Integrated Circuit Self-Service Key Generation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing process for manufacturing electronic integrated circuits is onerous due to the high costs and risks associated with handling and managing secret keys, particularly in the foundry's handling of root keys and transport/authentication keys, which complicates the production and personalization of smart cards and other electronic devices.
Innovation Solution
A method where the root key is recorded and the personal authentication key is generated within the integrated circuit upon initial power-up, using diversification of the root key based on unique identification data, and stored in non-volatile memory, simplifying operations and reducing the need for external key management, thereby enhancing security and reducing operational costs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the foundry handles and manages secret keys (root keys and transport/authentication keys) externally, then key distribution can be achieved, but operational costs and security risks increase significantly
Solution Approach 1:
The integrated circuit performs self-service by autonomously generating its own transport/authentication key using the root key and unique identification data stored in its non-volatile memory. This eliminates the need for external key management infrastructure, reducing both operational costs and security risks associated with foundry handling of secret keys.
Solution Approach 2:
The key management function is segmented into two parts: the root key and unique identification data are stored in the integrated circuit's non-volatile memory, while the transport/authentication key is generated locally within the circuit. This segmentation allows secure key distribution without requiring the foundry to manage all key types externally.
2Ease of operation
If transport/authentication keys are generated and stored externally before device delivery, then authentication capability is provided, but handling and management costs increase
Solution Approach 1:
The root key and unique identification data are stored in the integrated circuit's non-volatile memory during manufacturing as a preliminary action. The actual transport/authentication key is then generated automatically when the device is first powered on, eliminating the need for expensive external key generation and distribution processes while ensuring authentication capability is ready for use.
3Reliability
If secret keys are managed externally by the foundry, then key distribution is achieved, but risks associated with key manipulation increase
Solution Approach 1:
Each integrated circuit generates its own transport/authentication key autonomously using the root key and unique identification data stored in its secure non-volatile memory. This self-service approach eliminates the need for the foundry to manipulate and distribute individual secret keys, thereby eliminating the security risks associated with external key handling while maintaining reliable key distribution.
Solution Approach 2:
The root key and unique identification data stored in the integrated circuit's non-volatile memory serve as an intermediary, allowing the circuit to generate its own secure transport/authentication key without requiring direct external key manipulation. This intermediary mechanism enables secure key distribution while minimizing exposure to key manipulation risks.
Data Source
Figure 1
Figure 2~3
Figure 4
AI summary
The method involves storing (E4') a root key (MSK) and a unique identification data (IDi) e.g. unique serial number, of an electronic device i.e. integrated circuit (10i), in a non-volatile memory of the device, before authenticating access to the device. A personal authentication key (MSKDi) is generated (E61') within the device in response to an analog signal or a digital signal e.g. control statement, received by the device, by diversifying the root key from the identification data. An access device is authenticated (E13') to access the electronic device by using the authentication key. Independent claims are also included for the following: (1) a method for producing electronic devices such as integrated circuits (2) an integrated circuit type electronic device comprising an authentication module (3) a system for producing electronic devices such as integrated circuits.