Session Key Update for MIPI CSI-2 and DSI-2

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing CSI-2 and DSI-2 standards do not support key updates for session keys, which is necessary for secure communication in various applications, including mobile devices and IoT systems.

Innovation Solution

An information processing device, mobile device, and communication system are designed with a protection unit that derives and updates session keys using a key schedule, enabling secure encryption and message authentication across multiple communication layers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the SPDM standard is applied to CSI-2 or DSI-2 standards, then security protection for communication is improved, but the session key cannot be updated which limits long-term security

Engineering Contradiction:
Improvesecurity protectionVSAvoidsession key update capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The key management process is segmented into multiple distinct phases: initial key derivation from master secret, session key generation and transmission, and periodic key updates. This segmentation allows each phase to be optimized independently, enabling session key updates while maintaining the security structure of the original SPDM standard.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The master secret is derived in advance from the key schedule during system initialization, before actual communication begins. This preliminary derivation enables subsequent session keys to be generated from this pre-established master secret, allowing for secure key updates without requiring changes to the fundamental key schedule structure.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If a session key transmitted via SPDM-protected communication is used, then communication security is improved, but it requires defining update mechanisms which increases system complexity

Engineering Contradiction:
Improvecommunication securityVSAvoidkey update definition
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The master secret derived from the key schedule serves as a universal foundation for generating multiple session keys throughout the communication lifecycle. This single master secret can derive numerous session keys using different random inputs, eliminating the need for separate update mechanisms and reducing system complexity while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The master secret acts as an intermediary between the key schedule and individual session keys. Rather than directly managing multiple session keys or their updates, the system uses the master secret as a mediator that can generate any required session key, simplifying the key management architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20240007286A1Information processing device, mobile device, and communication system
Publication Date: 2024.01.04 SONY SEMICON SOLUTIONS CORP
  • US20240007286A1 patent drawing
  • US20240007286A1 patent drawing
  • US20240007286A1 patent drawing

AI summary

The present disclosure relates to an information processing device, a mobile device, and a communication system capable of updating a session key. A first secret is derived from a key schedule by using first communication including transmission or reception of a command for controlling second communication faster than the first communication or a response to the command, a first session key related to the first secret is derived, the first session key is used for encryption or message authentication of the first communication, a second session key is received, transmitted, or derived by using the first communication, the second session key is used for encryption or message authentication of the second communication, a third session key is received, transmitted, or derived by using the first communication, and the third session key is used instead of the second session key. The present technology can be applied to, for example, a communication system conforming to the MIPI standard.