Double Encrypted Vendor Key for Logic Core Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The IEEE 1735 V2 standard for protecting logic cores from unauthorized access has vulnerabilities that can lead to theft or corruption of designs, such as through Trojan horse injection, which are not adequately addressed by existing methods.
Innovation Solution
A method involving double encryption of the vendor private key, using user and vendor public-private key pairs, and pass phrases to create a protected package that includes a session key, allowing secure decryption and implementation of electronic designs, while also enabling tracing of unauthorized package distribution.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the IEEE 1735 V2 standard encryption method is used to protect logic cores, then the security protection is provided, but vulnerabilities exist that can lead to theft or corruption of designs through Trojan horse injection
Solution Approach 1:
The patent segments the encryption process into multiple independent stages: first encrypting the design data with a symmetric key, then encrypting that symmetric key with the vendor's public key, and finally encrypting the vendor's private key with the user's public key. This multi-layer segmentation ensures that compromise of one layer does not expose the underlying data, directly addressing the vulnerability to Trojan horse injection by preventing single-point failures in the encryption scheme.
Solution Approach 2:
The patent implements preliminary action by pre-encrypting the vendor's private key with the user's public key before delivering it to the user. This creates a secure envelope that can only be opened by the intended user, preventing unauthorized access or injection of malicious code during key exchange. The double encryption structure is established in advance, eliminating security gaps that could be exploited by Trojan horses.
2Reliability
If double encryption of vendor private key is implemented, then security is enhanced, but device complexity increases
Solution Approach 1:
The patent introduces symmetric keys as intermediaries between the asymmetric key pairs. The symmetric key serves as a mediator that simplifies the encryption of large design data, while the asymmetric keys (vendor and user key pairs) act as intermediaries for secure key exchange. This intermediary approach maintains high security through multiple encryption layers while managing complexity by using well-established cryptographic primitives in a structured sequence.
Solution Approach 2:
The patent applies the nested doll principle by creating nested encryption layers: the design data is encrypted with a symmetric key, which is then encrypted with the vendor's public key, and the vendor's private key is encrypted with the user's public key. Each encryption layer is nested within the previous one, forming a secure envelope structure. This nesting organizes the complexity hierarchically, making the multi-step process more manageable while enhancing security at each layer.
3Reliability
If multiple key pairs and pass phrases are used for encryption, then unauthorized access is reduced, but ease of operation decreases
Solution Approach 1:
The patent implements self-service by enabling the user to autonomously decrypt the vendor's private key using their own private key and the embedded vendor pass phrase. The system is designed so that the user's private key automatically decrypts the vendor's encrypted private key, and the embedded pass phrase automatically decrypts the session key. This self-service mechanism reduces operational complexity by eliminating manual intervention while maintaining strong security through multiple authentication factors.
Solution Approach 2:
The patent incorporates feedback by embedding the vendor pass phrase within the encrypted package, which provides automatic verification and decryption capability. When the user attempts decryption, the system uses the embedded pass phrase to verify authenticity and automatically decrypt the session key and design data. This feedback mechanism streamlines the decryption process by providing automatic error detection and correction, reducing the operational burden on users while maintaining security.
Data Source
AI summary
Removing protections on a session-key protected design include receiving a double encrypted vendor private key and an encrypted session key. The double encrypted vendor private key is decrypted into a single encrypted vendor-private key using a user private key, and the single encrypted vendor-private key is decrypted into a vendor private key using a vendor pass phrase. The encrypted session key is decrypted into a session key using the vendor private key, and the session-key protected design is decrypted into a plain design using the session key.


