Integrated Circuit Self-Service Key Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing process for manufacturing electronic integrated circuits is onerous due to the high costs and risks associated with handling and managing secret keys, particularly in the foundry's handling of root keys and transport/authentication keys, which complicates the production and personalization of smart cards and other electronic devices.

Innovation Solution

A method where the root key is recorded and the personal authentication key is generated within the integrated circuit upon initial power-up, using diversification of the root key based on unique identification data, and stored in non-volatile memory, simplifying operations and reducing the need for external key management, thereby enhancing security and reducing operational costs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the foundry handles and manages secret keys (root keys and transport/authentication keys) externally, then key distribution can be achieved, but operational costs and security risks increase significantly

Engineering Contradiction:
ImprovesecurityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The integrated circuit performs self-service by autonomously generating its own transport/authentication key using the root key and unique identification data stored in its non-volatile memory. This eliminates the need for external key management infrastructure, reducing both operational costs and security risks associated with foundry handling of secret keys.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The key management function is segmented into two parts: the root key and unique identification data are stored in the integrated circuit's non-volatile memory, while the transport/authentication key is generated locally within the circuit. This segmentation allows secure key distribution without requiring the foundry to manage all key types externally.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If transport/authentication keys are generated and stored externally before device delivery, then authentication capability is provided, but handling and management costs increase

Engineering Contradiction:
Improveauthentication capabilityVSAvoidmanufacturing cost
Core Design Contradiction:
Ease of operationVSEase of manufacture

Solution Approach 1:

The root key and unique identification data are stored in the integrated circuit's non-volatile memory during manufacturing as a preliminary action. The actual transport/authentication key is then generated automatically when the device is first powered on, eliminating the need for expensive external key generation and distribution processes while ensuring authentication capability is ready for use.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If secret keys are managed externally by the foundry, then key distribution is achieved, but risks associated with key manipulation increase

Engineering Contradiction:
Improvekey distributionVSAvoidkey manipulation risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

Each integrated circuit generates its own transport/authentication key autonomously using the root key and unique identification data stored in its secure non-volatile memory. This self-service approach eliminates the need for the foundry to manipulate and distribute individual secret keys, thereby eliminating the security risks associated with external key handling while maintaining reliable key distribution.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The root key and unique identification data stored in the integrated circuit's non-volatile memory serve as an intermediary, allowing the circuit to generate its own secure transport/authentication key without requiring direct external key manipulation. This intermediary mechanism enables secure key distribution while minimizing exposure to key manipulation risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2388949B1Method of managing electronic devices, such as integrated circuits, with internal generation of a personal authentication key
Publication Date: 2019.07.17 IDEMIA FRANCE SAS
  • EP2388949B1 patent drawingFigure 1
  • EP2388949B1 patent drawingFigure 2~3
  • EP2388949B1 patent drawingFigure 4

AI summary

The method involves storing (E4') a root key (MSK) and a unique identification data (IDi) e.g. unique serial number, of an electronic device i.e. integrated circuit (10i), in a non-volatile memory of the device, before authenticating access to the device. A personal authentication key (MSKDi) is generated (E61') within the device in response to an analog signal or a digital signal e.g. control statement, received by the device, by diversifying the root key from the identification data. An access device is authenticated (E13') to access the electronic device by using the authentication key. Independent claims are also included for the following: (1) a method for producing electronic devices such as integrated circuits (2) an integrated circuit type electronic device comprising an authentication module (3) a system for producing electronic devices such as integrated circuits.