HSM-Based Cryptographic Key Management for Device Manufacturing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for distributing cryptographic secrets in device manufacturing are complex and cumbersome, necessitating an improved and efficient process for securely handling secrets common to a product family.

Innovation Solution

A computer-implemented method utilizing Hardware Security Modules (HSMs) to generate and distribute unique encryption keys, encrypting them at each manufacturing stage, and decrypting them using the first key stored on a server to authenticate software loaded on devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic secrets are distributed through traditional manufacturing processes, then device functionality is achieved, but security is compromised due to complex and cumbersome handling requirements

Engineering Contradiction:
ImprovesecurityVSAvoidprocess complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the cryptographic secret distribution process into distinct phases: key generation at secure HSM locations, encrypted parameter embedding in software, and controlled decryption at manufacturing stages. This segmentation allows each phase to be optimized independently, reducing overall process complexity while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces encrypted parameters as an intermediary between the cryptographic secrets and the manufacturing process. Instead of directly handling sensitive keys, the system uses encrypted parameters that can be safely transmitted and stored, reducing security handling complexity while maintaining reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cryptographic secrets are securely handled through multiple manufacturing stages, then security is maintained, but manufacturing efficiency decreases

Engineering Contradiction:
ImprovesecurityVSAvoidmanufacturing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary encryption of parameters and embedding into software during earlier manufacturing stages, so that cryptographic secrets are already protected before reaching later stages. This preliminary action reduces the security handling burden in subsequent stages, improving overall manufacturing efficiency without compromising security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The manufacturing system uses automated decryption and verification processes that operate autonomously at each stage, reducing manual intervention requirements. The encrypted parameters self-verify their integrity through cryptographic checks, improving efficiency while maintaining security.

Inventive Principle:
Principle #25Self-service

3Reliability

If cryptographic secrets are protected through encryption and decryption processes, then data security is improved, but processing time increases

Engineering Contradiction:
Improvedata securityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system applies different levels of cryptographic protection to different parameters based on their security requirements. Critical secrets receive stronger encryption, while less sensitive parameters use lighter protection, optimizing the balance between data security and processing time for each specific element.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20250330313A1Computer System and Method for Providing Secured Cryptographic Management for Design and Manufacturing Processes
Publication Date: 2025.10.23 SCHNEIDER ELECTRIC USA INC
  • US20250330313A1 patent drawing
  • US20250330313A1 patent drawing
  • US20250330313A1 patent drawing

AI summary

A computer-implemented method for authenticating software loaded in a device during a device manufacturing process having one or more manufacturing stages. A unique identifier first key is generated for encryption of software to be loaded on a manufactured device. The first key is loaded onto a security device for storage on a server. A unique identifier second key is generated that is to be included as a parameter with software to be loaded on the manufactured device whereby the second key is encrypted utilizing the first key. The encrypted second key is incorporated as a software parameter in the device whereafter the second key is decrypted utilizing the first key stored in the computer server to authenticate the software loaded on the device during its manufacturing process.