In-Field Security Protocol Patching for Integrated Circuit Chips

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Secure integrated circuit chips face challenges in securely updating or removing legacy security protocols to transition to more secure newer protocols, necessitating an improved method for software provisioning to enhance security features.

Innovation Solution

A method for software provisioning that involves developing a patch to deactivate legacy security protocols, encrypting and signing it, and deploying it through a patch service integrated into document inspection systems, ensuring authenticity and secure installation on the chip using manufacturer-specific keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If legacy security protocols are removed from secure integrated circuit chips to enhance security, then security level is improved, but device functionality and compatibility are reduced

Engineering Contradiction:
Improvesecurity levelVSAvoidprotocol compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic protocol configuration where the secure element can transition between supporting legacy protocols and newer protocols based on operational context. The system dynamically selects which protocol implementation to use based on the transaction type, counterparty requirements, and security policy settings, allowing both legacy and modern protocols to coexist with appropriate activation/deactivation logic.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the state parameter of protocol implementations from static to controllable. By introducing activation flags and configuration parameters that can be modified through secure update mechanisms, the system can transition protocol implementations between active and inactive states, enabling security enhancements while preserving compatibility options.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If new security features are added to secure integrated circuit chips to counter security flaws, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidprotocol implementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security protocol implementation into separate, independently manageable components. Each protocol (legacy and newer) is implemented as a distinct module that can be individually updated, activated, or deactivated. This modular architecture allows new security features to be added without monolithically increasing overall system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary configuration of multiple protocol implementations during manufacturing or initial provisioning, preparing the system for future security updates. By pre-establishing the framework for multiple protocols and update mechanisms, the system reduces the complexity burden when new security features need to be deployed later.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If secure updates are deployed to deactivate legacy protocols in the field, then security is enhanced, but update deployment complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidupdate deployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service update capabilities where the secure element autonomously verifies, validates, and applies security updates without requiring complex external intervention. The system includes built-in mechanisms for update authentication, integrity verification, and safe application, reducing the operational complexity of field deployments.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces an intermediary update management layer that mediates between the update source and the secure element. This intermediary handles the complexity of update distribution, authentication, and installation procedures, shielding the core security protocols from deployment complexity while enabling secure field updates.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP4617933A1In-the-field patching of a security protocol implementation
Publication Date: 2025.09.17 THALES DIS FRANCE SA
  • EP4617933A1 patent drawingFigure 1~2
  • EP4617933A1 patent drawingFigure 3
  • EP4617933A1 patent drawingFigure 4

AI summary

Deactivation of a first security protocol implementation by developing a patch that disables the first security protocol implementation, bundling the patch into an issuance solution that is deployable at a patch service, presenting the integrated circuit to the patch service, and receiving into the integrated circuit chip from the patch service the software patch disabling the first security protocol implementation.