Key generation method
By using software update programs and secret values in electronic systems to generate symmetric keys, and using one-way functions and hash functions for key derivation, the problem of keys being discovered by pirates is solved, and the security management and update of encryption keys is realized.
Patent Information
- Application Number
- CN202010919879.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-09-06
- Filing Date
- 2020-09-04
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2040-09-04
AI Technical Summary
When generating and managing encryption keys in electronic systems, the prior art has the problem that the next key is no longer secret after the key is discovered by the pirate, and there is a security risk in the key management process.
By using software update programs and secret values in electronic devices to generate symmetric keys, converting software update programs and secret values into words using one-way functions and hash functions, and then generating a new symmetric key using the key derivation function, ensuring that secret values are not exposed during the update and management of the key.
The security of generating and managing encryption keys in an electronic system is realized, ensuring that the key is not discovered by pirates during the update process, and improving the overall security of the system.
Smart Images

Figure CN112468289B_ABST
Abstract
Description
[0001] Cross - Reference to Related Applications
[0002] This application claims priority to French Patent Application No. 1909823, filed on September 6, 2019, which is incorporated herein by reference. Technical Field
[0003] The present disclosure generally relates to methods for protecting electronic systems, and more particularly to methods for generating encipherment and / or encryption keys. Background Art
[0004] Cryptography is a discipline that aims, in particular, to protect messages or content sent between two electronic devices using encryption or encipherment keys (ensuring confidentiality, authenticity, and integrity). The key enables the encryption and decryption of the message. A person without the correct key cannot read the message. Summary of the Invention
[0005] Embodiments provide a method for generating a symmetric key, wherein the symmetric key is generated by an electronic device based on a program for updating software and a secret value stored by the electronic device.
[0006] According to one embodiment, the method includes receiving, by the device, an update program of software sent by a server.
[0007] According to one embodiment, the update program is encrypted.
[0008] According to one embodiment, the symmetric key is also generated by the server.
[0009] According to one embodiment, the method includes a step of generating a first word representing the update program.
[0010] According to one embodiment, the first word represents the decrypted update program.
[0011] According to one embodiment, the method includes a step of generating at least one second word representing the secret value.
[0012] According to one embodiment, the symmetric key is generated by applying a key derivation function to at least one of the first word and the second word.
[0013] According to one embodiment, the symmetric key is generated by applying a key derivation function to a third word representing one of the first word and the second word.
[0014] According to one embodiment, the generation of the word is done by a one-way function.
[0015] According to one embodiment, the generation of the word is done by a hash function.
[0016] According to one embodiment, the secret value is a key that has been written to the non-volatile memory during the initial programming of the software.
[0017] According to one embodiment, the secret value is a key that has been generated during a previous update of the software.
[0018] According to one embodiment, the secret value is an identifier of the device.
[0019] Another embodiment provides an electronic circuit that includes means for performing the previously described method.
[0020] Another embodiment provides an electronic system that includes a server and at least one electronic device, and the server and these electronic devices include circuits as previously described. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] The foregoing features and advantages, as well as other features and advantages, will be described in detail in the following description of specific embodiments given by way of illustration and not limitation, with reference to the accompanying drawings, in which:
[0022] Figure 1 An electronic device system to which the described embodiments are applicable is shown;
[0023] Figure 2 A method according to one embodiment of the method for generating a key is shown in block diagram;
[0024] Figure 3 A method according to another embodiment of the method for generating a key is shown in block diagram;
[0025] Figure 4 A method according to yet another embodiment of the method for generating a key is shown in block diagram;
[0026] Figure 5 A method according to still another embodiment of the method for generating a key is shown in block diagram; and
[0027] Figure 6 is shown Figure 1 an example functional scenario of the system of. DETAILED DESCRIPTION
[0028] In the various figures, like features have been denoted by like reference numerals. In particular, structural features and / or functional features common to the various embodiments may have the same reference numerals and may be provided with the same structural characteristics, dimensional characteristics, and material characteristics.
[0029] For clarity, only the operations and elements useful for understanding the embodiments described herein are shown and described in detail. In particular, elements that can be used to send messages, for example, between an electronic device and a server, are not described in detail, and the described embodiments are compatible with all known transmission elements.
[0030] Unless otherwise stated, when referring to two elements connected together, this means a direct connection without any intermediate element other than a conductor, and when referring to two elements coupled together, this means that the two elements can be connected or they can be coupled via one or more other elements.
[0031] In the following disclosure, unless otherwise stated, when referring to absolute position qualifiers (such as the terms "front", "rear", "top", "bottom", "left", "right", etc.) or relative position qualifiers (such as the terms "above", "below", "higher", "lower", etc.) or orientation qualifiers (such as "horizontal", "vertical", etc.), the orientation shown in the figures is referenced.
[0032] Unless otherwise stated, the expressions "about", "approximate", "substantially", and "approximately" mean within 10%, and preferably within 5%.
[0033] Figure 1 An electronic device system of the following type is shown, and the described embodiments are applicable to this type of electronic device system.
[0034] Figure 1 An electronic system 100 including an electronic device is shown. More particularly, system 100 includes a server 102 (SERVER) and devices 104 (DEVICE1, DEVICE2, DEVICE3, DEVICE4). Electronic system 100 includes at least one device 104, preferably at least two devices 104. Although only one device 104 (DEVICE1) is described in detail, devices 104 are preferably similar.
[0035] Device 104 is configured to be able to receive data from server 102 and, optionally, to be able to send data to server 102. Server 102 periodically sends software updates to device 104. Optionally, device 104 can be configured to send data between these devices 104 without going through server 102.
[0036] Data transmitted between device 104 and server 102 or between devices 104 is preferably encrypted to protect the data from pirates or third parties attempting to illegally obtain the data. To encrypt the transmitted data, server 102 and device 104 each include at least one encryption key (KEY).
[0037] Preferably, the encoding and / or encryption key is a symmetric key. Thus, for example, during data transmission between the server 102 and one or more of the devices 104, the server 102 uses the symmetric encryption key to encrypt the data, and the device(s) 104 use the same key as the key that allowed the encryption of the message to decrypt the data after reception.
[0038] The devices 104 all have, for example, the same key to encrypt / decrypt the data transmitted between the devices 104 and the server 102. The server 102 can then include only a single key to encrypt / decrypt the data transmitted using the devices 104.
[0039] As a variant, the devices 104 can each have their own encryption key. The server 102 then has as many encryption keys as there are devices 104 included in the system. The data to be transmitted is then encrypted using the key corresponding to the device 104 that the data is intended for. When it is desired to send data to all the devices 104, each device 104 receives the encrypted data with its encryption key.
[0040] Optionally, the server 102 and the devices 104 can include private and public keys such that data can be encrypted / decrypted asymmetrically.
[0041] For various reasons, it may be desirable to periodically modify the key(s), for example to ensure that the key is not known to a third party. However, in terms of computer security, directly sending a new encryption key, even if encrypted, is risky, especially if there is a risk that the previous key will no longer be protected.
[0042] The devices 104 each include, for example: a processor 106 (μ); a communication circuit 108 (COM) configured to allow data transmission between the device 104 and a circuit external to the device 104 (such as the server 102); one or more memories 110 (MEM) including non-volatile memory and optionally volatile memory (such as RAM memory), the non-volatile memory and optionally volatile memory including in particular one or more programs of the encoding and / or encryption key(s) and the software of the device; and a circuit 112 (KEY GEN) representing the part of the device configured to generate a new key.
[0043] Generating a new key by the circuit 112 is done, for example, by software, in which case the circuit 112 includes a processor, such as the processor 106 or another processor. Generating a new key by the circuit 112 can also be done, for example, by hardware, that is to say, by circuits and logic gates, in which case the circuit 112 includes the hardware used.
[0044] Refer toFigures 2 to 5 Embodiments of a method for generating a symmetric key are described. The generated symmetric key can be an encoding and / or encryption key. An element common to all the described embodiments is that they include generating the key locally according to a software update. These methods are preferably applied each time the device 104 receives a software update program (e.g., a "firmware image").
[0045] Figure 2 Embodiments of a method for generating or updating a symmetric key are shown. The key is generated from a software update program and a secret value (here the previous key).
[0046] The generating method or updating method includes step 200 (transmitting the update), during which the server 102 ( Figure 1 ) supplies the software update program to all devices 104. The transmitted program has been encrypted with an encryption key, preferably a symmetric key used only for transmitting the update, e.g., a key supplied to the device during initial programming of the device and stored in non-volatile memory. The key generated by the methods described herein is preferably not used for transmitting the update, but for transmitting other messages. As mentioned above, if different devices each have their own symmetric key, the program is encrypted separately for each device with the corresponding key.
[0047] The update program transmitted during step 200 is available to the device 104, for example, during a given time period. Thus, during this time period, the device can obtain or download the update program and decrypt the update program with the device's symmetric key. Thus, the server 102 maintains the current key(s) at least during this entire time period.
[0048] The method will be described below considering only the server 102 and a single device 104 Figure 2 Of course, it should be understood that when all devices 104 receive the software update, the method is executed in parallel by all devices 104.
[0049] In the next step 202 (D1 = f1(FIRMWAREIMAGE)), the device 104 generates a word D1 representing the update program by applying the function f1() to the software update program. The function f1() is preferably a one-way function, that is, it is not possible to obtain the input value of the one-way function from the result. The function f1() is, for example, a hash function, such as the so-called SHA256 function. The function f1() is, for example, a function for generating a signature.
[0050] Preferably, the software update program is decrypted by using the current symmetric key, and the function f1() is applied to the decrypted program. This makes it difficult for pirates to obtain the word D1 even if the transmission of the software update program is intercepted. Optionally, the function f1() can be applied to the encrypted software update program.
[0051] During the next step 204 (D2 = f2(KEY)), the word D2 representing the previous symmetric key is generated by applying the function f2() to the previous symmetric key.
[0052] The previous key is, for example, a key different from the key used for transmitting the update and provided to the device 104 during the initial programming of the system, such as an OEM (Original Equipment Manufacturer) key. The same previous key is used, for example, to generate the word D2 each time a software update is performed.
[0053] The previous key is, for example, a key that has been generated by the same method used for generating the symmetric key during a previous software update.
[0054] The function f2() is preferably the same function as the function f1(). However, the function f2() can be another function, preferably a one-way function, such as another hash function, such as another function for generating a signature.
[0055] Steps 202 and 204 are, of course, interchangeable. Thus, step 204 can be performed before step 202. Steps 202 and 204 can also be performed simultaneously.
[0056] During the next step 206 (Symkey = KDF(D1 / D2)), a new symmetric key (SymKey), that is, an updated symmetric key, is generated from the words D1 and D2 by applying the key derivation function KDF() to the words D1 and D2. For example, the function KDF() can be applied to the concatenation D1 / D2 of the words D1 and D2.
[0057] The key derivation function KDF() is, for example, the hash key derivation function HKDF. The key derivation function KDF() is, for example, a signature generation function.
[0058] Before or after step 200 for transmitting the software update program, the server 102 performs steps 202, 204, and 206 from the same elements (key, encrypted program, or decrypted program) in order to obtain the same key.
[0059] When considering all the devices 104 of the system 100, the devices 104 preferably all execute the same method. However, the devices 104 can execute the method with different previous keys KEY. Therefore, the devices 104 all obtain a new key SymKey specific to these devices.
[0060] In the case where each device 104 obtains a key specific to that device, the server 102 executes the method the same number of times as the number of devices 104 present, in order to generate new keys for all the devices 104.
[0061] Figure 3 Another embodiment of a method for generating or updating a symmetric key is shown. A key is generated from a software update program and a secret value (here the previous key).
[0062] Figure 3 The method includes steps similar to those of Figure 2 the method. In particular, for each device 104, Figure 3 the method includes:
[0063] - Step 200, during which the server 102 transmits an encrypted software update program to the devices 104 of the system 100, which program is then decrypted by each device 104;
[0064] - Step 202, during which a word D1 representing the software update program is generated by applying the function f1() to the encrypted or decrypted software update program; and
[0065] - Step 204, during which a word D2 representing the previous encryption key is generated by applying the function f2() to the previous key.
[0066] As previously mentioned, steps 202 and 204 are of course interchangeable. Thus, step 204 can be executed before step 202. Steps 202 and 204 can also be executed simultaneously.
[0067] Figure 3 The method then includes step 300 (D3 = f3(D1 / D2)), during which a word D3 representing the words D1 and D2 is generated. The word D3 is obtained by applying the function f3() to the words D1 and D2 (e.g., to the concatenation D1 / D2 of the words D1 and D2).
[0068] The function f3() is, for example, the same function as the function f1() and / or the function f2(). The function f3() is, for example, another one-way function. The function f3() is, for example, a function such that it can ensure that the word D3 has a size smaller than the concatenation D1 / D2 of the words D1 and D2 (e.g., has the same size as the word D1 and / or the word D2).
[0069] During the next step 302 (Symkey = KDF(D3)), a new encryption key SymKey is obtained by applying the key derivation function KDF() to the third word D3.
[0070] Before or after step 200 for transmitting the software update program, the server 102 performs steps 202, 204, 300, and 302 on the same elements (key, encrypted program, or decrypted program) to obtain the same key.
[0071] Figure 4 Another embodiment of a method for generating or updating a symmetric key is shown. A key is generated from a software update program and a secret value (here a secret word).
[0072] Figure 4 The method includes steps similar to those of Figure 2 and Figure 3 the method. In particular, for each device 104, Figure 4 the method includes:
[0073] - Step 200, during which the server 102 transmits the encrypted software update program to the device 104 of the system 100, which is then decrypted by each device 104; and
[0074] - Step 202, during which a word D1 representing the software update program is generated by applying the function f1() to the encrypted or decrypted software update program.
[0075] During the next step 400 (D4 = f4(DEVICE.ID)), each device 104 generates the word D4. The words D4 generated by the devices 104 can all be different from each other. In fact, each word D4 represents a secret word preferably known only to the server 102 and the corresponding device 104. Each word D4 is generated by applying the function f4() to the secret word.
[0076] The secret word is, for example, the identification number (DEVICE.ID) of the device 104. The identification number can be determined and programmed, for example, during the initial programming of the system. As a variant, the identification number can be a Physical Unclonable Function (PUF), that is, preferably a random number associated with the electronic device by physical characteristics.
[0077] The function f4() is, for example, the same function as the function f1(). The function f4() is, for example, another one-way function. The function f4() is, for example, a hash function. The function f4() is, for example, a function for generating a signature.
[0078] Steps 202 and 400 are of course interchangeable. Thus, step 400 can be executed before step 202. Steps 202 and 400 can also be executed simultaneously.
[0079] During the next step 402 (Symkey = KDF(D1 / D2)), a new symmetric key (SymKey), that is, an updated symmetric key, is generated from words D1 and D4 by applying the key derivation function KDF() to words D1 and D4. More particularly, the function KDF() can be applied to the concatenation D1 / D4 of words D1 and D4.
[0080] The key derivation function KDF() is, for example, a hash key derivation function HKDF. The key derivation function KDF() is, for example, a signature generation function.
[0081] Before or after step 200 for transmitting the software update program, the server 102 performs steps 202, 400, and 402 from the same elements (key, encrypted program, or decrypted program) in order to obtain the same key.
[0082] Figure 5 Another embodiment of a method for generating or updating a symmetric key is shown. A key is generated from a software update program and a secret value (here a secret word).
[0083] Figure 5 The method includes steps similar to those of Figure 4 the method of Figure 5 The method includes:
[0084] - Step 200, during which the server 102 transmits an encrypted software update program to the device 104 of the system 100, which program is then decrypted by each device 104;
[0085] - Step 202, during which a word D1 representing the software update program is generated by applying the function f1() to the encrypted or decrypted software update program; and
[0086] - Step 400, during which a word D4 representing a secret word associated with the device 104 is generated by applying the function f4() to the secret word.
[0087] As previously mentioned, steps 202 and 400 are of course interchangeable. Thus, step 400 can be executed before step 202. Steps 202 and 400 can also be executed simultaneously.
[0088] Figure 5The method then includes step 500 (D5 = f5(D1 / D4)), during which a word D5 representing words D1 and D4 is generated. Word D5 is obtained by applying function f5() to words D1 and D4 (e.g., to the concatenation of words D1 and D4).
[0089] Function f5() is, for example, the same function as function f1() and / or function f4(). Function f5() is, for example, the same function as Figure 3 function f3(). Function f5() is, for example, another one-way function. Function f5() is, for example, a function such that it can be ensured that word D5 has a size smaller than the concatenation D1 / D4 of words D1 and D4 (e.g., has the same size as word D1 or word D4).
[0090] In the next step 502 (Symkey = KDF(D5)), a new symmetric key SymKey is obtained by applying the key derivation function KDF() to word D5.
[0091] Before or after step 200 for transmitting the software update program, server 102 performs steps 202, 400, 500, and 502 from the same elements (key, encrypted program, or decrypted program) in order to obtain the same key.
[0092] Figure 6 An example functional scenario of a system having Figure 1 the type of system is shown.
[0093] In Figure 6 the example, devices 104DEVICE1, DEVICE2, and DEVICE3 have received the software update program, for example, by downloading the software update program. These devices have generated a new symmetric key KEY' by using the generation method described with reference to Figure 2 , Figure 3 , Figure 4 or Figure 5 . Similarly, server 102 has generated a new symmetric key KEY'.
[0094] However, in this example, device 104DEVICE 4 has not received or downloaded the update program when the update program is available. This is, for example, because a piracy attack has disrupted the software. Thus, this device 104 has an unupdated symmetric key KEY, and this device 104 cannot access the data transmitted by server 102. This makes it possible to prevent a device with compromised security from accessing encrypted data and compromising the security of the entire system.
[0095] An advantage of some embodiments of previously generating a new symmetric key is that they enable ensuring that device 104 has received all updates.
[0096] An advantage of some embodiments of always generating a new key from the same secret value is that this enables ensuring that if the key is discovered by a third party (e.g., a pirate), the next key remains secret. Additionally, the secret value is never transmitted outside the device and the server, which enables ensuring that the secret value is not discovered.
[0097] An advantage of embodiments where each device has its own latest key is that the transmission between server 102 and one of the devices 104 is secure with respect to the other devices 104. Thus, it is impossible for device 104 to decrypt a message for another device 104.
[0098] Various embodiments and variations have been described. Those skilled in the art will understand that certain features of these embodiments can be combined, and other variations will readily occur to those skilled in the art. In particular, other steps can be added to embodiments of the method for generating a symmetric key, such as other steps for generating words. In particular, the first word D1 can be used with any combination of the words D1, D2, D3, D4, and D5 to generate a new encryption key.
[0099] Additionally, additional functions can be applied to different words during different embodiments of the method for generating an encryption key.
[0100] Finally, based on the functional descriptions provided above, the actual implementation of the embodiments and variations described herein is within the capabilities of those skilled in the art.
Claims
1. A method for generating a symmetric key, comprising: Receiving, by an electronic device, an encrypted update program for updating software of the electronic device from a server; Decrypting, by the electronic device, the encrypted update program using an encryption key stored in a memory of the electronic device during initial programming of the electronic device; Generating, by the electronic device, the symmetric key according to the decrypted update program and a secret value saved by the electronic device; And Decrypting, by the electronic device, an encrypted message received from the server using the symmetric key, the encrypted message being encrypted data other than the encrypted update program; Further comprising: generating a first word representing the update program by applying a function to the software update program.
2. The method according to claim 1, wherein the symmetric key is further generated by the server.
3. The method according to claim 1, wherein the first word represents the decrypted update program.
4. The method according to claim 1, wherein generating the symmetric key comprises: Applying a key derivation function to the first word and at least one second word.
5. The method according to claim 1, wherein generating the symmetric key comprises: Applying a key derivation function to a third word, the third word representing the first word and a second word.
6. The method according to claim 1, wherein generating the first character comprises: Generating the first word by a one-way function.
7. The method according to claim 1, wherein generating the first character comprises: Generating the first word by a hash function.
8. The method according to claim 1 further comprises: Generating at least one second word, the second word representing the secret value.
9. The method according to claim 1, wherein the secret value is a key written into a non-volatile memory during initial programming of the software.
10. The method according to claim 1, wherein the secret value is a key generated during a previous update of the software.
11. The method according to claim 1, wherein the secret value is an identifier of the electronic device.
12. An electronic device, comprising: A processor; And A non-transitory computer-readable storage medium configured to store a program for execution by the processor, the program including instructions for performing the method according to claim 1.
13. An electronic system, comprising: A server; And At least one electronic device according to claim 12.
Citation Information
Patent Citations
Key generating apparatus, key generating method, key generating program, and electronic apparatus
JP2009284231A
Apparatus and method of decoding firmware for upgrading the firmware
KR1020090051475A
Secure firmware update procedure for programmable security devices
US20060005046A1
Method and system for protected transmission of files
US9225692B2