Key Management in Field-Programmable Integrated Circuits

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need to protect external communication of Hardware Apps in field-programmable integrated circuits from compromise, as existing solutions do not adequately secure key management and communication with entities outside the reconfigurable digital chip or module.

Innovation Solution

A method for key management in field-programmable integrated circuits is implemented, using a hardware configuration with key derivation functionality based on secret and unique information within the integrated circuit, employing the Diffie-Hellman key agreement method to derive cryptographic keys that are bound to the hardware, ensuring secure communication between the integrated circuit and external entities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a Hardware App is loaded into a field-programmable integrated part to perform computation-intensive tasks and cryptographic operations, then processing power and security for cryptographic operations are improved, but communication with external entities may be compromised due to inadequate key management protection

Engineering Contradiction:
Improvesecurity of cryptographic operationsVSAvoidcompromise of external communication
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system separates key management functionality into distinct components: key generation, key derivation, and key storage are implemented as separate hardware modules within the field-programmable integrated part. This segmentation isolates critical security functions from the reconfigurable logic, preventing unauthorized access while maintaining cryptographic security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A dedicated key management interface acts as an intermediary between the Hardware App and external entities. This interface controls all key-related operations, ensuring that keys never leave the secured hardware environment while still enabling secure communication through encrypted channels.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If key management is implemented in software within the Hardware App, then flexibility and ease of configuration are improved, but security against malicious software attacks deteriorates

Engineering Contradiction:
Improveflexibility of Hardware App configurationVSAvoidprotection from malicious software
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent replaces software-based key management with hardware-based key management. The field-programmable integrated part contains dedicated hardware circuits for key generation, derivation, and storage, eliminating the security vulnerabilities inherent in software implementations while maintaining the adaptability of Hardware Apps through programmable interfaces.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system separates key management functionality into distinct components: key generation, key derivation, and key storage are implemented as separate hardware modules within the field-programmable integrated part. This segmentation isolates critical security functions from the reconfigurable logic, preventing unauthorized access while maintaining cryptographic security.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If the field-programmable integrated part is made reconfigurable to load different Hardware Apps, then versatility and adaptability are improved, but security consistency across different applications deteriorates

Engineering Contradiction:
Improveability to load different Hardware AppsVSAvoidconsistency of security protection
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The key management interface is designed as a universal security subsystem that serves all Hardware Apps loaded into the field-programmable integrated part. It provides consistent key generation, derivation, and protection mechanisms regardless of which specific Hardware App is active, ensuring security consistency across diverse applications.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Each Hardware App automatically utilizes the hardware-based key management interface for its security needs without requiring separate key management implementations. The interface self-adapts to different applications while maintaining consistent security protocols, eliminating the need for manual security configuration.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12192348B2Key management in an integrated circuit
Publication Date: 2025.01.07 SIEMENS AG
  • US12192348B2 patent drawing
  • US12192348B2 patent drawing
  • US12192348B2 patent drawing

AI summary

A method for key management in a field-programmable integrated part of an integrated circuit is disclosed herein. According to the method, a hardware configuration for the field-programmable integrated part is loaded into the field-programmable integrated part. The hardware configuration includes a key derivation functionality. Further, using the key derivation functionality, a cryptographic key is derived based on information provided in the field-programmable integrated part.