Authentication Key Management via Volatile Memory Extraction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication systems for electronic devices, such as image forming devices, are vulnerable to microprobing attacks that expose secret information stored in Large Scale Integrated Circuit (LSI) chips, leading to potential malfunction and counterfeiting.

Innovation Solution

An authentication system that employs a challenge-response mechanism using encrypted keys and random number generation to update and derive authentication keys, ensuring that the original key is temporarily held in volatile memory and not stored in non-volatile memory, making it difficult to expose and use for counterfeiting.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If secret information is stored in non-volatile memory of LSI chip, then authentication functionality is maintained, but the system becomes vulnerable to microprobing attacks that expose secret information

Engineering Contradiction:
Improveauthentication functionalityVSAvoidmicroprobing attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the original key from non-volatile memory and stores it only in volatile memory during authentication operations. The non-volatile memory contains only encrypted forms (encrypted original key and authentication key), while the plaintext original key exists temporarily only in volatile memory, removing the persistent storage vulnerability to microprobing attacks.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs preliminary encryption of the original key before storing it in non-volatile memory. The original key is encrypted to create an encrypted original key, and further encrypted to create an authentication key for storage. This preliminary cryptographic transformation ensures that even if non-volatile memory is probed, the attacker cannot obtain the plaintext original key.

Inventive Principle:
Principle #10Preliminary action

2Duration of action of stationary object

If original key is stored in non-volatile memory, then key persistence is achieved, but secret information can be exposed through microprobing attacks

Engineering Contradiction:
Improvekey persistenceVSAvoidsecret information exposure
Core Design Contradiction:
Duration of action of stationary objectVSLoss of information

Solution Approach 1:

The patent extracts the plaintext original key from persistent storage and limits its presence to volatile memory only during active authentication. The non-volatile memory stores only cryptographic transformations of the key, eliminating the risk that persistent storage will expose the secret information through microprobing.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system changes the state of the key in non-volatile memory from plaintext to encrypted form. By storing the authentication key (which is an encrypted transformation of the original key) instead of the original key itself, the patent maintains key persistence while changing the parameter of the stored data from secret to non-secret.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If secret key is stored in LSI chip, then authentication can be performed, but counterfeit products can be created using exposed secret information

Engineering Contradiction:
Improveauthentication operationVSAvoidcounterfeit product creation
Core Design Contradiction:
Ease of operationVSObject-generated harmful factors

Solution Approach 1:

The patent extracts the original key from permanent storage and uses it only temporarily in volatile memory for authentication operations. This extraction eliminates the source material that counterfeiters would need to replicate the authentication mechanism, preventing counterfeit product creation while maintaining ease of authentication operation.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs preliminary cryptographic processing to derive an authentication key from the original key through encryption. This authentication key is what gets stored in non-volatile memory, while the original key remains in volatile memory only during operations. This preliminary transformation creates a one-way protection against counterfeiting.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12149640B2Technique for protecting secret information of authentication-target apparatus
Publication Date: 2024.11.19 CANON KK
  • US12149640B2 patent drawing
  • US12149640B2 patent drawing
  • US12149640B2 patent drawing

AI summary

An authentication system for authenticating an authentication-target apparatus by transmitting challenge data from an authenticating apparatus to the authentication-target apparatus and transmitting response data from the authentication-target apparatus to the authenticating apparatus. The authentication-target apparatus updates ae secret key and an encrypted original key stored in a memory using a new secret key and a new encrypted original key, derives an authentication key based on an original key, and generates the response data based on a challenge data received from the authenticating apparatus and the authentication key. The authentication apparatus derives an authentication key based on identification information of the authentication-target apparatus and an authentication original key, generates response data for verification based on the challenge data and the authentication key, and obtains an authentication result.