OTP Register Scrambling for Cryptographic Lifecycle Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Electronic devices face challenges in securely managing cryptographic keys throughout their lifecycle, particularly when devices are sent for repair or ownership changes, as existing solutions fail to effectively protect sensitive data from unauthorized access.

Innovation Solution

A cryptographic lifecycle management system utilizing one-time programmable (OTP) memory registers to scramble and unscramble secret key values, ensuring secure key changes and permanent protection of data and authorizations, with OTP memory bits being changed irreversibly to prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic keys are changed during lifecycle events, then data protection against unauthorized access is improved, but key management complexity increases

Engineering Contradiction:
Improvedata protectionVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The cryptographic key management is segmented into distinct lifecycle states (debug, field, returned, lost/stolen) with dedicated key material for each state. This segmentation allows automated key changes based on device state without requiring complex manual management, as each state has predetermined key handling rules.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Key material is preliminarily prepared and associated with each lifecycle state before the device actually transitions to that state. When a lifecycle event occurs, the system simply activates the pre-prepared key material for the new state, eliminating the need for complex real-time key generation and management during the transition.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If OTP memory bits are changed irreversibly to prevent unauthorized access, then security against unauthorized key recovery is improved, but flexibility in key restoration is reduced

Engineering Contradiction:
Improvesecurity against unauthorized accessVSAvoidkey restoration flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

Different OTP memory regions are assigned different properties: some regions contain irreversibly changed key material for security, while other regions contain restorable key material for flexibility. This local differentiation allows simultaneous achievement of security (through irreversible changes) and restoration capability (through restorable regions).

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system discards (irreversibly changes) certain key material in OTP memory to prevent unauthorized access, while simultaneously preserving (maintaining in restorable regions) the ability to recover and restore key material through authorized procedures. This balanced approach achieves both security and flexibility.

Inventive Principle:
Principle #34Discarding and recovering

3Reliability

If key material is scrambled using OTP registers, then protection of sensitive data during device repair is improved, but operational complexity increases

Engineering Contradiction:
Improvedata protection during repairVSAvoidoperational simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs automatic key scrambling and unscrambling operations based on device lifecycle state transitions without requiring manual intervention. The OTP registers self-manage the key material transformation, eliminating complex operational procedures while maintaining strong security protection during device repair and lifecycle events.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11582033B2Cryptographic management of lifecycle states
Publication Date: 2023.02.14 RAMBUS INC
  • US11582033B2 patent drawing
  • US11582033B2 patent drawing
  • US11582033B2 patent drawing

AI summary

A secret key value that is inaccessible to software is scrambled according to registers consisting of one-time programmable (OTP) bits. A first OTP register is used to change the scrambling of the secret key value whenever a lifecycle event occurs. A second OTP register is used to undo the change in the scrambling of the secret key. A third OTP register is used to affect a permanent change to the scrambling of the secret key. The scrambled values of the secret key (whether changed or unchanged) are used as seeds to produce keys for cryptographic operations by a device.