Crypto-Processing LSI Unique Key Generation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The manufacturing of terminals is hindered by the inefficiency and increased costs associated with setting unique device keys, as existing methods require on-site key setting during production and involve high administrative burdens for key management across multiple locations, leading to potential key exposure and misuse.
Innovation Solution
A key terminal apparatus with a crypto-processing LSI that embeds unique information, a manufacturer key storage unit for encrypted keys, and an interface connected to a device key encryption server, allowing for the generation and transmission of unique device keys, enabling secure and cost-effective key management by decrypting keys using a master key and unique manufacturer keys.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If device keys are set during terminal manufacturing, then key security is improved, but manufacturing efficiency deteriorates and costs increase
Solution Approach 1:
The patent applies preliminary action by embedding unique information (device unique value) and encrypted device keys in the terminal during manufacturing, while the actual key decryption and generation occurs later after manufacturing. This allows the terminal to be prepared in advance with necessary cryptographic materials without requiring time-consuming key setting operations during the manufacturing process itself, thus resolving the contradiction between key security and manufacturing efficiency
2Reliability
If device keys are set during terminal manufacturing, then key security is improved, but administrative burden increases
Solution Approach 1:
The patent introduces an intermediary approach by using a key generation unit that automatically generates device keys through cryptographic operations based on embedded unique information, rather than requiring manual key distribution and administration. The system uses encrypted device keys and unique device identifiers as intermediaries to automatically establish secure keys, eliminating the need for complex administrative key management across multiple locations
3Ease of manufacture
If the same device key is used in multiple terminals, then manufacturing cost is reduced, but key security deteriorates
Solution Approach 1:
The patent applies local quality by making each terminal's device key unique through the incorporation of device-unique information (device unique value) that is specific to each terminal. While the key generation process and encryption methods are standardized, the resulting device keys are locally adapted to each terminal's unique identifier, ensuring that each terminal has a distinct cryptographic identity without requiring complex manual key distribution
4Ease of operation
If device keys are exposed or tampered with, then key management simplicity is improved, but security deteriorates
Solution Approach 1:
The patent applies preliminary anti-action by preemptively protecting device keys through encryption and secure embedding in the terminal's LSI before any potential exposure or tampering can occur. The device keys are stored in encrypted form and can only be decrypted by authorized key generation units within the terminal, creating a preventive security mechanism that counteracts potential future threats without complicating key management operations
Data Source
AI summary
A key terminal apparatus includes a crypto-processing LSI that performs predetermined crypto-processing. Unique information identifying the crypto-processing LSI is embedded in the crypto-processing LSI. A predetermined master key corresponding to a predetermined key is embedded in the crypto-processing LSI. The crypto-processing LSI (a) receives an encrypted manufacturer key from the manufacturer key storage unit, (b) decrypts the encrypted manufacturer key using the predetermined master key to generate a manufacturer key, (c) generates a unique manufacturer key identical to the predetermined unique manufacturer key, based on the unique information embedded in the crypto-processing LSI and the generated manufacturer key, and (d) decrypts the received encrypted device key using the generated identical unique manufacturer key to generate a predetermined device key.


