Semiconductor device, certificate generation method in semiconductor device, and program
The semiconductor device efficiently generates a device certificate by decrypting and using a CA key to create a device key and certificate data, addressing inefficiencies and security limitations in existing methods.
Patent Information
- Application Number
- PCT/JP2024/037514
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-11
- Filing Date
- 2024-10-22
- Publication Date
- 2025-06-19
AI Technical Summary
Existing methods for generating certificates in semiconductor devices are inefficient, requiring time-consuming communication and incurring manufacturing costs, and do not allow for flexible key management, such as changing authentication keys for each user.
A semiconductor device equipped with a first key processing unit to decrypt a CA key supplied from outside, a second key processing unit to generate a device key, a certificate data generation unit to generate certificate data, and a signature processing unit to sign with the CA key, allowing the device to self-generate a device certificate.
This approach improves the efficiency of certificate generation in semiconductor devices by reducing communication time and manufacturing costs, while also enhancing security through flexible key management and self-certification within the device.
Smart Images

Figure JP2024037514_19062025_PF_FP_ABST
Abstract
Description
Semiconductor device, certificate generation method and program for semiconductor device
[0001] The present technology relates to a semiconductor device, a certificate generation method for a semiconductor device, and a program.
[0002] In semiconductor devices (such as semiconductor chips) used in electronic devices, etc., in order to provide security functions to users of the semiconductor device (such as purchasers of the semiconductor device), it is necessary to store a device key and a certificate linked to the device key in the semiconductor device during the manufacturing process of the semiconductor device.
[0003] To generate a device certificate, a key other than the device key is required, and the value of that key differs for each user who uses the semiconductor device. Also, the value of the device key is required to differ for each semiconductor device. In other words, certificate generation must be performed for each semiconductor device using a key that differs for each user.
[0004] In the conventional manufacturing of semiconductor devices, first, the semiconductor device itself generates a device key, an external server reads the device key from the semiconductor device, and the external server transmits the device key to a certificate creation server. Then, a tester stores the certificate created by the certificate creation server for each semiconductor device. This process has the problem of taking a long time for communication and increasing manufacturing costs.
[0005] Regarding the creation of certificates, a technology has been proposed in which a device issues a certificate by itself (Patent Document 1).
[0006] Special Publication No. 2002-535740
[0007] However, in the technology of Patent Document 1, an authentication key (e.g., a so-called CA key) for creating a certificate for a device key is embedded in the device during the manufacturing process before the device is shipped, and is then used when generating the device key. Therefore, the authentication key is fixed at the time of shipping the device, and the authentication key cannot be changed for each user during the device manufacturing process, leaving room for improvement in terms of the efficiency of the certificate generation process.
[0008] The present technology has been developed in consideration of such problems, and aims to provide a semiconductor device, a certificate generation method in a semiconductor device, and a program that can improve the efficiency of certificate generation in the semiconductor device.
[0009] In order to solve the above-mentioned problems, there is a semiconductor device that includes a first key processing unit that decrypts a CA key supplied from outside, a second key processing unit that generates a device key, a certificate data generation unit that generates certificate data using the device key, and a signature processing unit that signs with the CA key to generate a signature.
[0010] The second technology is a certificate generation method for a semiconductor device, which acquires a CA key supplied from outside, decrypts the CA key, generates a device key, generates certificate data using the device key, signs with the CA key to generate a signature, and generates a device certificate consisting of the certificate data and the signature.
[0011] Furthermore, the third technology is a program that causes a computer to execute a certificate generation method in a semiconductor device, which acquires a CA key supplied from outside, decrypts the CA key, generates a device key, generates certificate data using the device key, signs with the CA key to generate a signature, and generates a device certificate consisting of the certificate data and the signature.
[0012] It is an explanatory diagram of key sharing. It is a block diagram showing the configuration of the semiconductor device 100. It is a diagram showing the processing in the semiconductor device 100. It is a diagram showing the configuration of a device certificate. It is a diagram showing the configuration of a device certificate.
[0013] Hereinafter, embodiments of the present technology will be described with reference to the drawings. The description will be made in the following order: <Embodiment> [Key sharing] [Configuration of semiconductor device 100] [Processing in semiconductor device 100] <Modification>
[0014] 1, a description will be given of key sharing for generating a device certificate in the semiconductor device 100. The key is shared by the security department of the manufacturer, the manufacturing department of the manufacturer, the user, and the semiconductor device 100.
[0015] The device certificate is an electronic certificate that certifies that the semiconductor device 100 is an authentic product manufactured by a manufacturer. The semiconductor device 100 in which the device certificate is stored is recognized as an authentic device that can use a system, etc., and is able to use specific functions such as security functions, connect to various servers and services, etc.
[0016] A manufacturer is a business that manufactures semiconductor devices 100 and provides them to users, who are customers. A manufacturer is divided into a security department and a manufacturing department. The security department is a department within a manufacturer that is responsible for processing and processes related to the security of the semiconductor device 100. The manufacturing department is a department within a manufacturer that is responsible for manufacturing the semiconductor device 100.
[0017] The user is a customer of the manufacturer who receives the semiconductor device 100 from the manufacturer by purchasing it or the like and uses it.
[0018] The security department and manufacturing department of the manufacturer share a common key, a pre-shared key (PSK), in advance before manufacturing the semiconductor device 100. Therefore, communication between the security department and the manufacturing department may not be necessary.
[0019] Also, the manufacturing department of the manufacturer stores the PSK in the semiconductor device 100 during the manufacturing process before providing the semiconductor device 100 to the user.
[0020] Furthermore, it is assumed that a security department of the manufacturer generates a CA (Certificate Authority) key in advance before providing the semiconductor device 100 to a user. The security department of the manufacturer stores the generated CA key in a secure server (not shown) or the like. The CA key is an authentication key required to generate a device certificate, and is managed by the manufacturer that produces the semiconductor device 100. The CA key has a different value for each user, but if the user uses multiple semiconductor devices 100, the value does not need to be different for each semiconductor device 100.
[0021] Before the key sharing process described below is executed, the manufacturer supplies (ships, etc.) the semiconductor device 100 to the user, but at the time of supply, the device certificate, device key, and CA key are not stored in the semiconductor device 100. The semiconductor device 100 has a mechanism for generating a device certificate and a device key.
[0022] As shown in Figure 1, first, the manufacturer's security department wraps the CA key using PSK. Wrapping is an encryption process to prevent the plaintext CA key from being leaked or stolen over the communication path and being misused. The manufacturer's security department encrypts the CA key by wrapping it in advance. Therefore, the manufacturer's manufacturing department does not need to encrypt the CA key. The encryption algorithm is not limited to a specific algorithm, and various encryption algorithms can be used.
[0023] Next, the manufacturer's security department sends the wrapped CA key to the user. The security department of the manufacturer calculates the MAC value of the CA key in advance and sends the MAC value of the CA key to the user along with the wrapped CA key.
[0024] In this way, the manufacturer's security department sends the CA key to the user, but if the CA key is sent in plain text, there is a possibility that it may be leaked. Therefore, the CA key is wrapped.
[0025] Although the CA key is different for each user, it is not different for each semiconductor device 100, and therefore the same CA key may be stored in multiple semiconductor devices 100 used by a specific user. Therefore, even when a user uses multiple semiconductor devices 100, the security department of the manufacturer may supply the user with one type of CA key rather than supplying different CA keys for each semiconductor device 100.
[0026] The user inputs the acquired CA key and the MAC value of the CA key into the semiconductor device 100. In this way, in the present technology, the CA key is input into the semiconductor device 100 by the user. In this technology, a device certificate is generated within the semiconductor device 100, so the CA key required for generating the device certificate is also sent to each semiconductor device 100 at the time of manufacture. The process of inputting this CA key into the semiconductor device 100 is performed in a process carried out by the user. The user corresponds to an external entity in the scope of the claims that supplies and inputs the CA key into the semiconductor device 100.
[0027] The semiconductor device 100 decrypts the encrypted CA key by performing unwrapping processing using a PSK. After unwrapping processing, the semiconductor device 100 checks the MAC value. Then, the semiconductor device 100 generates and stores a device certificate using the decrypted plaintext CA key.
[0028] 2, the configuration of the semiconductor device 100 will be described. The semiconductor device 100 includes a storage unit 101, a communication unit 102, a control unit 103, a first key processing unit 104, a true random number generation unit 105, a second key and signature processing unit 106, a certificate data generation unit 107, and a hash value calculation unit 108.
[0029] The storage unit 101 stores keys and various data used in processing in the semiconductor device 100. Specifically, the storage unit 101 stores a PSK, a private key of a generated public key pair, a generated device certificate, and the like. The PSK is stored in the storage unit 101 in advance by the manufacturing department of the manufacturer before the semiconductor device 100 is provided to a user. The storage unit 101 is, for example, a non-volatile memory such as an OTP (One Time Programmable) memory.
[0030] The communication unit 102 performs communication processing with the host 200 including the communication unit 201. An example of a communication method is I2C (Inter-Integrated Circuit). I2C is a synchronous serial communication method that communicates data in synchronization with a clock, and is mainly used for data communication with EEPROMs (Electrically Erasable and Programmable Read Only Memory) and sensors. However, the communication method is not limited to I2C and other methods may be used. The communication unit 102 communicates with the manufacturer's system and the user's system via the host 200.
[0031] The control unit 103 is composed of a CPU (Central Processing Unit), RAM (Random Access Memory), ROM (Read Only Memory), etc. The CPU executes various processes and issues commands according to programs stored in the ROM to control the entire semiconductor device 100 and each unit, and also manages the transmission and reception of data between each processing unit, compares MAC values, discards CA keys, and generates device certificates as a device certificate generating unit.
[0032] The first key processing unit 104 unwraps the encrypted CA key using PSK. Unwrapping is a process that includes decrypting the CA key and generating a MAC value for the CA key.
[0033] The true random number generation unit 105 generates true random numbers that are the basis of a public key pair.
[0034] The second key and signature processing unit 106 generates a public key pair based on a true random number using public key cryptography. The public key pair is a pair of keys consisting of a public key and a private key, and the public key is a unique key whose value is different for each semiconductor device 100 and is called a device key. The second key and signature processing unit 106 also signs the hash value of the certificate data with a CA key to generate a signature.
[0035] The certificate data generating unit 107 generates certificate data from the device key of the public key pair.
[0036] The hash value calculation unit 108 calculates a hash value of the certificate data.
[0037] The semiconductor device 100 is configured as described above. The semiconductor device 100 may be a semiconductor chip used in various devices using semiconductors, such as various sensors such as a camera, an image sensor, a light detection and ranging (LiDAR), an infrared sensor, a millimeter-wave radar, and an inertial measurement unit (IMU), an IoT (Internet of Things) device, a smartphone, a tablet terminal, a personal computer, a game console, and a wearable device. The semiconductor device 100 may be any device that requires a device certificate. When the certificate generation method in the semiconductor device 100 according to the present technology is realized by executing a program, the program may be installed in the semiconductor device 100 in advance by a manufacturer, or may be distributed by download or via a storage medium and installed by a user.
[0038] [Processing in Semiconductor Device 100] Next, processing in the semiconductor device 100 will be described with reference to FIGS.
[0039] First, the control unit 103 acquires the CA key encrypted by Wrap and the MAC value of the CA key, both of which are input by the user. Then, the control unit 103 supplies the encrypted CA key to the first key processing unit 104.
[0040] Next, the first key processing unit 104 reads the PSK from the storage unit 101 and unwraps the encrypted CA key using the PSK. As shown in FIG. 4 , the unwrapping is a process that includes decrypting the encrypted CA key and calculating the MAC value of the CA key. The first key processing unit 104 then supplies the decrypted plaintext CA key and the MAC value of the CA key to the control unit 103. This unwrapping, which causes the CA key to be in plaintext, occurs only within the semiconductor device 100, and the semiconductor device 100 must perform the process in a secure state where it cannot be accessed illegally from the outside.
[0041] By encrypting the CA key, it is possible to prevent the CA key from being leaked or stolen during the process in which the user inputs the CA key into the semiconductor device 100 or during the communication path, and from being misused by a third party.
[0042] Next, the control unit 103 compares the MAC value of the CA key input by the user with the MAC value calculated by the first key processing unit 104. If the comparison results in a mismatch, the process has failed and the user is notified of this. If the MAC value of the CA key input by the user and the MAC value calculated by the first key processing unit 104 do not match, the CA key is deemed to have been tampered with and further processing is not performed. In this way, using the MAC value makes it possible to detect tampering of the CA key. Tampering can be, for example, bit inversion.
[0043] If the MAC value of the CA key input by the user matches the MAC value calculated by the common key processing unit, the control unit 103 notifies the true random number generation unit 105 that the MAC values match. If the MAC values match, the CA key has not been tampered with, so the subsequent processing continues.
[0044] Next, the true random number generation unit 105 generates a true random number and supplies the true random number to the control unit 103. Then, the control unit 103 supplies the true random number to the second key and signature processing unit .
[0045] Next, the second key and signature processing unit 106 generates a public key pair, which is a combination of a device key (public key) and a private key, based on the true random number, and supplies the public key pair to the control unit 103. The control unit 103 then supplies the public key pair to the certificate data generation unit 107. The public key method may be RSA cryptography or elliptic curve cryptography.
[0046] Next, the certificate data generation unit 107 uses the device key of the public key pair to generate binary data in a format conforming to a predetermined standard as certificate data. The certificate data generation unit 107 supplies the certificate data to the control unit 103. The control unit 103 then supplies the certificate data to the hash value calculation unit 108.
[0047] Next, the hash value calculation unit 108 calculates a hash value of the certificate data and supplies the hash value to the control unit 103. The control unit 103 then supplies the hash value and the plaintext CA key to the second key and signature processing unit 106.
[0048] Next, the second key and signature processing unit 106 signs the hash value of the certificate data with the CA key to generate a signature, and then supplies the signature to the control unit 103.
[0049] Next, the control unit 103 constructs a device certificate by associating the hash value of the certificate data with the signature. As shown in Fig. 5, the device certificate is composed of a device key (public key) of the public key pair, certificate data including the device key, and a signature in which the hash value of the certificate data is signed with a CA key. The device certificate in Fig. 5 is merely an example, and the present technology is not limited to this.
[0050] Next, the control unit 103 discards the plaintext CA key, thereby preventing the CA key from being misused by a malicious third party.
[0051] Next, the control unit 103 writes and stores the device certificate and the private key of the public key pair in the storage unit 101 .
[0052] The control unit 103 then notifies the user that the device certificate has been successfully generated and stored.
[0053] Processing in the semiconductor device 100 is carried out in the manner described above.
[0054] According to the present technology, in addition to generating a device key, the semiconductor device 100 itself also generates a device certificate. This eliminates the need to transmit a device key generated within the semiconductor device 100 to an external device in order to generate a device certificate, and to transmit a device certificate from an external device to the semiconductor device 100, as in the past, thereby improving the manufacturing efficiency of the semiconductor device 100. Furthermore, since the time required for communication with the external device is reduced, the manufacturing efficiency of the semiconductor device 100 can be improved and manufacturing costs can be reduced. Furthermore, the risk of the device key and device certificate being leaked to the external device during communication can be reduced.
[0055] Furthermore, in this technology, the CA key is supplied to the semiconductor device 100 in an encrypted form from outside during the manufacturing process, and is discarded after the certificate data is generated and is not stored within the semiconductor device 100. Therefore, there is no risk of the CA key being leaked from the semiconductor device 100.
[0056] Conventionally, a different device certificate is generated for each semiconductor device 100 using a CA key that is a different value for each user and a device key that is a different value for each semiconductor device 100, and the device certificate is stored in the semiconductor device 100. Therefore, in the manufacturing process, processing must be performed individually for each semiconductor device 100, which poses a problem of time and effort required to generate multiple semiconductor devices 100 simultaneously in parallel at the manufacturing site. However, the PSK used in the present technology is a key common to each user, and the device key is generated within the semiconductor device 100, so it is possible to generate and store device certificates in multiple semiconductor devices 100 simultaneously in parallel.
[0057] Since the manufacturer only needs to manufacture the semiconductor device 100 and store the common key PSK in the semiconductor device 100, it is easy to manufacture multiple semiconductor devices 100 in parallel, thereby improving the manufacturing efficiency of the semiconductor device 100.
[0058] Furthermore, the PSK is a common key that is not different for each user, and the CA key is different for each user, but does not need to be a different key for each of the multiple semiconductor devices 100 that the user owns, so there is no need to separate the model numbers of the semiconductor devices 100 for each user, which also makes inventory management of the semiconductor devices 100 easier.
[0059] Furthermore, since there is no need to generate a device certificate on an external server or the like, the generation of the device certificate does not become a bottleneck in the external server, and the manufacturing efficiency of the semiconductor device 100 can be improved.
[0060] Furthermore, since the CA key is unwrapped, a device certificate is generated using the CA key, and the CA key is discarded without being accessed illegally from outside, leakage and unauthorized use of the CA key can be prevented.
[0061] Furthermore, since the device certificate is generated within the semiconductor device 100 and stored in the memory unit 101, there is no need for the tester (the manufacturer's manufacturing department or the user) to write an individual device certificate for each semiconductor device 100, which simplifies the tester program.
[0062] Since the user transmits the CA key, which is a value that differs for each user, to the semiconductor device 100, the manufacturer does not need to store the CA key in the semiconductor device 100, thereby reducing the manufacturing costs at the manufacturer.
[0063] The CA key, which is a value that differs for each user, is simply supplied from the manufacturer to the user without going through the manufacturer's manufacturing process, thereby reducing the manufacturer's operating costs and manufacturing costs.
[0064] The CA key generated by the manufacturer is protected by encryption technology and tamper-proof technology so that it can only be used within the semiconductor device 100. Since the process for protecting the CA key can be performed separately from the manufacture of the semiconductor device 100, the manufacturing cost of the semiconductor device 100 can be reduced.
[0065] <Modifications> Although the embodiments of the present technology have been specifically described above, the present technology is not limited to the above-described embodiments, and various modifications based on the technical ideas of the present technology are possible.
[0066] The manufacturer may store a PSK for each user in the semiconductor device 100. Alternatively, the manufacturer may store the PSK in the semiconductor device 100 while keeping it common to all users, and instead of using the PSK to wrap and unwrap the CA key, a separate key for each user derived from the PSK may be used. In this case, a "(non-confidential) customer ID" is transmitted via I2C along with the CA key, and a key for each customer is derived from the PSK and customer ID inside the semiconductor device 100. This makes it possible to increase security by avoiding the sharing of the PSK between different users, especially when the CA key is generated and wrapped on the user side.
[0067] The user transmits the CA key and its MAC value via I2C, but metadata to be copied to the certificate data (such as the creation date and time of the certificate data) may also be transmitted via I2C. In this case, like the CA key, the metadata can also be protected by the MAC value and transmitted to the semiconductor device 100.
[0068] In the embodiment, the CA key is wrapped by the manufacturer, but the user may generate the CA key and wrap it. Note that the PSK is handled by the manufacturer, not the user, and must be stored in the semiconductor device 100 before the semiconductor device 100 is provided to the user.
[0069] 1, in the embodiment, the manufacturer is divided into a security department and a manufacturing department, but since both are manufacturers from the user's perspective, the security department and the manufacturing department do not necessarily need to be separate and may be integrated. Also, another department of the manufacturer may be responsible for the processing and work required to implement this technology.
[0070] In the embodiment, the first key processing unit 104, the true random number generation unit 105, the second key / signature processing unit 106, the certificate data generation unit 107, and the hash value calculation unit 108 exchange data via the control unit 103, but each unit may exchange data directly without going through the control unit 103.
[0071] In the embodiment, the second key and signature processing unit generates a public key pair and then issues a signature, but the processing unit that generates the public key pair and the processing unit that issues the signature may be separated.
[0072] In the embodiment, the control unit 103 has been described as functioning as a device certificate generating unit, but the device certificate generating unit may be a processing unit separate and independent from the control unit 103 .
[0073] In the embodiment, the encrypted CA key is decrypted using a PSK (pre-shared key), but the CA key may also be decrypted using a public key.
[0074] The present technology may also be configured as follows. (1) A semiconductor device including: a first key processing unit that decrypts a CA key supplied from an external device; a second key processing unit that generates a device key; a certificate data generation unit that generates certificate data using the device key; and a signature processing unit that generates a signature by signing with the CA key. (2) The semiconductor device according to (1), including a device certificate generation unit that generates a device certificate consisting of the certificate data and the signature. (3) The semiconductor device according to (1) or (2), in which the CA key is supplied from the external device in a pre-encrypted state. (4) The semiconductor device according to (3), in which the CA key is encrypted in advance using a pre-shared key. (5) The semiconductor device according to any one of (1) to (4), in which a MAC value of the CA key is calculated, and if the calculated MAC value matches a MAC value of the CA key calculated in advance and input from the external device, the second key processing unit generates the device key. (6) The semiconductor device according to any one of (1) to (5), including a hash value calculation unit that calculates a hash value of the certificate data. (7) The semiconductor device according to any one of (1) to (6), which discards the CA key after generating the device certificate. (8) The semiconductor device according to any one of (1) to (7), in which the CA key is supplied from the outside in a state in which it has been encrypted in advance. (9) The semiconductor device according to any one of (1) to (8), in which the outside is a user who receives the semiconductor device from a semiconductor device manufacturer. (10) The semiconductor device according to (9), in which the CA key is provided to the user by the manufacturer. (11) The semiconductor device according to (2), which includes a storage unit, and which stores and holds the device certificate in the storage unit. (12) A certificate generation method for a semiconductor device, comprising: acquiring a CA key supplied from the outside; decrypting the CA key; generating a device key; generating certificate data using the device key; signing with the CA key to generate a signature; and generating a device certificate consisting of the certificate data and the signature.(13) A program causing a computer to execute a certificate generation method for a semiconductor device, the method comprising: acquiring a CA key supplied from outside; decrypting the CA key; generating a device key; generating certificate data using the device key; signing with the CA key to generate a signature; and generating a device certificate consisting of the certificate data and the signature.
[0075] REFERENCE SIGNS LIST 100: Semiconductor device 103: Control unit 104: First key processing unit 106: Second key / signature processing unit 107: Certificate data generation unit 108: Hash value calculation unit
Claims
1. A semiconductor device comprising: a first key processing unit that decrypts a CA key supplied from an external source; a second key processing unit that generates a device key; a certificate data generation unit that generates certificate data using the device key; and a signature processing unit that signs with the CA key to generate a signature.
2. The semiconductor device according to claim 1, further comprising a device certificate generating unit that generates a device certificate composed of said certificate data and said signature.
3. The semiconductor device according to claim 1, wherein the CA key is supplied from the outside in a pre-encrypted state.
4. The semiconductor device according to claim 3, wherein the CA key is encrypted in advance using a pre-shared key.
5. The semiconductor device according to claim 1, wherein the second key processing unit calculates a MAC value of the CA key, and if the calculated MAC value matches a MAC value of the CA key that has been calculated in advance and input from outside, generates the device key.
6. The semiconductor device according to claim 1, further comprising a hash value calculation unit for calculating a hash value of the certificate data.
7. The semiconductor device according to claim 1, wherein the CA key is discarded after the device certificate is generated.
8. The semiconductor device according to claim 1, wherein the CA key is supplied from the outside in a state in which the CA key has been encrypted in advance.
9. The semiconductor device according to claim 1, wherein the external party is a user who receives the semiconductor device from a semiconductor device manufacturer.
10. The semiconductor device according to claim 9, wherein the CA key is provided to the user by the manufacturer.
11. The semiconductor device according to claim 2, further comprising a storage unit, wherein the device certificate is stored and held in the storage unit.
12. A certificate generation method for a semiconductor device, comprising: acquiring a CA key supplied from outside; decrypting the CA key; generating a device key; generating certificate data using the device key; signing with the CA key to generate a signature; and generating a device certificate consisting of the certificate data and the signature.
13. A program causing a computer to execute a certificate generation method for a semiconductor device, the method comprising: acquiring a CA key supplied from outside; decrypting the CA key; generating a device key; generating certificate data using the device key; signing with the CA key to generate a signature; and generating a device certificate consisting of the certificate data and the signature.
Citation Information
Patent Citations
Editor program and method for electronic certificate and IC card
JP2006108767A
Certificate issuing system, secure element, certificate issuing method, and program
JP2023160601A
Apparatus and Methods for Distributed Certificate Enrollment
US20190238342A1