IC Provisioning with Hardware Verification and Fragmented Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing IC device provisioning processes rely on trust in manufacturers, which can be compromised by malicious entities, leading to vulnerabilities such as unauthorized access and leaks of fixed, hardware-based secrets, affecting multiple devices.
Innovation Solution
A secure provisioning process that divides sensitive data into fragments, encrypts each with unique cryptographic keys, and verifies IC device integrity through multiple secure transfer operations, using dynamically generated keys to establish secure links without relying on fixed secrets.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If fixed, hardware-based secrets are built into IC devices to reduce trust in manufacturers, then security against unauthorized access is improved, but the system becomes vulnerable to leaks and reverse engineering affecting multiple devices
Solution Approach 1:
The provisioning data is divided into multiple fragments, each encrypted with a different cryptographic key. Each IC device receives only its specific fragment through a secure transfer operation that includes hardware verification. This segmentation ensures that even if one device's secret is compromised, other devices remain secure as their fragments and keys are distinct.
Solution Approach 2:
The system transitions from static, fixed hardware-based secrets to dynamic, per-device cryptographic keys that are generated and distributed through a verified provisioning process. Each device receives unique encryption keys that are tied to its specific hardware identity, creating a dynamic security model that adapts to individual device verification rather than relying on universal fixed secrets.
2Device complexity
If trust-based provisioning processes are used where manufacturers are trusted not to intercept sensitive data, then the provisioning process is simpler, but the system becomes open to compromise by malicious entities
Solution Approach 1:
The secure transfer operation incorporates hardware verification that provides feedback on the integrity of the IC device before provisioning data is transferred. The system validates the device's hardware identity and verifies that the device is legitimate, creating a feedback mechanism that prevents malicious entities from intercepting or compromising provisioning data while maintaining automated verification rather than manual trust relationships.
Solution Approach 2:
Hardware verification is performed as a preliminary action before the actual provisioning data transfer occurs. The system validates the IC device's hardware integrity and identity in advance, ensuring that only verified legitimate devices receive provisioning data. This preliminary verification prevents malicious interference during the provisioning process without requiring complex ongoing trust management.
Data Source
AI summary
The present disclosure describes various aspects of secure provisioning with hardware verification. In some aspects, sensitive data are provisioned to an integrated circuit (IC) device through a provisioning process. Provisioning data for the IC device are divided into a plurality of fragments, and each fragment is encrypted in one of a plurality of cryptographic keys. Corresponding cryptographic keys are generated at the IC device. The encrypted fragments are transferred to the IC device in respective secure transfer operations, each including sending a seed value to the IC device, validating integrity data configured to characterize integrated circuitry within a portion of the IC device specified by the seed value, and transferring the encrypted fragment to the IC device in response to validating the integrity data. In response to completing the secure transfer operation, the IC device may reconstruct the provisioning data from the encrypted fragments and corresponding cryptographic keys.


