute a binary extended greatest common denominator of a first input value and a second input value for a cryptographic operation; compute, by a binary extended GCD algorithm, the binary extended GCD using a multiplication with an inverse of two, instead of a division by two, to obtain a first output value; compute, by the binary extended GCD algorithm, a second output value and a third output value; and return, to the cryptographic process, the first output value, the second output value, and the third output value.

IPC Classes  ?

  • H04L 9/00 - Arrangements for secret or secure communicationsNetwork security protocols
  • G06F 7/72 - Methods or arrangements for performing computations using a digital non-denominational number representation, i.e. number representation without radixComputing devices using combinations of denominational and non-denominational quantity representations using residue arithmetic
  • G06F 7/38 - Methods or arrangements for performing computations using exclusively denominational number representation, e.g. using binary, ternary, decimal representation

61.

Data flow control module for autonomous flow control of multiple DMA engines

      
Application Number 18063959
Grant Number 12229065
Status In Force
Filing Date 2022-12-09
First Publication Date 2023-06-15
Grant Date 2025-02-18
Owner Cryptography Research, Inc. (USA)
Inventor
  • Wu, Winthrop John
  • Gummalla, Samatha
  • Wang, Bryan Jason

Abstract

A DMA system includes two or more DMA engines that facilitate transfers of data through a shared memory. The DMA engines may operate independently of each other and with different throughputs. A data flow control module controls data flow through the shared memory by tracking status information of data blocks in the shared memory. The data flow control module updates the status information in response to read and write operations to indicate whether each block includes valid data that has not yet been read or if the block has been read and is available for writing. The data flow control module shares the status information with the DMA engines via a side-channel interface to enable the DMA engines to determine which block to write to or read from.

IPC Classes  ?

  • G06F 13/28 - Handling requests for interconnection or transfer for access to input/output bus using burst mode transfer, e.g. direct memory access, cycle steal

62.

LOW-LATENCY MULTI-DOMAIN MASKING

      
Application Number US2022051054
Publication Number 2023/107285
Status In Force
Filing Date 2022-11-28
Publication Date 2023-06-15
Owner CRYPTOGRAPHY RESEARCH, INC. (USA)
Inventor
  • Hutter, Michael
  • Abril, Victor, Manuel, Arribas

Abstract

A multi-domain masked AND gate includes inner-domain calculations, re-sharing, register stage, cross-domain calculations, and compression. The inner-domain multiplication and the re-sharing are calculated prior to storing the re-shared variables in the register stage. Thus, the inputs to the cross-domain multiplication and the compression are performed on variables that have been refreshed by additional randomness. This AND gate does not need statistically independent inputs, is secure in the probing model even in the presence of glitches, also known as the robust probing model. A two-domain input and two domain output AND gate can be implemented using six (6) registers, four (4) two input logical AND gates, and eight (8) exclusive-OR (XOR) gates. The AND gate may also be used to implement an AES S-box that has two (2) register stages and takes two (2) clock cycles per computation.

IPC Classes  ?

  • G06F 21/76 - Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information in application-specific integrated circuits [ASIC] or field-programmable devices, e.g. field-programmable gate arrays [FPGA] or programmable logic devices [PLD]
  • G11C 19/00 - Digital stores in which the information is moved stepwise, e.g. shift registers
  • G06F 21/72 - Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information in cryptographic circuits
  • H04L 9/28 - Arrangements for secret or secure communicationsNetwork security protocols using particular encryption algorithm

63.

PHYSICALLY UNCLONEABLE FUNCTION AS SECURE STORAGE

      
Application Number US2022051080
Publication Number 2023/107287
Status In Force
Filing Date 2022-11-28
Publication Date 2023-06-15
Owner CRYPTOGRAPHY RESEARCH, INC. (USA)
Inventor
  • Wu, Winthrop John
  • Best, Scott, C.
  • Wittenauer, Joel

Abstract

Multiple helper data solutions (a.k.a., helper data images) are generated to produce preselected non-random values (a.k.a., "target values") from a physically unclonable function (PUF) circuit. Therefore, multiple preselected PUF output values may be generated for a given integrated circuit die, where each the output values are derived from a combination of the chip-unique PUF circuit and the chip-unique helper data solution. These helper data blocks are stored in a nonvolatile memory on the integrated circuit die. In an embodiment, the preselected non-random values may be used as secret encryption or decryption keys. In this manner, multiple secret values can be reliably stored within a chip, using a combination of the chip-unique PUF circuit and the multiple chip-unique helper data solution.

IPC Classes  ?

  • G06F 21/30 - Authentication, i.e. establishing the identity or authorisation of security principals
  • G06F 21/62 - Protecting access to data via a platform, e.g. using keys or access control rules
  • G06F 21/72 - Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information in cryptographic circuits
  • G06F 21/76 - Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information in application-specific integrated circuits [ASIC] or field-programmable devices, e.g. field-programmable gate arrays [FPGA] or programmable logic devices [PLD]

64.

Using cryptographic blinding for efficient use of montgomery multiplication

      
Application Number 18061879
Grant Number 11863657
Status In Force
Filing Date 2022-12-05
First Publication Date 2023-06-08
Grant Date 2024-01-02
Owner CRYPTOGRAPHY RESEARCH, INC. (USA)
Inventor Tunstall, Michael

Abstract

Aspects of the present disclosure involves receiving an input message, generating a first random value that is used to blind the input message to prevent a side-channel analysis (SCA) attack, computing a second random value using the first random value and a factor used to compute the Montgomery form of a blinded input message without performing an explicit Montgomery conversion of the input message, and computing a signature using Montgomery multiplication, of the first random value and the second random value, wherein the signature is resistant to the SCA attack.

IPC Classes  ?

  • H04L 9/00 - Arrangements for secret or secure communicationsNetwork security protocols
  • H04L 9/08 - Key distribution
  • H04L 9/30 - Public key, i.e. encryption algorithm being computationally infeasible to invert and users' encryption keys not requiring secrecy
  • H04L 9/32 - Arrangements for secret or secure communicationsNetwork security protocols including means for verifying the identity or authority of a user of the system

65.

Efficient integrity monitoring of processing operations with multiple memory arrays

      
Application Number 17992221
Grant Number 12287874
Status In Force
Filing Date 2022-11-22
First Publication Date 2023-05-25
Grant Date 2025-04-29
Owner Cryptography Research, Inc. (USA)
Inventor
  • Hamburg, Michael Alexander
  • Wu, Winthrop John

Abstract

Disclosed systems and techniques are directed to efficient integrity monitoring of computational operations using multiple memory arrays collectively representative of known events associated with the computational operations. Disclosed techniques include obtaining event identification value representative of a state of the computing device associated with execution of an operation on the computing device, obtaining memory pointers and selecting, based on the memory pointers, mapping values from multiple memory arrays, computing an event response value, and classifying the operation among a plurality of classes, based on the event response value.

IPC Classes  ?

  • G06F 21/55 - Detecting local intrusion or implementing counter-measures

66.

ENTROPY DISTRIBUTION

      
Application Number 17989594
Status Pending
Filing Date 2022-11-17
First Publication Date 2023-05-25
Owner Cryptography Research, Inc. (USA)
Inventor
  • Wu, Winthrop
  • Best, Scott C.

Abstract

Technologies for selectively distributing a same random number to multiple cryptographic circuits are described. One apparatus includes a plurality of cryptographic circuits. Each of the plurality of cryptographic circuits is to receive a random number for differential power analysis (DPA) protection of a cryptographic operation. At least two of the plurality of cryptographic circuits are configured to selectively use a same random number.

IPC Classes  ?

  • H04L 9/08 - Key distribution
  • H04L 9/00 - Arrangements for secret or secure communicationsNetwork security protocols

67.

Authentication using an ephemeral asymmetric keypair

      
Application Number 17915367
Grant Number 12362948
Status In Force
Filing Date 2021-03-26
First Publication Date 2023-05-18
Grant Date 2025-07-15
Owner Cryptography Research, Inc. (USA)
Inventor
  • Marson, Mark Evan
  • Best, Scott C.

Abstract

A prover chip uses a key multiplier value generated by a proof-of-work function from a challenge value, a random number, and elliptic curve cryptography (ECC) techniques to generate a one-time (or ephemeral) use private key. Similarly, a verifier chip uses the key multiplier value generated by an equivalent proof-of-work function, a public key received from the prover, and ECC techniques to derive a one-time use public key that corresponds to the ephemeral private key generated by the prover chip. The prover chip uses the ephemeral private key to sign the second challenge value and send this signed second challenge value to the verifier chip. The verifier verifies the value it receives using the one-time use public key and if the signature on the second challenge value is valid, authenticates the prover chip to a system.

IPC Classes  ?

  • H04L 9/32 - Arrangements for secret or secure communicationsNetwork security protocols including means for verifying the identity or authority of a user of the system
  • H04L 9/08 - Key distribution
  • H04L 9/30 - Public key, i.e. encryption algorithm being computationally infeasible to invert and users' encryption keys not requiring secrecy

68.

PACKAGING TECHNIQUES FOR BACKSIDE MESH CONNECTIVITY

      
Application Number 17984155
Status Pending
Filing Date 2022-11-09
First Publication Date 2023-05-04
Owner Cryptography Research, Inc. (USA)
Inventor
  • Best, Scott C.
  • Li, Ming

Abstract

The embodiments herein are directed to technologies for backside security meshes of semiconductor packages. One package includes a substrate having a first interconnect terminal of a first type and a second interconnect terminal of a second type. The package also includes a first security mesh structure disposed on a first side of an integrated circuit die and a conductive path coupled between the first interconnect terminal and the second interconnect terminal. The first security mesh structure is coupled to the first interconnect terminal and the second interconnect terminal being coupled to a terminal on a second side of the integrated circuit die.

IPC Classes  ?

  • H01L 23/00 - Details of semiconductor or other solid state devices
  • G06F 21/87 - Secure or tamper-resistant housings by means of encapsulation, e.g. for integrated circuits
  • H04L 9/08 - Key distribution

69.

SECURE ASSET MANAGEMENT INFRASTRUCTURE FOR ENFORCING ACCESS CONTROL POLICIES

      
Application Number US2022047056
Publication Number 2023/069464
Status In Force
Filing Date 2022-10-18
Publication Date 2023-04-27
Owner CRYPTOGRAPHY RESEARCH, INC. (USA)
Inventor
  • Chamaraj, Sangeetha
  • Orzen, Matthew E.
  • Pochuev, Denis Alexandrovich

Abstract

An application executing at a first platform receives, from a tester device, a first request to generate a secure data asset. Responsive to authenticating the client, the application sends, to a second platform, a second request to determine whether the client has access to the secure data asset. Responsive to receiving an indication, from the second platform, that the client has access to the secure data asset, the application performs one or more operations to generate the secure data asset. The application sends, to the tester device, the generated secure data asset.

IPC Classes  ?

  • G06F 21/62 - Protecting access to data via a platform, e.g. using keys or access control rules
  • G06F 21/72 - Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information in cryptographic circuits
  • H04W 12/06 - Authentication
  • G06F 21/73 - Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information by creating or determining hardware identification, e.g. serial numbers
  • H04W 12/0431 - Key distribution or pre-distributionKey agreement

70.

LOW-LATENCY MULTI-KEY ENCRYPTION AND DECRYPTION ENGINE AND TECHNIQUES

      
Application Number US2022047031
Publication Number 2023/069441
Status In Force
Filing Date 2022-10-18
Publication Date 2023-04-27
Owner CRYPTOGRAPHY RESEARCH, INC. (USA)
Inventor
  • Hamburg, Michael Alexander
  • Erickson, Evan Lawrence
  • Handschuh, Helena
  • Marson, Mark Evan

Abstract

Disclosed systems and techniques involve low-latency multi-key encryption processing in which block keys are precomputed based on multiple cryptographic keys, stored, and then selected for encryption or decryption of data during run-time cryptographic operations. The block keys may be precomputed, for each cryptographic key, in such quantities that allow uninterrupted flow of encryption or decryption operations. Replacement block keys may be concurrently generated to replace the blocks being consumed and authentication values may be computed or updated. Various described techniques allow parallel processing for efficient low-latency block key generation and cryptographic operations.

IPC Classes  ?

  • H04L 9/00 - Arrangements for secret or secure communicationsNetwork security protocols
  • H04L 9/14 - Arrangements for secret or secure communicationsNetwork security protocols using a plurality of keys or algorithms

71.

Protection of cryptographic substitution-permutation networks from fault injection attacks

      
Application Number 17948017
Grant Number 12500738
Status In Force
Filing Date 2022-09-19
First Publication Date 2023-03-23
Grant Date 2025-12-16
Owner Cryptography Research, Inc. (USA)
Inventor
  • Hamburg, Michael Alexander
  • Handschuh, Helena
  • Marson, Mark Evan
  • Wu, Winthrop John

Abstract

Aspects of the present disclosure involve a method and a system to perform the method to obtain a cryptographic output of a plurality of rounds of a cipher, by performing a plurality of modified rounds of the cipher, each of the modified rounds computing an unmasking transform, an operation of a respective round of the cipher, and a masking transform, the unmasking transform being an inverse of the masking transform of a previous round of the cipher.

IPC Classes  ?

  • H04L 9/06 - Arrangements for secret or secure communicationsNetwork security protocols the encryption apparatus using shift registers or memories for blockwise coding, e.g. D.E.S. systems

72.

Authentication timers

      
Application Number 17792090
Grant Number 12323418
Status In Force
Filing Date 2021-01-11
First Publication Date 2023-02-16
Grant Date 2025-06-03
Owner Cryptography Research, Inc. (USA)
Inventor
  • Best, Scott C.
  • Orzen, Matthew E.

Abstract

A first device transmits a first message to a second device as part of a challenge-response protocol in order to authenticate the second device. A power limited power supply coupled to the second device limits power consumption by the second device during the second device's challenge-response protocol calculations. The first device measures a response time of the second device during the challenge-response protocol. The authentication of the second device is based on the response time of the second device while it has limited power consumption.

IPC Classes  ?

73.

Managing privileges of different entities for an integrated circuit

      
Application Number 17876960
Grant Number 11789625
Status In Force
Filing Date 2022-07-29
First Publication Date 2023-02-16
Grant Date 2023-10-17
Owner Cryptography Research, Inc. (USA)
Inventor
  • Jun, Benjamin Che-Ming
  • Rawlings, William Craig
  • Kumar, Ambuj
  • Marson, Mark Evan

Abstract

A request associated with one or more privileges assigned to a first entity may be received. Each of the one or more privileges may correspond to an operation of an integrated circuit. Information corresponding to the first entity and stored in a memory that is associated with the integrated circuit may be identified. Furthermore, the memory may be programmed to modify the information stored in the memory that is associated with the integrated circuit in response to the request associated with the one or more privileges assigned to the first entity.

IPC Classes  ?

  • G06F 3/06 - Digital input from, or digital output to, record carriers
  • G06F 21/71 - Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information
  • G06F 21/76 - Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information in application-specific integrated circuits [ASIC] or field-programmable devices, e.g. field-programmable gate arrays [FPGA] or programmable logic devices [PLD]
  • G11C 17/16 - Read-only memories programmable only onceSemi-permanent stores, e.g. manually-replaceable information cards in which contents are determined by selectively establishing, breaking or modifying connecting links by permanently altering the state of coupling elements, e.g. PROM using electrically-fusible links
  • G11C 17/18 - Auxiliary circuits, e.g. for writing into memory

74.

SIGN-EFFICIENT ADDITION AND SUBTRACTION FOR STREAMINGCOMPUTATIONS IN CRYPTOGRAPHIC ENGINES

      
Application Number 17865036
Status Pending
Filing Date 2022-07-14
First Publication Date 2023-02-09
Owner Cryptography Research, Inc. (USA)
Inventor
  • Hamburg, Michael Alexander
  • De Meyer, Lauren
  • Singh, Arvind

Abstract

Aspects of the present disclosure involve techniques and cryptographic processors configured to perform the techniques that include sign-efficient addition and subtraction operations that use Montgomery reduction and are capable of facilitating fast streaming operations. The techniques involve receiving a first number and a second number, where the first number and second number are within a target interval, and performing a modular operation to obtain a third number, the third number being within the same target interval and representing a sum or a difference of a rescaled first number and a rescaled second number, and wherein the modular operation includes a Montgomery reduction.

IPC Classes  ?

  • H04L 9/30 - Public key, i.e. encryption algorithm being computationally infeasible to invert and users' encryption keys not requiring secrecy
  • G06F 7/491 - Computations with decimal numbers

75.

MULTI-LANE CRYPTOGRAPHIC ENGINE AND OPERATIONS THEREOF

      
Application Number US2022037024
Publication Number 2023/003737
Status In Force
Filing Date 2022-07-13
Publication Date 2023-01-26
Owner CRYPTOGRAPHY RESEARCH, INC. (USA)
Inventor
  • Hamburg, Michael, Alexander
  • Singh, Arvind
  • De Meyer, Lauren

Abstract

Aspects of the present disclosure involve a cryptographic processor that includes four or more multiplication circuits, two or more addition circuits, and two or more memory circuits. The cryptographic engine is configured to perform a variety of operations, including modular multiplication, modular inversion, matrix multiplication, Montgomery multiplication, computations of Jacobi symbols, and the like. The cryptographic engine support streaming computations where at least some of the multiplication circuits operate on multipliers and/or multiplicands that are also used during other cycles of computations.

IPC Classes  ?

  • G06F 7/53 - Multiplying only in parallel-parallel fashion, i.e. both operands being entered in parallel
  • G06F 7/505 - AddingSubtracting in bit-parallel fashion, i.e. having a different digit-handling circuit for each denomination
  • G06F 7/72 - Methods or arrangements for performing computations using a digital non-denominational number representation, i.e. number representation without radixComputing devices using combinations of denominational and non-denominational quantity representations using residue arithmetic
  • H04L 9/14 - Arrangements for secret or secure communicationsNetwork security protocols using a plurality of keys or algorithms

76.

MULTI-LANE CRYPTOGRAPHIC ENGINES WITH SYSTOLIC ARCHITECTURE AND OPERATIONS THEREOF

      
Application Number US2022037206
Publication Number 2023/003756
Status In Force
Filing Date 2022-07-14
Publication Date 2023-01-26
Owner CRYPTOGRAPHY RESEARCH, INC. (USA)
Inventor
  • Hamburg, Michael, Alexander
  • Singh, Arvind

Abstract

Aspects of the present disclosure involve a cryptographic processor that includes a systolic array having a plurality of processing lanes (PLs), each PL including a systolic subarray of two or more processing elements (PEs), each PE being configured to multiply two numbers to obtain and store a multiplication product. The cryptographic processor is configured to efficiently perform a variety of operations, including multiplication of large numbers, modular reduction, Montgomery reduction, and the like.

IPC Classes  ?

  • G06F 15/80 - Architectures of general purpose stored program computers comprising an array of processing units with common control, e.g. single instruction multiple data processors
  • G06F 7/53 - Multiplying only in parallel-parallel fashion, i.e. both operands being entered in parallel
  • G06F 9/44 - Arrangements for executing specific programs

77.

Share domain arrangements for masked hardware implementations

      
Application Number 17780428
Grant Number 12307000
Status In Force
Filing Date 2020-11-30
First Publication Date 2023-01-19
Grant Date 2025-05-20
Owner Cryptography Research, Inc. (USA)
Inventor
  • Hutter, Michael
  • Handschuh, Helena
  • Best, Scott C.

Abstract

Hardware masking may be used as a countermeasure to make power analysis attacks more difficult. Masking attempts to decouple the secret and/or processed values of a cryptographic algorithm from its intermediate values. One method of masking probabilistically splits each bit of a computation into multiple shares. Mask-share domains (i.e., the wires and gates that perform a computation on a share) are physically spaced to reduce coupling between mask-share domains. The mask-share domains may be connected to the same power supply network. The physical distance between mask-share domains along the power-supply network may be selected to reduce coupling between mask-share domains that may occur via the power supply network. The mask-share domains may each be connected to different on-chip power supply networks.

IPC Classes  ?

  • G06F 21/75 - Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information by inhibiting the analysis of circuitry or operation, e.g. to counteract reverse engineering
  • H04L 9/00 - Arrangements for secret or secure communicationsNetwork security protocols
  • H04L 9/06 - Arrangements for secret or secure communicationsNetwork security protocols the encryption apparatus using shift registers or memories for blockwise coding, e.g. D.E.S. systems
  • H04L 9/08 - Key distribution

78.

Masked gate logic for resistance to power analysis

      
Application Number 17862134
Grant Number 11861047
Status In Force
Filing Date 2022-07-11
First Publication Date 2022-12-22
Grant Date 2024-01-02
Owner Cryptography Research, Inc. (USA)
Inventor
  • Leiserson, Andrew John
  • Marson, Mark Evan
  • Wachs, Megan Anneke

Abstract

A method of and system for gate-level masking of secret data during a cryptographic process is described. A mask share is determined, wherein a first portion of the mask share includes a first number of zero-values and a second number of one-values, and a second portion of the mask share includes the first number of one-values and the second number of zero-values. Masked data values and the first portion of the mask share are input into a first portion of masked gate logic, and the masked data values and the second portion of the mask share are input into a second portion of the masked gate logic. A first output from the first portion of the masked gate logic and a second output from the second portion of the masked gate logic are identified, wherein either the first output or the second output is a zero-value.

IPC Classes  ?

  • H04L 9/32 - Arrangements for secret or secure communicationsNetwork security protocols including means for verifying the identity or authority of a user of the system
  • G06F 21/72 - Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information in cryptographic circuits
  • G06F 21/71 - Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information
  • G06F 21/75 - Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information by inhibiting the analysis of circuitry or operation, e.g. to counteract reverse engineering
  • H04L 9/00 - Arrangements for secret or secure communicationsNetwork security protocols

79.

Protecting cryptographic keys stored in non-volatile memory

      
Application Number 17854295
Grant Number 12393702
Status In Force
Filing Date 2022-06-30
First Publication Date 2022-12-22
Grant Date 2025-08-19
Owner CRYPTOGRAPHY RESEARCH, INC. (USA)
Inventor
  • Marson, Mark Evan
  • Hamburg, Michael A.

Abstract

Systems and methods for protecting cryptographic keys stored in a non-volatile memory. An example method may comprise: storing a device root key in a non-volatile memory; storing a volatile key in a volatile memory; storing a masked cryptographic key in the non-volatile memory, wherein the masked cryptographic key is produced by combining a cryptographic key and the device root key; storing a masked device root key in the non-volatile memory, wherein the masked root key is produced by combining the device root key and the volatile key; and erasing the device root key from the non-volatile memory.

IPC Classes  ?

  • G06F 21/60 - Protecting data
  • G06F 1/24 - Resetting means
  • G06F 12/14 - Protection against unauthorised use of memory
  • G06F 21/79 - Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure storage of data in semiconductor storage media, e.g. directly-addressable memories
  • H04L 9/08 - Key distribution

80.

Protection of stored and communicated secret data against side-channel attacks

      
Application Number 17834511
Grant Number 12547754
Status In Force
Filing Date 2022-06-07
First Publication Date 2022-12-15
Grant Date 2026-02-10
Owner Cryptography Research, Inc. (USA)
Inventor
  • Marson, Mark Evan
  • Hamburg, Michael Alexander
  • Handschuh, Helena

Abstract

Described are implementations directed to protecting secret data against adversarial attacks by obfuscating the secret data during storage and communication. Obfuscation techniques include, among other things, splitting secret data into a plurality of portions, performing rotation of secret data, splitting secret data into a plurality of shares, modifying shares of secret data in view of the values of the shares, and various other protection mechanisms.

IPC Classes  ?

  • G06F 21/00 - Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
  • G06F 12/14 - Protection against unauthorised use of memory
  • G06F 21/62 - Protecting access to data via a platform, e.g. using keys or access control rules

81.

Secure computation environment

      
Application Number 17650544
Grant Number 12229272
Status In Force
Filing Date 2022-02-10
First Publication Date 2022-12-01
Grant Date 2025-02-18
Owner Cryptography Research, Inc. (USA)
Inventor Kumar, Ambuj

Abstract

A container corresponding to executable code may be received. In response to receiving the container, a container manager resident in a memory of a computation environment may be executed to verify the container. The container manager may be verified by a boot loader of the computation environment. Permissions of the container to access the resources of a computation environment may be determined after the verification of the container by the container manager. Access to one or more resources of the computation environment may be provided by transferring control to the one or more resources from the container manager to the container based on the permissions of the container for the resources of the computation environment.

IPC Classes  ?

  • G06F 21/57 - Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
  • G06F 9/4401 - Bootstrapping
  • G06F 21/44 - Program or device authentication
  • G06F 21/51 - Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems at application loading time, e.g. accepting, rejecting, starting or inhibiting executable software based on integrity or source reliability
  • H04L 9/32 - Arrangements for secret or secure communicationsNetwork security protocols including means for verifying the identity or authority of a user of the system

82.

Anti-tamper shield based on strings of series resistors

      
Application Number 17633534
Grant Number 11797718
Status In Force
Filing Date 2020-08-21
First Publication Date 2022-11-10
Grant Date 2023-10-24
Owner Cryptography Research, Inc. (USA)
Inventor Best, Scott C.

Abstract

A resistor mesh with distributed sensing points is provided in a security chip as an anti-tamper shield. An analog multiplexing circuit is configured to receive a pair of digital selection values created by an algorithm processing circuit, and produce a respective differential voltage formed by a pair of voltages obtained at a pair of selected sensing points within the resistor mesh corresponding to the pair of digital selection values. Each differential voltage is converted into a corresponding digital output value. An algorithm processing circuit is configured to receive a respective digital output value associated with each pair of digital selection values and derive a binary value based on a subset of the digital output values, wherein the binary value is unique to the security chip.

IPC Classes  ?

  • G06F 21/00 - Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
  • G06F 21/87 - Secure or tamper-resistant housings by means of encapsulation, e.g. for integrated circuits

83.

Securely provisioning a target device

      
Application Number 17722226
Grant Number 11895109
Status In Force
Filing Date 2022-04-15
First Publication Date 2022-10-13
Grant Date 2024-02-06
Owner Cryptography Research, Inc. (USA)
Inventor
  • Hamburg, Michael
  • Jun, Benjamin Che-Ming
  • Kocher, Paul C.
  • O'Loughlin, Daniel
  • Pochuev, Denis Alexandrovich

Abstract

The embodiments described herein describe technologies for Module management, including Module creation and Module deployment to a target device in an operation phase of a manufacturing lifecycle of the target device in a cryptographic manager (CM) environment. One implementation includes a Root Authority (RA) device that receives a first command to create a Module and executes a Module Template to generate the Module in response to the first command. The RA device receives a second command to create a deployment authorization message. The Module and the deployment authorization message are deployed to an Appliance device. A set of instructions of the Module, when permitted by the deployment authorization message and executed by the Appliance device, results in a secure construction of a sequence of operations to securely provision a data asset to the target device.

IPC Classes  ?

  • H04L 9/40 - Network security protocols
  • H04W 12/06 - Authentication
  • G06F 21/60 - Protecting data
  • G06F 21/62 - Protecting access to data via a platform, e.g. using keys or access control rules
  • G06F 21/72 - Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information in cryptographic circuits
  • G06F 21/73 - Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information by creating or determining hardware identification, e.g. serial numbers
  • G06F 21/33 - User authentication using certificates
  • H04W 12/30 - Security of mobile devicesSecurity of mobile applications
  • H04W 12/0431 - Key distribution or pre-distributionKey agreement
  • H04L 67/60 - Scheduling or organising the servicing of application requests, e.g. requests for application data transmissions using the analysis and optimisation of the required network resources

84.

Detection of a netlist version in a security chip

      
Application Number 17636831
Grant Number 11868512
Status In Force
Filing Date 2020-09-04
First Publication Date 2022-08-25
Grant Date 2024-01-09
Owner CRYPTOGRAPHY RESEARCH, INC. (USA)
Inventor
  • Best, Scott C.
  • Rodgers, Christopher Leigh

Abstract

A pattern detector circuit is provided in a security chip, wherein the pattern detector circuit monitors accesses of a plurality of configuration registers, each of the plurality of configuration registers having a corresponding address. In response to receiving from a host a predefined sequence of accesses of the plurality of configuration registers for one or more operations to the plurality of configuration registers, a processor in the pattern detector circuit determines a value indicative of a current version of a netlist for the security chip. The determined value is made available to be obtained by a read operation by the host at a specific configuration register address.

IPC Classes  ?

  • G06F 21/40 - User authentication by quorum, i.e. whereby two or more security principals are required
  • G06F 21/76 - Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information in application-specific integrated circuits [ASIC] or field-programmable devices, e.g. field-programmable gate arrays [FPGA] or programmable logic devices [PLD]

85.

Anti-counterfeiting applications for advanced memories

      
Application Number 17612527
Grant Number 12314372
Status In Force
Filing Date 2020-05-21
First Publication Date 2022-07-28
Grant Date 2025-05-27
Owner Cryptography Research, Inc. (USA)
Inventor Best, Scott C.

Abstract

A block of data is provided from a verifier module to an authenticator module, the size of the block being correlated with one or more desired characteristics of the authenticator module. The verifier module receives a response from the authenticator module, the response comprising data result derived from a calculation involving the challenge value and the block of data. The verifier module verifies whether the response is indicative of the one or more desired characteristics of the authenticator module.

IPC Classes  ?

  • G06F 21/00 - Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
  • G06F 12/14 - Protection against unauthorised use of memory
  • G06F 21/44 - Program or device authentication

86.

PROTECTION OF NEURAL NETWORKS BY OBFUSCATION OF NEURAL NETWORK OPERATIONS AND ARCHITECTURE

      
Application Number US2021063880
Publication Number 2022/140163
Status In Force
Filing Date 2021-12-16
Publication Date 2022-06-30
Owner CRYPTOGRAPHY RESEARCH, INC. (USA)
Inventor
  • Marson, Mark Evan
  • Hamburg, Michael Alexander
  • Handschuh, Helena

Abstract

Aspects of the present disclosure involve implementations that may be used to protect neural network models against adversarial attacks by obfuscating neural network operations and architecture. Obfuscation techniques include obfuscating weights and biases of neural network nodes, obfuscating activation functions used by neural networks, as well as obfuscating neural network architecture by introducing dummy operations, dummy nodes, and dummy layers into the neural networks.

IPC Classes  ?

  • G06F 17/16 - Matrix or vector computation
  • G06F 21/00 - Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
  • G06F 21/14 - Protecting executable software against software analysis or reverse engineering, e.g. by obfuscation
  • G06N 3/02 - Neural networks
  • G06N 3/04 - Architecture, e.g. interconnection topology

87.

Protection of neural networks by obfuscation of activation functions

      
Application Number 17553536
Grant Number 12099622
Status In Force
Filing Date 2021-12-16
First Publication Date 2022-06-23
Grant Date 2024-09-24
Owner Cryptography Research, Inc (USA)
Inventor
  • Marson, Mark Evan
  • Hamburg, Michael Alexander
  • Handschuh, Helena

Abstract

Aspects of the present disclosure involve implementations that may be used to protect neural network models against adversarial attacks by obfuscating neural network operations and architecture. Obfuscation techniques include obfuscating weights and biases of neural network nodes, obfuscating activation functions used by neural networks, as well as obfuscating neural network architecture by introducing dummy operations, dummy nodes, and dummy layers into the neural networks.

IPC Classes  ?

  • G06F 21/62 - Protecting access to data via a platform, e.g. using keys or access control rules
  • G06F 21/14 - Protecting executable software against software analysis or reverse engineering, e.g. by obfuscation
  • G06N 3/02 - Neural networks
  • G06N 3/048 - Activation functions
  • G06V 10/82 - Arrangements for image or video recognition or understanding using pattern recognition or machine learning using neural networks

88.

Protection of neural networks by obfuscation of neural network architecture

      
Application Number 17553545
Grant Number 12056219
Status In Force
Filing Date 2021-12-16
First Publication Date 2022-06-23
Grant Date 2024-08-06
Owner Cryptography Research, Inc. (USA)
Inventor
  • Marson, Mark Evan
  • Hamburg, Michael Alexander
  • Handschuh, Helena

Abstract

Aspects of the present disclosure involve implementations that may be used to protect neural network models against adversarial attacks by obfuscating neural network operations and architecture. Obfuscation techniques include obfuscating weights and biases of neural network nodes, obfuscating activation functions used by neural networks, as well as obfuscating neural network architecture by introducing dummy operations, dummy nodes, and dummy layers into the neural networks.

IPC Classes  ?

  • G06F 21/14 - Protecting executable software against software analysis or reverse engineering, e.g. by obfuscation
  • G06N 3/02 - Neural networks

89.

Functions with a pre-charge operation and an evaluation operation

      
Application Number 17598189
Grant Number 12021969
Status In Force
Filing Date 2020-04-01
First Publication Date 2022-06-16
Grant Date 2024-06-25
Owner Cryptography Research, Inc. (USA)
Inventor
  • Sasdrich, Pascal
  • Bilgin, Begül
  • Hutter, Michael

Abstract

An input data may be received. A portion of a cryptographic operation may be performed with the received input data at a first function component. During the performance of the cryptographic operation at the first function component, a pre-charge operation may be performed at a second function component. Furthermore, the second function component may be used to perform another portion of the cryptographic operation with a result of the portion of the cryptographic operation performed at the first function component.

IPC Classes  ?

  • H04L 29/00 - Arrangements, apparatus, circuits or systems, not covered by a single one of groups
  • H04L 9/00 - Arrangements for secret or secure communicationsNetwork security protocols
  • H04L 9/06 - Arrangements for secret or secure communicationsNetwork security protocols the encryption apparatus using shift registers or memories for blockwise coding, e.g. D.E.S. systems

90.

Efficient side-channel-attack-resistant memory encryptor based on key update

      
Application Number 17601205
Grant Number 11863670
Status In Force
Filing Date 2020-04-04
First Publication Date 2022-06-09
Grant Date 2024-01-02
Owner Cryptography Research, Inc. (USA)
Inventor
  • Marson, Mark Evan
  • Hutter, Michael
  • Stevens, Bart

Abstract

Disclosed are memory encryption systems and methods that rotate encryption keys for robust resistance against side-channel-analysis (SCA)-based attacks on communication paths between an encryption engine within a trust boundary and an external memory component. A key data structure has a plurality of keys that are used to encrypt a plurality of memory blocks in the external memory. The memory blocks encrypted with the oldest key of the key data structure are identified. Encrypted data is read from the identified memory blocks. The encrypted data is decrypted from the identified memory blocks. The data is then re-encrypted using the selected key that is newer than the oldest key, and re-written to the identified memory blocks.

IPC Classes  ?

  • G06F 21/00 - Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
  • H04L 29/06 - Communication control; Communication processing characterised by a protocol
  • H04L 9/08 - Key distribution
  • H04L 9/00 - Arrangements for secret or secure communicationsNetwork security protocols
  • H04L 9/16 - Arrangements for secret or secure communicationsNetwork security protocols using a plurality of keys or algorithms the keys or algorithms being changed during operation

91.

DPA-resistant key derivation function

      
Application Number 17606434
Grant Number 11956345
Status In Force
Filing Date 2020-04-30
First Publication Date 2022-06-09
Grant Date 2024-04-09
Owner CRYPTOGRAPHY RESEARCH, INC. (USA)
Inventor
  • Hamburg, Michael Alexander
  • Pochuev, Denis Alexandrovich

Abstract

Aspects of the present disclosure involve a method and a system to support execution of the method to obtain a first N cryptographic key, receive a key diversification information comprising a first plurality of bits, obtain an expanded key diversification information (EKDI) comprising a second plurality of bits, wherein a number of bits in the second plurality of bits is greater than a number of bits in the first plurality of bits, and wherein a value of each bit of the second plurality of bits is deterministically obtained in view of values of the first plurality of bits, and apply, by the processing device, a key derivation function to the first cryptographic key and the EKDI to obtain a second cryptographic key.

IPC Classes  ?

  • H04L 29/06 - Communication control; Communication processing characterised by a protocol
  • G06F 21/00 - Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
  • H04L 9/00 - Arrangements for secret or secure communicationsNetwork security protocols
  • H04L 9/08 - Key distribution

92.

System and method to optimize generation of coprime numbers in cryptographic applications

      
Application Number 17532460
Grant Number 11902432
Status In Force
Filing Date 2021-11-22
First Publication Date 2022-05-26
Grant Date 2024-02-13
Owner Cryptography Research, Inc. (USA)
Inventor
  • Tunstall, Michael
  • Hamburg, Michael Alexander
  • Xiao, Qinglai

Abstract

Aspects of the present disclosure involve a method, a system and a computer readable memory to perform a cryptographic operation that includes identifying a first set of mutually coprime numbers, obtaining a second set of input numbers coprime with a corresponding one of the first set of mutually coprime numbers, obtaining an output number that is a weighted sum of the second set of input numbers, each of the second set of input numbers being taken with a weight comprising a product of all of the first set of mutually coprime numbers except the corresponding one of the first set of mutually coprime numbers, and performing the cryptographic operation using the output number.

IPC Classes  ?

  • G06F 21/00 - Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
  • H04L 9/08 - Key distribution
  • G06F 7/02 - Comparing digital values

93.

Side-channel-attack-resistant memory access on embedded central processing units

      
Application Number 17435360
Grant Number 11914870
Status In Force
Filing Date 2020-03-04
First Publication Date 2022-05-12
Grant Date 2024-02-27
Owner CRYPTOGRAPHY RESEARCH, INC. (USA)
Inventor
  • De Mulder, Elke
  • Hutter, Michael
  • Gummalla, Samantha

Abstract

Aspects of the present disclosure calculate masked data shares dynamically inside the CPU boundary, and use a plurality of memory channels to write the masked data shares to an external memory location and/or to read the data shares from that external memory location. Each dynamically generated mask value is uniquely associated with a corresponding memory channel during writing data to the external memory. The modified masked data is unmasked or remasked during a subsequent read operation.

IPC Classes  ?

  • G06F 3/06 - Digital input from, or digital output to, record carriers

94.

Security chip with resistance to external monitoring attacks

      
Application Number 17382333
Grant Number 11797683
Status In Force
Filing Date 2021-07-21
First Publication Date 2022-03-17
Grant Date 2023-10-24
Owner Cryptography Research, Inc. (USA)
Inventor
  • Kocher, Paul C.
  • Rohatgi, Pankaj
  • Jaffe, Joshua M.

Abstract

A method for performing a security chip protocol comprises receiving, by processing hardware of a security chip, a message from a first device as part of performing the security chip protocol. The processing hardware retrieves a secret value from secure storage hardware operatively coupled to the processing hardware. The processing hardware determines a path through a key tree based at least in part on the message. The processing hardware derives a validator at least in part from the secret value using a sequence of entropy redistribution operations associated with the path through the key tree. The processing hardware exchanges the validator between the security chip and the first device as part of the security chip protocol in order to authenticate at least one of the security chip or the first device.

IPC Classes  ?

  • G06F 21/57 - Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
  • G06F 21/60 - Protecting data
  • H04L 9/08 - Key distribution
  • H04L 9/32 - Arrangements for secret or secure communicationsNetwork security protocols including means for verifying the identity or authority of a user of the system
  • G06F 21/55 - Detecting local intrusion or implementing counter-measures
  • H04L 9/00 - Arrangements for secret or secure communicationsNetwork security protocols
  • G06F 12/14 - Protection against unauthorised use of memory
  • H04L 9/06 - Arrangements for secret or secure communicationsNetwork security protocols the encryption apparatus using shift registers or memories for blockwise coding, e.g. D.E.S. systems
  • H04L 9/16 - Arrangements for secret or secure communicationsNetwork security protocols using a plurality of keys or algorithms the keys or algorithms being changed during operation
  • G06F 9/445 - Program loading or initiating
  • G06F 21/76 - Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information in application-specific integrated circuits [ASIC] or field-programmable devices, e.g. field-programmable gate arrays [FPGA] or programmable logic devices [PLD]
  • G06F 8/71 - Version control Configuration management
  • H04L 9/40 - Network security protocols
  • G06F 21/75 - Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information by inhibiting the analysis of circuitry or operation, e.g. to counteract reverse engineering

95.

System and method to generate prime numbers in cryptographic applications

      
Application Number 17447122
Grant Number 12284278
Status In Force
Filing Date 2021-09-08
First Publication Date 2022-03-17
Grant Date 2025-04-22
Owner Cryptography Research, Inc. (USA)
Inventor
  • Xiao, Qinglai
  • Hamburg, Michael Alexander
  • Tunstall, Michael

Abstract

Aspects of the present disclosure involve a method, a system and a computer readable memory to generate and use prime numbers in cryptographic operations by determining one or more polynomial functions that have no roots modulo each of a predefined set of prime numbers, selecting one or more input numbers, generating a candidate number by applying one or more instances of the one or more polynomial functions to the one or more input numbers, determining that the candidate number is a prime number, and using the determined prime number to decrypt an input into the cryptographic operation.

IPC Classes  ?

  • H04L 9/30 - Public key, i.e. encryption algorithm being computationally infeasible to invert and users' encryption keys not requiring secrecy
  • G06F 7/72 - Methods or arrangements for performing computations using a digital non-denominational number representation, i.e. number representation without radixComputing devices using combinations of denominational and non-denominational quantity representations using residue arithmetic
  • H04L 9/00 - Arrangements for secret or secure communicationsNetwork security protocols

96.

System and method to optimize decryption operations in cryptographic applications

      
Application Number 17447129
Grant Number 12231562
Status In Force
Filing Date 2021-09-08
First Publication Date 2022-03-17
Grant Date 2025-02-18
Owner Cryptography Research, Inc. (USA)
Inventor
  • Hamburg, Michael Alexander
  • Tunstall, Michael
  • Pochuev, Denis Alexandrovich

Abstract

Aspects of the present disclosure involve a method, a system and a computer readable memory to optimize performance of cryptographic operations by avoiding computations of inverse values during decryption of encrypted messages.

IPC Classes  ?

  • H04L 9/30 - Public key, i.e. encryption algorithm being computationally infeasible to invert and users' encryption keys not requiring secrecy

97.

Protection of cryptographic operations by intermediate randomization

      
Application Number 17309937
Grant Number 11983280
Status In Force
Filing Date 2020-01-06
First Publication Date 2022-03-10
Grant Date 2024-05-14
Owner Cryptography Research, Inc. (USA)
Inventor
  • Hamburg, Michael Alexander
  • Tunstall, Michael
  • Hutter, Michael

Abstract

Aspects of the present disclosure involve a method and a system to support execution of the method to perform a cryptographic operation involving a first vector and a second vector, by projectively scaling the first vector, performing a first operation involving the scaled first vector and the second vector to obtain a third vector, generating a random number, storing the third vector in a first location, responsive to the random number having a first value, or in a second location, responsive to the random number having a second value, and performing a second operation involving a first input and a second input, wherein, based on the random number having the first value or the second value, the first input is the third vector stored in the first location or the second location and the second input is a fourth vector stored in the second location or the first location.

IPC Classes  ?

  • G06F 21/00 - Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
  • G06F 7/523 - Multiplying only
  • G06F 7/58 - Random or pseudo-random number generators
  • G06F 17/16 - Matrix or vector computation
  • G06F 21/60 - Protecting data
  • G06F 21/78 - Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure storage of data

98.

Efficient squaring with loop equalization in arithmetic logic units

      
Application Number 17309933
Grant Number 11961420
Status In Force
Filing Date 2020-01-06
First Publication Date 2022-03-10
Grant Date 2024-04-16
Owner Cryptography Research, Inc. (USA)
Inventor Hamburg, Michael Alexander

Abstract

b, wherein a+b=2j+m, j≥0 and m≥0, and wherein all second loops have an equal number of second loop iterations.

IPC Classes  ?

  • H04L 29/06 - Communication control; Communication processing characterised by a protocol
  • G06F 7/57 - Arithmetic logic units [ALU], i.e. arrangements or devices for performing two or more of the operations covered by groups or for performing logical operations
  • G06F 7/72 - Methods or arrangements for performing computations using a digital non-denominational number representation, i.e. number representation without radixComputing devices using combinations of denominational and non-denominational quantity representations using residue arithmetic
  • G09C 1/00 - Apparatus or methods whereby a given sequence of signs, e.g. an intelligible text, is transformed into an unintelligible sequence of signs by transposing the signs or groups of signs or by replacing them by others according to a predetermined system
  • H04L 9/30 - Public key, i.e. encryption algorithm being computationally infeasible to invert and users' encryption keys not requiring secrecy

99.

Maintaining secure session state with failover during endpoint provisioning

      
Application Number 17410195
Grant Number 11768746
Status In Force
Filing Date 2021-08-24
First Publication Date 2022-03-03
Grant Date 2023-09-26
Owner Cryptography Research, Inc. (USA)
Inventor Pochuev, Denis Alexandrovich

Abstract

The embodiments described herein describe technologies to maintaining a secure session state with failover during endpoint provisioning. A cluster of hardware devices can be used for provisioning endpoint devices with secrecy, integrity, access controller, high availability, minimal transaction time, and interactive transactions with multiple requests and response within a session. The embodiments are directed to a first computing device being elected as a leader and sharing context information of a session with other computing devices as followers in the cluster such that a follower can resume the session if the leader fails.

IPC Classes  ?

  • G06F 11/20 - Error detection or correction of the data by redundancy in hardware using active fault-masking, e.g. by switching out faulty elements or by switching in spare elements
  • G06F 21/71 - Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information
  • G06F 21/44 - Program or device authentication

100.

Sign-based partial reduction of modular operations in arithmetic logic units

      
Application Number 17309935
Grant Number 12657007
Status In Force
Filing Date 2020-01-06
First Publication Date 2022-02-24
Grant Date 2026-06-16
Owner Cryptography Research, Inc. (USA)
Inventor Hamburg, Michael Alexander

Abstract

Aspects of the present disclosure involve a method and a system to execute the method to perform a cryptographic operation involving a modulo N computation, the method comprising loading a first integer number and a second integer number, wherein the first integer number and the second integer number are within an interval of 2N integer numbers, and performing an arithmetic operation involving the first integer number and the second integer number, wherein the arithmetic operation is to produce a third integer number, and wherein the arithmetic operation comprises a shifting operation to ensure that the third integer number is inside the interval of 2N integer numbers.

IPC Classes  ?

  • G06F 7/72 - Methods or arrangements for performing computations using a digital non-denominational number representation, i.e. number representation without radixComputing devices using combinations of denominational and non-denominational quantity representations using residue arithmetic
  1     2     3     4        Next Page