Cryptographic Key Generation Using Device Physical Characteristics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cryptographic devices are insufficiently protected against attacks that aim to recover cryptographic keys, particularly due to limitations in side-channel and fault attack mitigation techniques, especially in resource-constrained environments.

Innovation Solution

A cryptographic key determination device that generates cryptographic keys based on dynamic data from test programs executed by the device, combining static and dynamic data to enhance security by making key recovery more difficult for attackers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic devices use traditional key storage methods, then key access is simple and fast, but security against attacks is insufficient

Engineering Contradiction:
ImprovesecurityVSAvoidkey generation mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by generating cryptographic keys from device-specific physical characteristics (such as manufacturing variations in semiconductor structures) before any potential attack occurs. These physical characteristics are inherent to each device and cannot be replicated, so the keys are predetermined by the device's unique physical state rather than being stored or generated through complex algorithms during operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses device-specific physical characteristics as an intermediary between the hardware and the cryptographic key. Instead of directly storing keys or using complex key generation algorithms, the system measures physical properties (such as resistance, capacitance, or other electrical characteristics) that are unique to each device instance and uses these measurements to derive the key material, thereby adding a security layer without requiring complex additional hardware.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cryptographic devices implement side-channel attack mitigation techniques, then security against physical attacks is improved, but hardware resources are consumed

Engineering Contradiction:
ImprovesecurityVSAvoidhardware resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts the security function from complex computational processes and side-channel mitigation techniques, and instead derives it directly from inherent physical characteristics of the device. By measuring raw physical properties (such as electrical characteristics) that naturally vary between devices due to manufacturing processes, the system obtains security without requiring additional computational resources or complex mitigation infrastructure.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The device uses its own inherent physical characteristics to generate security credentials, eliminating the need for external security infrastructure or complex internal mitigation mechanisms. Each device serves its own security needs by measuring its own physical properties and deriving keys from these measurements, thereby consuming minimal additional hardware resources while maintaining strong security.

Inventive Principle:
Principle #25Self-service

3Reliability

If cryptographic devices store private data securely, then data protection is enhanced, but vulnerability to hardware attacks increases

Engineering Contradiction:
Improvedata protectionVSAvoidhardware attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by establishing data protection through device-specific physical characteristics before any attack scenario materializes. The keys are bound to the physical state of the device at the time of measurement, creating a security credential that cannot be extracted or replicated through hardware attacks. This preliminary establishment of security based on inherent physical properties prevents rather than reacts to potential attacks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces dynamics by using physical characteristics that can change or vary between device instances and over time. Rather than relying on static stored values that are vulnerable to extraction, the system measures dynamic physical properties that are difficult to replicate or predict, thereby creating security that adapts to the device's actual physical state and resists hardware attack attempts.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP3624392B1Methods and devices for secure secret key generation
Publication Date: 2023.05.10 SECURE IC
  • EP3624392B1 patent drawingFigure 1
  • EP3624392B1 patent drawingFigure 2

AI summary

There is provided a cryptographic key determination device (13) for determining one or more cryptographic keys in a cryptographic device (1), the cryptographic device (1) being configured to execute one or more test programs, the cryptographic device (1) comprising one or more components (11-i), each component (11-i) being configured to generate static and dynamic data, the dynamic data being generated in response to the execution of the one or more test programs, wherein the cryptographic key determination device (13) comprises: - a data extraction unit (131) configured to extract at least one part of the static data and at least one part of the dynamic data generated by the one or more components (11-i), and - a key generator (132) configured to combine the at least one part of static data and the at least one part of dynamic data, and to determine the one or more cryptographic keys by applying a cryptographic function to the combined data.