IC Provisioning with Hardware Verification and Fragmented Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing IC device provisioning processes rely on trust in manufacturers, which can be compromised by malicious entities, leading to vulnerabilities such as unauthorized access and leaks of fixed, hardware-based secrets, affecting multiple devices.

Innovation Solution

A secure provisioning process that divides sensitive data into fragments, encrypts each with unique cryptographic keys, and verifies IC device integrity through multiple secure transfer operations, using dynamically generated keys to establish secure links without relying on fixed secrets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If fixed, hardware-based secrets are built into IC devices to reduce trust in manufacturers, then security against unauthorized access is improved, but the system becomes vulnerable to leaks and reverse engineering affecting multiple devices

Engineering Contradiction:
Improvesecurity against unauthorized accessVSAvoidvulnerability to leaks and reverse engineering
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The provisioning data is divided into multiple fragments, each encrypted with a different cryptographic key. Each IC device receives only its specific fragment through a secure transfer operation that includes hardware verification. This segmentation ensures that even if one device's secret is compromised, other devices remain secure as their fragments and keys are distinct.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system transitions from static, fixed hardware-based secrets to dynamic, per-device cryptographic keys that are generated and distributed through a verified provisioning process. Each device receives unique encryption keys that are tied to its specific hardware identity, creating a dynamic security model that adapts to individual device verification rather than relying on universal fixed secrets.

Inventive Principle:
Principle #15Dynamics

2Device complexity

If trust-based provisioning processes are used where manufacturers are trusted not to intercept sensitive data, then the provisioning process is simpler, but the system becomes open to compromise by malicious entities

Engineering Contradiction:
Improveprovisioning process complexityVSAvoidsecurity against malicious interference
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The secure transfer operation incorporates hardware verification that provides feedback on the integrity of the IC device before provisioning data is transferred. The system validates the device's hardware identity and verifies that the device is legitimate, creating a feedback mechanism that prevents malicious entities from intercepting or compromising provisioning data while maintaining automated verification rather than manual trust relationships.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

Hardware verification is performed as a preliminary action before the actual provisioning data transfer occurs. The system validates the IC device's hardware integrity and identity in advance, ensuring that only verified legitimate devices receive provisioning data. This preliminary verification prevents malicious interference during the provisioning process without requiring complex ongoing trust management.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12475262B2Secure provisioning with hardware verification
Publication Date: 2025.11.18 GOOGLE LLC
  • US12475262B2 patent drawing
  • US12475262B2 patent drawing
  • US12475262B2 patent drawing

AI summary

The present disclosure describes various aspects of secure provisioning with hardware verification. In some aspects, sensitive data are provisioned to an integrated circuit (IC) device through a provisioning process. Provisioning data for the IC device are divided into a plurality of fragments, and each fragment is encrypted in one of a plurality of cryptographic keys. Corresponding cryptographic keys are generated at the IC device. The encrypted fragments are transferred to the IC device in respective secure transfer operations, each including sending a seed value to the IC device, validating integrity data configured to characterize integrated circuitry within a portion of the IC device specified by the seed value, and transferring the encrypted fragment to the IC device in response to validating the integrity data. In response to completing the secure transfer operation, the IC device may reconstruct the provisioning data from the encrypted fragments and corresponding cryptographic keys.