Asset Control Core Hardware Security for Feature Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional methods for feature programming in semiconductor manufacturing require a trusted environment, are costly to modify, and lack control over unauthorized feature activation, leading to revenue loss and brand dilution due to counterfeit or defective chips, as well as challenges in protecting proprietary data across untrusted manufacturing operations.

Innovation Solution

The Asset Management System (AMS) provides a comprehensive infrastructure for secure management of digital assets, enabling remote control and auditing of feature provisioning, key injection, and serialization across untrusted manufacturing locations through a network of controllers, appliances, and agents, using hardware security modules and an Asset Control Core for secure communications and data protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional feature programming methods are used, then manufacturing simplicity is maintained, but security and control over proprietary data are compromised

Engineering Contradiction:
Improvesecurity of proprietary dataVSAvoidcomplexity of feature programming system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the feature programming process into distinct phases: key generation at the secure element, key transport to the manufacturing facility, and feature programming execution. This segmentation allows the proprietary data and keys to be isolated from the untrusted manufacturing environment while maintaining operational simplicity through automated key injection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A secure element or hardware security module acts as an intermediary between the manufacturer's proprietary data and the untrusted manufacturing facility. This intermediary generates and manages cryptographic keys locally while allowing secure communication with the manufacturing system, thus protecting proprietary data without requiring full system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If manufacturing is outsourced to untrusted facilities, then productivity is improved, but loss of proprietary data and unauthorized feature activation increase

Engineering Contradiction:
Improvemanufacturing efficiencyVSAvoidproprietary data security
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

Cryptographic keys and security credentials are generated and prepared in advance at the manufacturer's secure facility before shipment to the untrusted manufacturing location. This preliminary action ensures that sensitive data never resides in the untrusted environment, allowing outsourced manufacturing to proceed efficiently while maintaining security through pre-established trust anchors.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The manufacturing facility performs feature programming operations autonomously using keys and instructions received from the manufacturer, without requiring continuous verification or control from the manufacturer's end. This self-service capability enables high productivity in outsourced facilities while the manufacturer retains control through cryptographic authentication and auditing mechanisms.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If feature programming is performed in distributed manufacturing locations, then manufacturing flexibility is improved, but control over feature activation and prevention of unauthorized enablement deteriorates

Engineering Contradiction:
Improvemanufacturing location flexibilityVSAvoidcontrol over feature activation
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system implements feedback mechanisms where the manufacturing facility reports completion status, programmed features, and consumption data back to the manufacturer. This feedback loop enables the manufacturer to verify that features were programmed correctly and to detect any unauthorized modifications, thus maintaining control over feature activation while allowing distributed manufacturing flexibility.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system uses parameter changes through cryptographic key management and feature flagging to control feature activation. By changing the state of security parameters (such as key validity periods, feature enablement flags, and authentication tokens), the manufacturer can dynamically control which features are active at each manufacturing location without compromising the flexibility of distributed production.

Inventive Principle:
Principle #35Parameter changes

4Ease of manufacture

If traditional feature programming methods are used, then implementation simplicity is maintained, but cost of counterfeit and defective chips increases

Engineering Contradiction:
Improvesimplicity of feature programmingVSAvoidrevenue loss from counterfeit chips
Core Design Contradiction:
Ease of manufactureVSLoss of energy

Solution Approach 1:

The system prepares and embeds cryptographic authentication mechanisms and secure feature programming routines into the manufacturing process before any chip production occurs. This beforehand cushioning creates a secure foundation that prevents counterfeit chips from entering the supply chain, protecting revenue while maintaining ease of manufacture through automated authentication protocols.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Data Source

PatentEP2350910B1System and method for hardware based security
Publication Date: 2018.07.25 CERTICOM CORP
  • EP2350910B1 patent drawingFigure 1
  • EP2350910B1 patent drawingFigure 2
  • EP2350910B1 patent drawingFigure 3

AI summary

An asset management system is provided, which includes a hardware module operating as an asset control core. The asset control core generally includes a small hardware core embedded in a target system on chip that establishes a hardware-based point of trust on the silicon die. The asset control core can be used as a root of trust on a consumer device by having features that make it difficult to tamper with. The asset control core is able to generate a unique identifier for one device and participate in the tracking and provisioning of the device through a secure communication channel with an appliance. The appliance generally includes a secure module that caches and distributes provisioning data to one of many agents that connect to the asset control core, e.g. on a manufacturing line or in an after-market programming session.