Fuse Attestation for Secure IC Key Provisioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
During integrated circuit manufacturing, there is a need to securely provision secret keys while preventing their exposure in non-production components, such as prototypes or experimental versions, which may have security features disabled or pose a risk.
Innovation Solution
The implementation of fuse attestation, which involves verifying the production status of a component before programming a production key, using a combination of configuration fuses, a physically unclonable function (PUF) circuit, and a key management server to ensure secure key provisioning by generating and managing unique keys.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If secret keys are programmed into components during manufacturing, then cryptographic security is improved, but the risk of key exposure in non-production components increases
Solution Approach 1:
The system performs preliminary verification of component authenticity and production status before programming the secret key. A fuse attestation mechanism is used to verify that the component is a genuine production unit before key provisioning, preventing keys from being programmed into non-production components such as prototypes or experimental versions.
Solution Approach 2:
The patent introduces an intermediary verification system consisting of fuse attestation mechanisms and key management servers that mediate between the key provisioning process and the component. This intermediary layer verifies component authenticity and production status before allowing key programming, thereby preventing direct key exposure to non-production components.
2Reliability
If fuse attestation verification is implemented before key provisioning, then key security is improved, but the manufacturing process complexity increases
Solution Approach 1:
The verification process is segmented into distinct functional components: fuse attestation mechanisms embedded in the component, key management servers that perform verification, and dedicated verification steps in the manufacturing process. This segmentation allows each component to perform its specific verification function independently, making the overall complex security system more manageable and implementable.
Solution Approach 2:
The system uses fuse attestation mechanisms that create a verifiable copy or representation of the component's authenticity and production status. This copied verification information can be independently verified by key management servers without requiring direct inspection of the actual component hardware, simplifying the verification process while maintaining security.
Data Source
AI summary
Embodiments of an invention for fuse attestation to secure the provisioning of secret keys during integrated circuit manufacturing are disclosed. In one embodiment, an apparatus includes a storage location, a physically unclonable function (PUF) circuit, a PUF key generator, an encryption unit, and a plurality of fuses. The storage location is to store a configuration fuse value. The PUF circuit is to provide a PUF value. The PUF key generator is to generate a PUF key based on the PUF value. The encryption unit is to encrypt the configuration fuse value using the PUF key. The PUF key and the configuration fuse value are to be provided to a key server. The key server is to determine that the configuration fuse value indicates that the apparatus is a production component, and, in response, provide a fuse key to be stored in the plurality of fuses.


