IC Provisioning with Segmented Key Injection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for provisioning integrated circuits (ICs) face challenges when the product types they will be used in are unknown at the time of manufacturing, leading to delays and inefficiencies in product delivery and storage.

Innovation Solution

A method where IC manufacturers provision ICs with a key pair and unique identifier during manufacturing, but without full provisioning. Once the product types are known, the IC manufacturer generates key pairs associated with those product types, creates certificates using these key pairs and unique identifiers, and securely transmits these certificates to the original equipment manufacturer (OEM) for injection into the ICs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If ICs are fully provisioned during manufacturing with product-specific certificates, then security is improved, but the ability to handle unknown product types deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidability to handle unknown product types
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The provisioning process is segmented into two phases: initial provisioning during manufacturing with a factory certificate, and secondary provisioning after product type is known with product-specific certificates. This allows the IC to be securely manufactured and then adapt to specific product types later.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The IC is preliminarily provisioned with a factory certificate and key pair during manufacturing, enabling secure identification and communication. The product-specific provisioning is then performed as a preliminary action before the IC is deployed to its final product.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If all possible product type certificates are stored in ICs during manufacturing, then adaptability to multiple product types is improved, but storage space deteriorates

Engineering Contradiction:
Improveability to support multiple product typesVSAvoidstorage space in IC
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The IC is designed with universal capability to work with multiple product types through a standardized interface and initial factory provisioning. The specific product type certificates are provided externally based on the actual product type, making the IC multi-functional without requiring all certificates to be stored internally.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

A provisioning server acts as an intermediary between the IC manufacturer and the IC. The server stores the product-specific certificates and provides them to the IC as needed, eliminating the need for the IC to store all possible product type certificates locally.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If product-specific provisioning is performed before product type is known, then productivity is improved, but security deteriorates

Engineering Contradiction:
Improveproduct delivery speedVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The provisioning process is segmented into secure initial provisioning during manufacturing and product-specific provisioning after product type is determined. This segmentation allows productivity to be improved by not delaying delivery, while security is maintained through the use of factory certificates and secure certificate transmission protocols.

Inventive Principle:
Principle #1Segmentation

4Reliability

If direct connection to HSM is required for provisioning, then security is improved, but device complexity deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidprovisioning system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A provisioning server acts as an intermediary between the HSM and the IC provisioning process. The server handles the complex interactions with the HSM, certificate generation, and secure transmission, while the IC manufacturer's system remains relatively simple and focused on IC production.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12321501B2Method for securely provisioning an integrated circuit
Publication Date: 2025.06.03 NXP BV
  • US12321501B2 patent drawing
  • US12321501B2 patent drawing
  • US12321501B2 patent drawing

AI summary

A method is provided for securely provisioning a plurality of integrated circuits (ICs) manufactured by a first entity for use in a plurality of manufactured product types manufactured by a second entity. Each IC of the plurality of ICs includes a key pair and a unique identifier (UID). The first entity generates a plurality of key pairs that are not related to the plurality of ICs. A plurality of product types is received from the second entity. A plurality of certificates is generated by the first entity using the UIDs and the key pairs. The plurality of certificates is transferred from a first computer system of the first entity to a second computer system under physical control of the second entity. The second entity injects the plurality of ICs with selected certificates of the plurality of certificates. Unused certificates may be deleted from the second computer system.