Cloud-Based Customer-Specific Key Databases for Offline Semiconductor Upgrades
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current semiconductor devices face challenges in secure field upgrades due to reliance on cloud-based key distribution, which requires a public network connection, introduces security risks, and is not feasible in high-value manufacturing environments, and bulk access to symmetric keys is not possible without electrical identification during manufacturing.
Innovation Solution
A system for secure field upgrades using symmetric key cryptography that allows activation of capabilities in semiconductor devices without a public network connection, enabling multiple key activations simultaneously, and preserving end-to-end security through a key management system (KMS) that generates and manages activation codes offline.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If cloud-based key distribution techniques are used to secure field upgrades, then key management is simplified, but security risks increase due to requirement of public network connection
Solution Approach 1:
A secure element acts as an intermediary between the cloud-based KMS and the semiconductor device. The secure element receives encrypted symmetric keys from the KMS via cloud network, stores them securely in isolated memory, and provides them to the device through secure internal communication channels. This mediator architecture allows cloud-based key distribution while maintaining security by preventing direct exposure of keys to untrusted networks.
2Ease of operation
If unique identifier (UID) values are read and uploaded individually to enable end-user to request symmetric keys, then key distribution is enabled, but bulk access to symmetric keys is not feasible due to temporal latency and costs
Solution Approach 1:
UID values are read from semiconductor devices during the manufacturing process and stored in advance in a manufacturing database associated with the secure element. When bulk key activation is needed, the secure element retrieves pre-stored UID values and requests corresponding symmetric keys from the KMS in batch operations. This preliminary preparation of UID data eliminates the need for individual device connections during field operations, enabling efficient bulk key access.
3Device complexity
If symmetric encryption is used to secure field upgrades, then encryption simplicity is maintained, but key distribution suffers from security risks and operational limitations
Solution Approach 1:
A secure element serves as a dedicated intermediary component that handles all symmetric key distribution operations. It establishes secure communication channels with the KMS, stores symmetric keys in protected memory with access controls, and manages key delivery to semiconductor devices through authenticated protocols. This specialized intermediary maintains the simplicity of symmetric encryption while solving key distribution security and operational limitations through dedicated hardware security features.
Data Source
AI summary
The disclosed embodiments are related to securely updating a semiconductor device and in particular to a key management system. In one embodiment, a method is disclosed comprising receiving a request for an activation code database from a remote computing device, the request including at least one parameter; retrieving at least one pair based on the at least one parameter, the pair including a unique ID (UID) and secret key; generating an activation code for the UID; and returning the activation code to the remote computing device.


