Boot ROM Secure Chip Provisioning via Key Index
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing secure provisioning methods for semiconductor chips are vulnerable to security breaches at untrusted manufacturing factories, as malicious entities can acquire security keys, compromising both consumer and OEM assets.
Innovation Solution
A computer-implemented method that generates a key provision key (KPK) set, where only the OEM receives a specific KPK, and the manufacturing factory receives only the KPK index, ensuring the integrity of the provisioning process remains secure irrespective of the manufacturing factory's trustworthiness, by using a boot ROM that internally derives and manages the KPKs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the manufacturing factory is restricted to trusted factories only, then security risk is reduced, but productivity and cost-effectiveness deteriorate due to limited manufacturing capacity
Solution Approach 1:
The security key management is segmented into two parts: the factory receives only a key index (not the actual security key), while the trusted OEM holds the actual security key. This segmentation allows any factory to perform provisioning operations without compromising security, as the factory never possesses the actual security key that could be misused.
Solution Approach 2:
The key index acts as an intermediary that enables the manufacturing factory to access the provisioning image without directly holding the security key. The factory uses the key index to retrieve the appropriate security key from the OEM, allowing secure provisioning while maintaining factory independence and trustworthiness.
2Productivity
If multiple manufacturing factories are permitted to produce chips, then productivity increases, but security risk increases due to potential malicious actions at untrusted factories
Solution Approach 1:
The actual security key is extracted from the manufacturing factory environment and retained exclusively by the trusted OEM. The factory is provided only with a key index, which is insufficient for malicious activities. This extraction eliminates the security risk associated with having security keys at untrusted locations while allowing multiple factories to operate.
3Ease of operation
If security keys are provided to the manufacturing factory for provisioning, then ease of operation improves, but security deteriorates due to potential key acquisition by malicious employees
Solution Approach 1:
Instead of providing the security key to the factory for ease of operation, the approach is inverted: the factory receives only a key index, and the actual security key remains with the OEM. This inversion maintains provisioning capability while fundamentally improving security by ensuring the factory never possesses the actual security key.
Data Source
AI summary
One embodiment of the present invention includes a boot read only memory (ROM) with an embedded, private key provision key (KPK) set that enables secure provisioning of chips. As part of taping-out a chip, the chip provider establishes the KPK set and provides the boot ROM exclusive access to the KPK. For each Original Equipment Manufacturer (OEM), the chip provider assigns and discloses an OEM-specific KPK that is included in the KPK set at a particular KPK index. Upon receiving a secured provisioning image and the associated KPK index, the boot ROM accesses the KPK set to reconstruct the KPK and then decrypts and executes the secured provisioning image. Advantageously, this enables the manufacturing factory to provision the chip without the security risks attributable to conventional provisioning approaches that require disclosing security keys to the manufacturing factory.


