Integrated Circuit Security Modules for Secure Data Communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional digital systems lack sufficient security at the electronic component level, as they rely on external servers for data communication security and are vulnerable to breaches, especially since private keys are stored in clear form and susceptible to hacking or virus attacks.

Innovation Solution

A secure digital system with integrated circuit (IC) components that include a key generator, memory for securely storing cipher keys, an authenticating module for neighboring ICs, and encryption/decryption modules for secure data communication, utilizing a unique public/private key pair and chip identification for authentication and encryption, with transaction histories stored in battery-backed memory.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If private keys are stored in clear form for easy access, then ease of operation is improved, but security is worsened due to vulnerability to hacking or virus attacks

Engineering Contradiction:
Improveease of key accessVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements nested security by placing the private key inside a hardware security module (HSM) that is itself protected by physical and logical barriers. The key is not stored in clear form in the main memory but within a secured enclave, creating multiple layers of protection where each layer protects the underlying key material.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent introduces a hardware security module as an intermediary between the application software and the private key. This HSM acts as a mediator that provides key management functions while isolating the actual key material from potential attacks by viruses or hackers in the main system.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If external servers are used for data communication security, then security is improved through centralized authentication, but device complexity increases and reliance on external systems is created

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service security by enabling each IC to generate its own unique public/private key pair and store it in its own secure memory. The authentication and encryption functions are performed locally within the IC using its private key, eliminating the need for external servers to manage cryptographic operations.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent makes the security mechanism universal by integrating the key generator, secure memory, authenticating module, and encryption/decryption modules directly into each IC. This allows any IC in the distributed system to perform security functions independently, making the system scalable without requiring external security infrastructure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If higher level keys are used for long periods, then productivity is improved through reduced key rotation, but security is worsened due to greater potential harm if compromised

Engineering Contradiction:
Improvekey management efficiencyVSAvoidpotential harm from key compromise
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the key hierarchy into multiple levels with different security characteristics. Each IC has its own unique private key that is never transmitted outside the IC, creating isolated security domains. This segmentation limits the impact of any single key compromise to only that specific IC rather than propagating through the entire system.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8281132B2Method and apparatus for security over multiple interfaces
Publication Date: 2012.10.02 AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE LTD
  • US8281132B2 patent drawing
  • US8281132B2 patent drawing
  • US8281132B2 patent drawing

AI summary

A secure digital system including a number of ICs that exchange data among each other. Each of the ICs includes a key generator for generating a cipher key; a memory for securely storing the generated cipher key; an authenticating module for authenticating neighboring ICs of a respective IC; an encryption module for encrypting data communicated from the respective IC to the neighboring ICs; and a decryption module for decrypting data received from the neighboring ICs.