Key-Ladder Personalization Data Conversion for Device-Specific Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing digital rights management systems face challenges in converting model-specific encrypted personalization data to device-specific uniquely encrypted data, making it difficult to ensure that personalization data can only be used on the intended device, especially in field provisioning scenarios where unique chip information is not readily available.
Innovation Solution
A method and system that converts globally-encrypted personalization data to device-specific uniquely encrypted data by deriving device-specific unique parameters and keys using chip unique information, allowing the personalization data to be securely tied to a specific device rather than a device model, using a multi-stage key ladder and hardware security module for secure key management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If globally-encrypted personalization data is used with a global root key, then the data can be provisioned to multiple devices of the same chip model, but the data cannot be restricted to a specific individual device
Solution Approach 1:
The patent segments the encryption approach by introducing an intermediate key layer between the global root key and the personalization data. The globally-encrypted data uses a global key derived from the global root key, while device-specific encryption uses a unique device key derived from the same global root key but personalized with device-specific information. This segmentation allows the system to maintain both global provisioning capability and device-specific security restriction.
Solution Approach 2:
The patent introduces an intermediate key derivation step as a mediator. The global root key serves as an intermediary that can derive both global keys (for model-level provisioning) and device-specific keys (for individual device restriction). This intermediary mechanism enables the conversion from globally-encrypted to device-specifically encrypted data while maintaining security and compatibility.
2Reliability
If device-specific unique parameters are derived from chip unique information, then the personalization data can be uniquely tied to a specific device, but the provisioning process becomes more complex
Solution Approach 1:
The patent applies preliminary action by pre-generating globally-encrypted personalization data that can later be converted to device-specific encryption. The globally-encrypted data is prepared in advance with a structure that allows future conversion using device-specific parameters. This preliminary preparation simplifies the overall provisioning process by separating data generation from device-specific customization.
Solution Approach 2:
The patent changes parameters by transforming the encryption key from a global key to a device-specific key through parameter derivation. The device-specific unique parameters are derived from chip unique information, and this parameter transformation enables the same personalization data to be securely adapted to individual devices without requiring complete re-encryption or complex provisioning procedures.
3Reliability
If multi-stage key ladder is used to derive keys, then secure key management is achieved, but the key generation process requires multiple computational steps
Solution Approach 1:
The patent applies preliminary action by pre-computing and storing the globally-encrypted personalization data with a structure that facilitates efficient conversion. The multi-stage key ladder is prepared in advance, and the globally-encrypted data is formatted to allow rapid derivation of device-specific keys when needed, reducing the computational burden during actual provisioning operations.
Data Source
AI summary
A system and method of provisioning personalization data of a second type to a device having personalization data of a first type, the device having a global root key GK_0, and a secure processing environment having unique information is disclosed. In one embodiment, the method comprises accepting a provisioning request from the device, the provisioning request comprising the unique information and an identifier of a second type of provisioning data requested, converting the personalization data from the first type to the second type, and transmitting the converted personalization data to the device.


