Integrated Circuit Authentication via Cryptographic Signatures
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Application providers face challenges in verifying the authenticity and technical capabilities of integrated circuits, particularly in ensuring they can trust the hardware before installing sensitive applications, due to the lack of direct knowledge about the manufacturer and potential security risks associated with unverified hardware.
Innovation Solution
An integrated circuit with a communication module that provides information about its technical capabilities, combined with a cryptographic challenge, and a signer that produces a signature using a cryptographic signing key, allowing application providers to verify the authenticity and technical capabilities of the circuit through a single protocol, thereby establishing trust.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If application providers install applications on integrated circuits without verifying manufacturer authenticity, then application installation speed and service deployment are improved, but security risk and trustworthiness deteriorate
Solution Approach 1:
The integrated circuit performs preliminary authentication by providing signed capability information before the application provider installs the application. The signing key is pre-installed in the circuit during manufacturing, enabling it to autonomously generate cryptographic proofs of its identity and capabilities in advance, eliminating the need for time-consuming verification processes during application installation.
Solution Approach 2:
A cryptographic signature mechanism acts as an intermediary between the integrated circuit and the application provider. The signature, generated using a pre-installed signing key, serves as a trusted intermediary that proves the circuit's authenticity and capabilities without requiring direct verification of the manufacturer's identity or detailed technical inspections.
2Adaptability or versatility
If integrated circuits provide detailed technical capability information, then application compatibility is improved, but information security and attack surface deteriorate
Solution Approach 1:
The patent transforms detailed technical capability parameters into a cryptographic signature. Instead of exposing raw technical parameters that could be exploited, the circuit changes the parameter representation to a signed hash or digest that proves capabilities without revealing implementation details, thereby maintaining compatibility verification while reducing the attack surface.
Solution Approach 2:
The integrated circuit provides a cryptographic copy or representation of its capabilities rather than the actual detailed technical information. The signature serves as a verified copy that proves the circuit's capabilities without exposing the underlying implementation details, configuration specifics, or vulnerable components that could be targeted by attackers.
3Adaptability or versatility
If multiple application smart cards are used without direct manufacturer relationship, then service versatility is improved, but verification complexity and trust establishment deteriorate
Solution Approach 1:
The integrated circuit implements a universal authentication mechanism using a standard cryptographic signature scheme that can be used across multiple applications and service providers. The same signing key and signature verification process works for any application, eliminating the need for application-specific verification procedures and enabling seamless multi-application support without increasing verification complexity.
Data Source
Figure 1
Figure 2a~2b
Figure 3
AI summary
An integrated circuit 100 is provided, which is configured for authentication itself and technical information concerning the integrated circuit or its installed software to an external computing device 200. The integrated circuit 100 comprises a signer 130 for producing a signature over the information and a challenge using a cryptographic signing key, and a communication module 110 for providing the information and the signature to the computing device 200. In response to receiving the information and the authentication, the computing device 200 may install new application code on the integrated circuit. After the installation, the integrated circuit may authenticate information concerning the new application code to other computing devices. The integrated circuit is advantageously a multiple application smart card, since it allows application providers to obtain trust in the multiple application smart card without having a relationship with its manufacturer.