Electronic Component Cloning Prevention via PKI Secure Hardware

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Manufacturers face challenges in preventing the cloning of electronic components, as existing methods fail to ensure authenticity and prevent unauthorized use or extended lifespan of OEM products.

Innovation Solution

Integration of a secure hardware device with electronic components using public key infrastructure (PKI) techniques, including a Trusted Platform Module (TPM), to verify the authenticity of components and limit their usage through digital signatures and key management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional authentication methods are used, then device complexity is low, but reliability of preventing cloning is insufficient

Engineering Contradiction:
Improveauthenticity verificationVSAvoidhardware structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a secure platform as an intermediary component between the processor and external environment. This secure platform contains a cryptographic module that generates and manages key pairs, acting as a mediator that provides cryptographic functions without requiring the main processor to handle complex security operations directly, thus improving reliability while controlling complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system is segmented into distinct functional components: a main processor for general operations and a separate secure platform for cryptographic operations. This segmentation allows the authentication functionality to be isolated in a dedicated secure module, improving the reliability of authentication while keeping the overall system architecture manageable through clear separation of concerns.

Inventive Principle:
Principle #1Segmentation

2Object-affected harmful factors

If simple authentication methods are used, then ease of operation is high, but ability to prevent unauthorized use is insufficient

Engineering Contradiction:
Improvecloning preventionVSAvoidusage verification
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The secure platform performs self-service by automatically generating key pairs and managing cryptographic operations without requiring external intervention or complex user procedures. The authentication process is automated through digital signatures and verification, eliminating the need for manual authentication steps while providing strong cloning prevention through cryptographic security.

Inventive Principle:
Principle #25Self-service

3Reliability

If digital signature verification is implemented, then reliability of authenticity verification is improved, but device complexity increases

Engineering Contradiction:
Improveauthentication accuracyVSAvoidcryptographic module
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The cryptographic module is merged with the secure platform, combining key generation, digital signature creation, and verification capabilities into a single integrated security subsystem. This merging approach improves authentication accuracy by ensuring all cryptographic operations occur within a trusted boundary, while the integrated design manages complexity through unified resource management and shared security protocols.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11716317B2Method to prevent cloning of electronic components using public key infrastructure secure hardware device
Publication Date: 2023.08.01 STMICROELECTRONICS INT NV
  • US11716317B2 patent drawing
  • US11716317B2 patent drawing

AI summary

An electronic component includes a processor and a memory. The electronic component has a secure platform capable of storing at least one dual key pair and a corresponding digital signature. There is also a system including a host machine and an electronic component capable of being operated by the host machine. The electronic component has a processor, a memory, and a secure platform capable of storing at least one dual key pair and a corresponding digital signature. Another aspect describes a method, which includes reading a public key from an electronic component by a host machine, verifying the public key against a stored key in the host machine, digitally signing data using a private key from the electronic component, verifying the signed data against the stored key, and using the electronic component by the host machine only if the signed data and the public key are verified.