Integrated Circuit Authentication via Unique ID and Device Key

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In contract manufacturing for integrated circuits, the risk of illicit clones is high due to overproduction by contract manufacturers, leading to unauthorized use of bandwidth and computation resources, which affects the stability and availability of online services, particularly for IoT devices.

Innovation Solution

A method involving provisioning integrated circuit devices with unique identification numbers (UIDs) and key derivation data (KDD), allowing the original device manufacturer to calculate and verify a secret device-specific key (DSK) for each device, ensuring only legitimate devices access online services by matching UIDs and DSKs, thereby preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If contract manufacturers are allowed to produce integrated circuits, then production capacity and productivity are improved, but the risk of illicit cloning and unauthorized production increases

Engineering Contradiction:
Improveproduction capacityVSAvoidauthenticity of devices
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by embedding unique identification numbers and cryptographic keys into devices during the manufacturing process, before the devices are distributed. This pre-configured authentication mechanism enables service providers to verify device legitimacy later, preventing illicit clones from accessing online services while maintaining high production capacity through contract manufacturers.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If more devices are allowed to access online services, then service coverage and adaptability are improved, but network bandwidth and computation resources are overwhelmed

Engineering Contradiction:
Improveservice coverageVSAvoidbandwidth and computation resources
Core Design Contradiction:
Adaptability or versatilityVSLoss of energy

Solution Approach 1:

The patent implements feedback by requiring authentication verification between devices and service providers through cryptographic protocols. This feedback mechanism allows service providers to identify and block illicit clones that would otherwise consume network bandwidth and computation resources, while still allowing legitimate devices to access services freely, thus maintaining service coverage without resource exhaustion.

Inventive Principle:
Principle #23Feedback

3Reliability

If authentication mechanisms are implemented to detect illicit devices, then device authenticity and service stability are improved, but system complexity and manufacturing complexity increase

Engineering Contradiction:
Improveservice stabilityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies copying by using cryptographic reproduction of authentication credentials that can be verified without requiring complex centralized verification infrastructure. Each device contains copied authentication elements (unique ID and key) that enable self-authentication, reducing the complexity of the overall authentication system while maintaining service stability and preventing illicit device access.

Inventive Principle:
Principle #26Copying

Data Source

PatentEP3410334B1Method for authenticating an intergrated circuit device
Publication Date: 2021.09.01 NXP BV
  • EP3410334B1 patent drawingFigure 1
  • EP3410334B1 patent drawingFigure 2
  • EP3410334B1 patent drawing

AI summary

A method is provided for authenticating an IC device. The method includes provisioning an integrated circuit (IC) device with a unique identification number (UID). The IC device is configured to calculate a device-specific key (DSK) using the UID. The UID is used with a secure application separate from the IC device to calculate the DSK. The DSK calculated by the IC device is the same as the DSK calculated by the secure application. The UID and the DSK calculated by the secure application is provided to a provider of an online service. The provider of the online service is enabled to authenticate the IC device using the UID and the DSK calculated with the secure application in response to the IC device contacting the online service. The provider may authenticate the device using a standard cryptographic challenge-response protocol. If the IC device has knowledge of a particular DSK, then the IC device is a legitimate authorized device.