Cloud-Based Customer-Specific Key Databases for Offline Semiconductor Upgrades

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current semiconductor devices face challenges in secure field upgrades due to reliance on cloud-based key distribution, which requires a public network connection, introduces security risks, and is not feasible in high-value manufacturing environments, and bulk access to symmetric keys is not possible without electrical identification during manufacturing.

Innovation Solution

A system for secure field upgrades using symmetric key cryptography that allows activation of capabilities in semiconductor devices without a public network connection, enabling multiple key activations simultaneously, and preserving end-to-end security through a key management system (KMS) that generates and manages activation codes offline.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If cloud-based key distribution techniques are used to secure field upgrades, then key management is simplified, but security risks increase due to requirement of public network connection

Engineering Contradiction:
Improvekey distributionVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

A secure element acts as an intermediary between the cloud-based KMS and the semiconductor device. The secure element receives encrypted symmetric keys from the KMS via cloud network, stores them securely in isolated memory, and provides them to the device through secure internal communication channels. This mediator architecture allows cloud-based key distribution while maintaining security by preventing direct exposure of keys to untrusted networks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If unique identifier (UID) values are read and uploaded individually to enable end-user to request symmetric keys, then key distribution is enabled, but bulk access to symmetric keys is not feasible due to temporal latency and costs

Engineering Contradiction:
Improvekey request capabilityVSAvoidbulk key access efficiency
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

UID values are read from semiconductor devices during the manufacturing process and stored in advance in a manufacturing database associated with the secure element. When bulk key activation is needed, the secure element retrieves pre-stored UID values and requests corresponding symmetric keys from the KMS in batch operations. This preliminary preparation of UID data eliminates the need for individual device connections during field operations, enabling efficient bulk key access.

Inventive Principle:
Principle #10Preliminary action

3Device complexity

If symmetric encryption is used to secure field upgrades, then encryption simplicity is maintained, but key distribution suffers from security risks and operational limitations

Engineering Contradiction:
Improveencryption systemVSAvoidkey distribution security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

A secure element serves as a dedicated intermediary component that handles all symmetric key distribution operations. It establishes secure communication channels with the KMS, stores symmetric keys in protected memory with access controls, and manages key delivery to semiconductor devices through authenticated protocols. This specialized intermediary maintains the simplicity of symmetric encryption while solving key distribution security and operational limitations through dedicated hardware security features.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12381735B2Cloud-based creation of a customer-specific symmetric key activation database
Publication Date: 2025.08.05 MICRON TECHNOLOGY INC
  • US12381735B2 patent drawing
  • US12381735B2 patent drawing
  • US12381735B2 patent drawing

AI summary

The disclosed embodiments are related to securely updating a semiconductor device and in particular to a key management system. In one embodiment, a method is disclosed comprising receiving a request for an activation code database from a remote computing device, the request including at least one parameter; retrieving at least one pair based on the at least one parameter, the pair including a unique ID (UID) and secret key; generating an activation code for the UID; and returning the activation code to the remote computing device.