Integrated Device Signing Model for HSM-Free Key Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing device manufacturing processes rely on separate hardware security modules (HSMs) for signing and provisioning certificates, which incur ongoing costs and risks of key corruption, loss, or leakage, leading to reduced production capacity and revoked certificates.

Innovation Solution

Implement a device signing model where model-specific keys are stored in a trusted execution environment or secure element, using fuses to encode model information, allowing the device to function as its own HSM for generating and transmitting signed device-unique public keys for authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate hardware security modules (HSMs) are used for signing and provisioning certificates, then device authentication security is improved, but manufacturing complexity and ongoing costs increase

Engineering Contradiction:
Improvedevice authentication securityVSAvoidmanufacturing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the HSM functionality from a separate external hardware module and integrates it directly into the device's processor system. The processor now includes built-in secure key generation, signing, and authentication capabilities, eliminating the need for separate HSM hardware while maintaining security functions.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent combines the HSM functions (key generation, signing, authentication) with the device's processor and memory systems. The secure element is integrated within the device architecture, merging previously separate security hardware with the main device components to reduce manufacturing complexity.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If separate hardware security modules (HSMs) are used for signing and provisioning certificates, then device authentication security is improved, but ongoing costs and key corruption risks increase

Engineering Contradiction:
Improvedevice authentication securityVSAvoidongoing costs
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The device performs its own authentication and signing operations using integrated secure elements within the processor. The device self-provisions certificates and manages its own cryptographic keys without requiring external HSM services, eliminating ongoing service costs and reducing key management risks.

Inventive Principle:
Principle #25Self-service

3Reliability

If custom software and hardware are used for provisioning devices with certificates, then security measures are improved, but manufacturing complexity increases

Engineering Contradiction:
Improvesecurity measuresVSAvoidmanufacturing ease
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The device's processor and secure elements are pre-configured with cryptographic capabilities during device fabrication. Model-specific keys are generated and stored in secure memory during manufacturing, and fuses are blown to encode model information, enabling the device to perform self-provisioning without requiring complex custom provisioning hardware or software.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If model-specific keys are stored in external HSMs, then key security is improved, but device autonomy and authentication efficiency are reduced

Engineering Contradiction:
Improvekey securityVSAvoidauthentication efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the key storage and processing functions by creating model-specific keys that are unique to each device model and storing them in dedicated secure memory regions within the processor. Each device has its own isolated secure element, enabling autonomous operation while maintaining key security through architectural isolation rather than external HSM dependency.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12463831B2Device signing model
Publication Date: 2025.11.04 QUALCOMM INC
  • US12463831B2 patent drawing
  • US12463831B2 patent drawing
  • US12463831B2 patent drawing

AI summary

Systems and techniques are provided for secure processing. For instance, a process can include generating a model signing key, wherein the device is associated with a device model, and wherein the model signing key is shared by apparatuses of the device model; obtaining a certificate for a device-unique public key of the apparatus; signing the device-unique public key based on the model signing key; and transmitting the signed device-unique public key for authentication.