Integrated Circuit Secure Key Self-Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Integrated circuits (ICs) face security risks due to potential compromise of critical security parameters (CSPs) during manufacturing, such as incorrect or malicious installation, and exposure through debug interfaces, which can lead to interception or manipulation of cryptographic keys.

Innovation Solution

The IC determines if the debug interface is disabled and generates CSPs, storing them in secure memory, protecting them from external access and ensuring they are not erased, and if the interface is re-enabled, it prevents normal operation by entering an error state, thereby securing the CSPs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If CSPs are delivered to the IC in a secure manufacturing environment, then the IC can obtain necessary security parameters, but the CSPs may be compromised through manufacturing errors or malicious actions

Engineering Contradiction:
Improvesecurity of CSP deliveryVSAvoidcompromise of CSP during manufacturing
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The IC performs self-testing and self-generation of CSPs without external intervention. The processor automatically executes test code, detects interface disablement, and generates CSPs internally, eliminating reliance on external manufacturing processes that could introduce security compromises.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The IC performs self-tests and checks for interface disablement before generating CSPs. By verifying the security conditions in advance and only proceeding with CSP generation when conditions are met, the system prevents compromised CSPs from being created in the first place.

Inventive Principle:
Principle #10Preliminary action

2Ease of manufacture

If CSP self-generation is implemented, then manufacturing costs are reduced and some security issues are avoided, but CSPs may still be compromised through debug interface interception

Engineering Contradiction:
Improvemanufacturing cost reductionVSAvoidCSP interception via debug interface
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The system applies preliminary anti-action by checking whether the debug interface is disabled before generating CSPs. If the interface is enabled, the system prevents CSP generation entirely, thereby preemptively blocking the potential attack vector of interface interception.

Inventive Principle:
Principle #9Preliminary anti-action

3Reliability

If the IC checks for first-time execution and interface disablement, then CSP security is enhanced, but the device complexity increases

Engineering Contradiction:
ImproveCSP securityVSAvoidsecurity check procedures
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The processor itself performs the security checks and CSP generation without requiring external security modules or complex hardware structures. The existing processor resources are utilized to execute test code and make security decisions, minimizing additional device complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8832781B2Secure key self-generation
Publication Date: 2014.09.09 RSAE LABS INC
  • US8832781B2 patent drawing
  • US8832781B2 patent drawing
  • US8832781B2 patent drawing

AI summary

Techniques are disclosed for providing secure critical security parameter (CSP) generation in an integrated circuit (IC). Embodiments generally include determining that an ability to read the CSP externally (e.g., through a debug interface) has been disabled before the CSP is generated. Depending on the functionality of the device, embodiments can include other steps, such as determining whether software for executing a method for providing a secure CSP is being run for a first time. Among other things, the techniques provided herein for providing secure CSP generation can increase the security of the CSP and reduce manufacturing costs of the IC.