AUTHENTICATION AND IDENTIFICATION OF PRODUCTS

By using a single pin and external resistor to derive a unique identification value for cryptographic authentication, the method addresses inefficiencies in product identification and authentication on untrusted manufacturing lines, improving security and reducing costs.

DE112023004292T5Pending Publication Date: 2025-08-14MICROCHIP TECHNOLOGY INC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
DE112023004292
Authority / Receiving Office
DE · DE
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-10-07
Filing Date
2023-10-06
Publication Date
2025-08-14

AI Technical Summary

Technical Problem

Manufacturing and assembly lines face challenges in securely identifying and authenticating products, especially in untrusted environments without access to trusted servers, and existing solutions require preprogramming or multiple pins, leading to inefficiencies and increased costs.

Method used

Devices and methods utilize an additional layer of key derivation based on an integer numerical identifier, configurable at assembly, using a single pin and external resistor to determine a unique identification value, which is then used to generate a cryptographic authentication code without preprogramming the integrated circuit.

Benefits of technology

This approach reduces errors, simplifies manufacturing, and lowers costs by allowing a single IC to identify multiple products, enhancing security and reducing the need for individual programming or multiple pins.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

A device comprising: a pin for connecting to a resistor and a power source; a measuring circuit for measuring a voltage at the pin; a circuit for determining an associated identification value of the device based on the voltage at the pin, the associated identification value encoding the device as an instance of a product from a set of products; and an authentication circuit. The authentication circuit calculates an authentication code using the associated identification value and provides the authentication code to an authentication host upon request from the authentication host.
Need to check novelty before this filing date? Find Prior Art

Description

RELATED CASES

[0001] This application claims priority to commonly owned U.S. Patent Application No. 63 / 414,099, filed October 7, 2022, the contents of which are hereby incorporated by reference for all purposes. TECHNICAL FIELD

[0002] The present disclosure relates to electronic identification of devices. Various examples include methods and / or devices for cryptographic authentication and identification with assembly-time configuration of identifying features. BACKGROUND

[0003] Manufacturing, assembly, and packaging lines may assemble products, including consumables, in insecure locations. Furthermore, such facilities may involve managing inventories of multiple products with individual part numbers or stock-keeping units (SKUs). Such lines may be used to label and authenticate parts, but such lines may be located in factories that are untrusted or lack access to trusted servers for labeling and authentication. SUMMARY

[0004] Devices and / or methods incorporating the teachings of the present disclosure may include authentication using an additional layer of key derivations based on an integer numeric identifier that is configurable by a device originator without preprogramming an integrated circuit (IC) device.An example device may include, for example: a pin for sensing a voltage at a point between a resistor and a power source; an analog-to-digital (A / D) converter for converting a signal from the pin into a digital signal; a bit masking circuit for filtering the digital signal and determining an associated identification value of the device based on the filtered digital signal, wherein the associated identification value corresponds to a particular instance of a product among a set of products; and an authentication circuit for: calculating an authentication code using the associated identification value; and providing the authentication code to an authentication host upon request from the authentication host.

[0005] Another example device may include: an integrated circuit (IC); a pin on the IC connected to a resistor and a power source; sensing circuitry in the IC to detect a voltage at the pin; calculating circuitry in the IC to determine an associated identification value of the device based on the voltage at the pin, wherein the associated identification value encodes the device as a particular instance of a product from a set of products; and authentication circuitry in the IC to: calculate an authentication code using the associated identification value; and provide the authentication code to an authentication host upon request from the authentication host.

[0006] An example method incorporating the teachings of the present disclosure may include: receiving a voltage from a point between a resistor and a power source; determining an associated identification value of a device based on the voltage, wherein the associated identification value encodes the device as a particular instance of a product from a set of products; calculating an authentication code using the associated identification value; and providing the authentication code to an authentication host upon request of the authentication host.

[0007] Another example method may include identifying a product type to be manufactured from a set of product types, wherein the product type connects an integrated circuit (IC) to identify and authenticate an instance of the product type; and based on the product type, connecting a selected resistor to a pin of the product, wherein the selected resistor indicates the product type. BRIEF DESCRIPTION OF THE DRAWINGS

[0008] The teachings of the present disclosure include devices and / or methods for authentication using an additional layer of key derivation based on an integer numeric identifier that is configurable by an originator of a device without preprogramming the device.

[0009] Some examples of devices and methods are represented in the drawings in which: Fig. 1 is a schematic drawing showing several exemplary devices incorporating the teachings of the present disclosure; Fig. 2 is a schematic drawing showing an exemplary circuit for the Fig. 1 shows the device shown; Fig. 3 is a drawing showing an exemplary data flow for a method incorporating the teachings of the present disclosure; Fig. 4 is a drawing showing a transaction diagram incorporating the teachings of the present disclosure; and Fig. 5 is a flow diagram showing an exemplary process incorporating the teachings of the present disclosure into a manufacturing process. DETAILED DESCRIPTION

[0010] Examples of the present disclosure may include authentication using an additional layer of key derivation based on an integer numeric identifier that is configurable by a device originator without requiring pre-programming of an IC of the device. Examples of the present disclosure may include devices with a single chip implementation, but that may be used as one of several different products or stock-keeping units (SKUs). Devices and / or methods incorporating the teachings of the present disclosure may reduce errors due to incorrect programming or mounting an incorrect chip on a board and simplify the creation of multiple configurations for different devices.

[0011] The device and / or methods may include using a discrete number as part of a key or other authentication information to identify different SKUs as part of the authentication process. The discrete number may be one of a range of possible numbers and may, for example, be an integer value. The discrete number may be configurable during assembly, e.g., by selecting components with different values, such as resistors.

[0012] Fig. 1 is a schematic representation of various exemplary devices incorporating teachings of the present disclosure. Fig. 1 shows four different devices that include an IC for authentication. The IC may include any suitable implementation without limitation, e.g., stored instructions for execution by a processor, an application-specific integrated circuit, a chip, a field-programmable gate array, a programmable logic device, analog circuits, digital circuits, or any suitable combination thereof. The IC may include an interface to a host. The interface may be provided via any suitable communication format. The host may include any suitable implementation without limitation, e.g., a computer, a server, a test machine, or other suitable electronic device. An IC device or IC may include any suitable implementation without limitation, e.g.,Instructions for execution by a processor, an application-specific integrated circuit, a chip, a field-programmable gate array, a programmable logic device, an analog circuit, a digital circuit, or any suitable combination thereof.

[0013] The devices may include any suitable item, such as a computer, a consumer device, a consumable, a printer cartridge, a toner cartridge, or a color cartridge. The devices may be categorized as different products identified by different SKU numbers. The devices may be differentiated by an external resistor, which is Fig. 1 is denoted by R1, R2, R3, Rn. The resistance value of the external resistor can categorize the device as a specific product. The resistance value of the resistor can vary according to each SKU, so a standardized IC with a symmetric master key can be used for identification and authentication.

[0014] In such examples, the symmetric keys are known to both parties involved in an authentication process. Some methods use a single master key in both the authenticator and the authenticated device. Alternative, more secure methods use a master key in the authenticator and a derived key in the authenticated device. The derived key is the result of a cryptographic hash of the master key with the serial number of the authenticated device. In these cases, a malicious actor accessing the derived key does not thereby gain access to the master key. In some of the methods described here, a derived key may be pre-placed in the authenticated device and further derived by a cryptographic hash with the associated identification value.The authenticator can read the serial number and the identification value (the value of the external resistor) and create the double-derived key to authenticate both the device and the device SKU.

[0015] Devices and / or methods incorporating the teachings of the present disclosure may be used to identify a particular item among various products, e.g., by SKU or configuration. The teachings of the present disclosure may be used and incorporated into an IC design. Some examples include, without limitation, analog and mixed-signal devices to generate an integer ID value with sufficient resolution to identify N different configurations. The ID value may be included in a cryptographically generated authentication code that may be generated by the device IC and validated by the host.

[0016] For example, a device including one IC can be used to implement eight different ink or flavor cartridges without requiring changes to the IC or the printed circuit board (PCB). This means that the same IC and PCB can be used for each color or flavor of a particular product (e.g., each SKU). Manufacturing logistics may limit the use of automated testing and programming. Additionally, the product manufacturer may prefer to purchase and use a single type of IC rather than eight different, factored parts. The teachings of the present disclosure can utilize a single component to determine the ID value during manufacturing.

[0017] This can enable one part number per project, which includes customized provisioning and secret exchange with the host for multiple products. This can facilitate the consolidation of the total number of parts produced and stored and better serve the consumables market. Fig. Figure 1 shows a set of four products. Each individual product represents a specific instance of a product from the group of products. However, each individual product uses the same IC as shown in the figure. The devices and methods described here can also be used for a much larger number of products. As described further below with reference to Table 1, a set of eight discrete products can use the same IC without requiring separate programming or provisioning for each product in the set.

[0018] An example device may require only a single pin, reducing cost and the attack surface. The term "pin," as used herein, includes any connection from an IC, including, without limitation, solder balls or contact pads. Furthermore, the device may provide a secure solution that uses an identifier as part of cryptographic authentication. This can facilitate low-tech manufacturing lines without programming devices, as the devices can be programmed with multiple SKUs using an external resistor, streamlining production line operations when multiple SKUs are involved.The teachings of the present disclosure may be used in any suitable product, including, without limitation, medical devices, e-cigarettes, battery replacement for e-mobility, cosmetics, air fragrances and fresheners, sodas, or any other suitable device. Furthermore, the teachings of the present disclosure may be used to identify and authenticate physical characteristics of a pluggable, replaceable, or consumable product, such as color, flavor or scent, strength, or capacity (battery or other storage). In such cases, the assigned identification value may correspond to a physical property of the product.

[0019] The devices and / or methods described herein may use a single pin of the IC to communicate with both the identification resistor and test equipment for validation. The gauges may be used to authenticate a cartridge, consumable, or other device, as well as an identification value of such a device's SKU. This could enable reallocation of inventory of the same type of ICs to produce different inventory. Furthermore, some examples may provide devices with an option to record and lock the product's assigned identification value in one-time programmable memory against future changes. This may be performed by the device IC or a host IC, device, or apparatus.

[0020] The device and / or method can facilitate the identification value determination during assembly without programming and encapsulate the identification value in an authentication code (MAC) that ensures the integrity and authenticity of the message. This contrasts with options that require one-time programming and individual handling of authentication for integrated circuits. Other solutions may require the use of multiple pins or writing an ID code into a device's memory. In some examples, a calculation circuit within the IC uses the assigned identification value to encode the device as a specific instance of one product from a range of products.

[0021] Fig. 2 shows a schematic drawing of an exemplary circuit for the Fig. 1. A power source can be applied to a pin of the IC in conjunction with a resistor R. As shown in Fig. As shown in Figure 2, the power source may comprise a current source. Other power sources may also be used if they are relatively constant, such as a regulated voltage source. The power source is applied to a first lead of resistor R. A second lead of resistor R is coupled to a common potential or return for the power source. The pin of the IC is coupled to the first lead of resistor R.

[0022] As in Fig. As shown in Figure 2, a signal from the pin is passed to a digital-to-analog (A / D) converter of the IC to convert the voltage at the pin into a digital value. The digital value can be converted to an associated ID value or filtered, involving bit masking or other techniques. Filtering the digital value reduces the number of finite discrete values ​​mapped to an input range and can eliminate the effects of small input voltage fluctuations.

[0023] In the example shown, the filter includes a decimation filter of the IC, which may, without limitation, contain instructions for execution by a processor, an application-specific integrated circuit, a chip, a field-programmable gate array, a programmable logic device, an analog circuit, a digital device, or any suitable combination thereof. The assigned ID value can be used by other parts of the IC. An example of the translation between voltages and resistance values ​​is shown in Table 1. In this example, the output of an 8-bit A / D converter produces a voltage range between 0 and 2.5 volts from a variety of resistance values. When the result is filtered by removing the lowest 5 bits, 8 discrete output values ​​are obtained:

[0024] In practice, an authentication host can request authentication of a specific product. In response, a voltage is detected at a point between the resistor and the power source. Based on this voltage, the assigned identification value can be determined. As described above, the assigned identification value encodes the device as a specific product from a range of products. The assigned identification value can be used to calculate an authentication code for the message. This message authentication code is ultimately returned to the requesting authentication host.

[0025] Fig. Figure 3 is a drawing showing an exemplary data flow for a method incorporating the teachings of the present disclosure. The upper arrow shows the assigned ID value, which is the result of the Fig. 2 shown circuit. The assigned ID value can be combined with other information stored in Fig. 3 labeled Padding Data for MAC, and a secret key known to or derived from a host and device. The associated ID value, other information, and the secret key can be hashed using a secure hash value (SHA) algorithm, an Advanced Encryption Standard (AES) algorithm, or another encryption algorithm to generate a MAC. The MAC can be provided by the device to the host, which can then use it to authenticate the MAC. In some options, a derived key can be formed using the secret key and a unique internal serial number of the device.This option enables the use of a diversified key, which can enhance the protection of the secret key and authenticates the device ID using the serial number in addition to authenticating the SKU using the issued ID value. An example authentication process is shown in . Fig. 4 shown.

[0026] Fig. Figure 4 is a float diagram showing an example of a method for authentication incorporating the teachings of the present disclosure. The diagram illustrates the steps and data used for cryptographic authentication and identification by SKU and serial number. The process enables an authenticating host to authenticate a device that includes one or more of the devices described herein. As shown, the host presents a request for authentication and a request for identification to the device. In response, the device reads the signal and generates the associated identification value. The associated identification value is sent from the device to the host. As shown, the host encrypts the associated identification value with a secret key.The host then sends a serial number request to the device, and the device responds with the device's serial number. After receiving the serial number, the host encrypts the received serial number with the previous hash value.

[0027] The host then requests a MAC from the device. The device calculates a MAC using a derived key hashed with the identification value created above and the device's serial number, and provides the calculated MAC in response to the host.

[0028] Finally, the host checks the MAC against the device's MAC using a master key, the received serial number, and the associated identification value. If they match, the device is assumed to be authenticated, and the manufacturing process can continue. If they do not match, an error message or a flag can be generated indicating that the device is not authenticated. This allows the IC to calculate an authentication code for the message and provide this code to the requesting authentication host.

[0029] Fig.5 is a flowchart showing an example method in which the teachings of the present disclosure are incorporated into a manufacturing process. The example method illustrates an example application scenario for using examples of the present disclosure. The shown method can be used to sort a customer's inventory into multiple SKUs. The application of the provided authentication devices in combination with a printed circuit board or generic assembly sorts generic inventory into the various SKUs shown by adding the correct resistor to each device without requiring individual programming and handling of the ICs. Other solutions may require the use of multiple pins or digitally writing memory to a device.

[0030] In practice, a customer may tag their inventory by adding corresponding resistors to the product. One method of tagging inventory may involve identifying a product as a particular product type from a set (or list) of product types. This particular product type may include an identifier used to identify and authenticate an instance of the product type. Based on the particular product type, a corresponding resistor is identified. The resistor is then connected to a corresponding pin on the IC, enabling one or more of the identification methods described here. In some cases, each product type in the set of product types has a matching IC, as described here, so that a single version of the IC can identify all product types in the set of product types.In some cases, the selection of a resistor corresponds to a physical property of the product.

[0031] Although the devices and methods described above are examples, other variations may be made from the teachings of this disclosure without departing from the spirit and scope of this disclosure. QUOTES CONTAINED IN THE DESCRIPTION

[0000] This list of documents submitted by the applicant was generated automatically and is included solely for the convenience of the reader. This list is not part of the German patent or utility model application. The DPMA assumes no liability for any errors or omissions. Cited patent literature

[0000] US 63 / 414,099

[0001]

Claims

[1] Device comprising: a pin for sensing a voltage at a point between a resistor and a power source; a digital-to-analog converter (A / D converter) for converting the sampling voltage from the pin into a digital signal; a bit masking circuit for filtering the digital signal and for determining an associated identification value of the device based on the filtered digital signal, the associated identification value corresponding to a particular instance of a product from a set of products; and an authentication circuit to: calculate a message authentication code using the associated identification value; and provide the message authentication code to an authentication host upon request from the authentication host. [2] The device of claim 1, wherein the associated identification value corresponds to a physical property of the device. [3] The device of any one of claims 1 to 2, wherein the bit masking circuit is to determine the associated identification value from data on the pin. [4] The device of any one of claims 1 to 3, wherein the bit masking circuit permanently writes the associated identification value after a first determination of the associated identification value. [5] Device comprising: an integrated circuit (IC); a pin on the IC connected to a resistor and a power source; a calculation circuit in the IC for determining an associated identification value of the device based on a voltage at the pin, the associated identification value encoding the device as a particular instance of a product from a set of products; and an authentication circuit in the IC to: calculate a message authentication code using the associated identification value; and provide the message authentication code to an authentication host upon request from the authentication host. [6] The device of claim 5, wherein the associated identification value corresponds to a stock keeping unit (SKU) of the device. [7] The apparatus of claim 6, wherein each product type within the set of product types includes a matching IC. [8] The device of claim 7, wherein the calculation circuit determines the associated identification value of the device based on data at the pin. [9] Device according to one of claims 7 to 8, wherein the IC permanently writes the assigned identification value after a first determination of the assigned identification value. [10] Method comprising: Receiving a voltage from a point between a resistor and a power source; Determining an associated identification value of a device based on the voltage, wherein the associated identification value encodes the device as a particular instance of a product from a set of products; and Calculating a message authentication code using the associated identification value; Providing the message authentication code to an authentication host upon request from the authentication host. [11] The method of claim 10, wherein the associated identification value identifies a physical property of the device. [12] The method of any one of claims 10 to 11, wherein providing the associated identification value to the authentication host supports the verification of the authentication code. [13] The method of any one of claims 10 to 12, further comprising determining the associated identification value of the device from data at a pin of the device. [14] The method of any one of claims 10 to 13, further comprising permanently writing a value of the associated identification value after a first determination of the associated identification value. [15] Method comprising: Identifying a product type to be manufactured from a set of product types, the product type including an integrated circuit (IC), to identify and authenticate an instance of the product type; and based on the product type, connecting a resistor to a pin of the product, where the resistor corresponds to the product type. [16] The method of claim 15, wherein each product of the set of products includes an instance of the IC. [17] A method according to any one of claims 15 to 16, wherein the selected resistance corresponds to a physical property of the product. [18] A method according to any one of claims 15 to 17, further comprising: Applying power to the pin; Cause the product to identify the product type; and Cause the product to permanently write a value of the product type to the IC.

Citation Information

Patent Citations

  • US-PATENTANMELDUNGNR.63/414,099