Processor Authentication Key Provisioning During Manufacturing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for provisioning cryptographic keys in processors are vulnerable to quantum computer attacks and impact manufacturing throughput, as they require individual key generation and transmission, which can be compromised and are computationally intensive.

Innovation Solution

Configuring an initial basis for authentication in processors during manufacturing, where the processor generates a secret value and shares a derived value with a secure service, allowing for efficient and secure key creation and verification, including the use of hash-based or symmetric key cryptographic computations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If individual key generation and transmission is performed for each processor, then authentication security is improved, but manufacturing throughput is reduced

Engineering Contradiction:
Improveauthentication securityVSAvoidmanufacturing throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by generating and provisioning authentication keys during the processor manufacturing process itself, rather than performing key generation individually after manufacturing. The secure service provisions keys to the processor during fabrication, embedding security into the manufacturing workflow. This eliminates the need for separate post-manufacturing key provisioning steps and maintains high throughput while ensuring each processor has unique authentication credentials.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If quantum computer capabilities are considered for key exchange, then future security is improved, but computational complexity and vulnerability to attacks increase

Engineering Contradiction:
Improvefuture securityVSAvoidcomputational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by generating unique key pairs during the processor manufacturing process itself, before the processor is deployed. This ensures that keys are provisioned when the processor is most secure (during fabrication in a controlled environment) and eliminates the need for complex key exchange protocols later. The keys are embedded in the processor hardware during manufacturing, providing future-proof security without requiring complex computational operations during execution.

Inventive Principle:
Principle #10Preliminary action

3Ease of manufacture

If key exchange messages and encrypted communications are transmitted, then key provisioning is achieved, but vulnerability to quantum attacks increases

Engineering Contradiction:
Improvekey provisioningVSAvoidvulnerability to quantum attacks
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The patent applies self-service by having the processor itself generate and store its unique authentication key pair during manufacturing, rather than relying on external key transmission. The processor's secure service provisions keys to the processor during fabrication, and the processor then uses these embedded keys for authentication throughout its lifecycle. This eliminates the need for transmitting key exchange messages that could be captured and decrypted by future quantum computers.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11283602B2Provisioning authentication keys in computer processor
Publication Date: 2022.03.22 INTEL CORP
  • US11283602B2 patent drawing
  • US11283602B2 patent drawing
  • US11283602B2 patent drawing

AI summary

Embodiments are directed to provisioning a general-use basis for authentication of a processor device. During manufacture, a hardware processor stores a secret value and shares a derived value produced based on the secret value with a secure service. These values may be used in a limited-use initial authentication process to authenticate the hardware processor. A general-use basis for authentication not so limited as the initial authentication process is established subsequent to the manufacture of the hardware processor. The general-use basis for authentication may include a public-private key pair, and is established upon successful completion of the initial authentication process. Authentication using the general-use process produces an authentication traceable to the manufacture of the hardware processor.