Programmable Hardware Device Authentication via Embedded Verification Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Programmable hardware chips lack the capability to prevent unauthorized reprogramming or reconfiguration, which compromises security systems, and they cannot authenticate commands effectively due to insufficient logic gates for cryptographic algorithms.
Innovation Solution
A system that includes a secure processor and a programmable hardware device, where a verification key is generated and embedded in the device's configuration to prevent unauthorized changes, and a command authentication key is used to validate received commands, ensuring the device's integrity and authenticity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If programmable hardware device is used for security functions, then security capability is improved, but vulnerability to unauthorized reprogramming increases
Solution Approach 1:
The patent embeds a verification key in the programmable hardware device during initial configuration before deployment. This preliminary action enables the device to later authenticate itself and commands, preventing unauthorized reprogramming attacks that would otherwise compromise security functions.
Solution Approach 2:
The patent introduces an intermediary authentication mechanism using verification keys and command verification tokens. This intermediary layer between the secure processor and programmable hardware device prevents direct unauthorized access, allowing security verification without requiring complex cryptographic algorithms in the programmable device itself.
2Reliability
If programmable hardware device has sufficient logic gates for cryptographic algorithms, then command authentication capability is improved, but device complexity increases
Solution Approach 1:
The patent uses the secure processor as an intermediary that performs complex cryptographic operations externally. The programmable hardware device only needs to store verification keys and perform simple verification operations, eliminating the need for it to contain full cryptographic algorithm implementations while still achieving command authentication.
Solution Approach 2:
The patent replaces the need for complex cryptographic logic gates in the programmable hardware device with a simplified verification mechanism. Instead of implementing full encryption/decryption algorithms, the device uses pre-shared verification keys and simple comparison operations, substituting mechanical cryptographic complexity with a lighter-weight authentication approach.
Data Source
AI summary
A method, device and system for authenticating a programmable hardware device, such as a programmable hardware chip, and a command received by the programmable hardware device. A secure processor or other trusted source authenticates the programmable hardware chip by verifying, with the secure processor's own verification key, a random number sent to the programmable hardware chip and encrypted using a verification key embedded within the programmable hardware chip, since the nature of the encryption is such that only the original logic function that includes the verification key can encrypt the data correctly. A command received by the programmable hardware chip is authenticated by verifying that a command authentication token received by the programmable hardware chip is generated using the correct command authentication key and consequently verifying that the command is received from the secure processor, as only the party who has the command authentication key can encrypt the data correctly.


