PUF-Based Integrated Circuit for Secure Control Program Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a risk of information leakage, particularly control programs, when distributed across wide area communication networks due to potential tapping by third parties, compromising manufacturers' know-how during the development and production of embedded systems.

Innovation Solution

An integrated circuit with a controller, PUF information output unit, key pair output unit, public key transmitter, and decryption unit is used to securely transmit and decrypt information using PUF-based public and private keys, ensuring encrypted data can only be decrypted with the corresponding private key, reducing the risk of unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If control programs are distributed via wide area communication network to overseas production bases, then hardware production efficiency is improved, but information security deteriorates due to potential tapping by third parties

Engineering Contradiction:
Improvehardware production efficiencyVSAvoidcontrol program security
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent applies preliminary action by generating and storing the public key in the integrated circuit before the control program is distributed. This allows the control program to be encrypted with the public key during transmission, ensuring that even if the communication is tapped, the encrypted program cannot be decoded without the corresponding private key that remains securely in the IC chip

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses public key cryptography as an intermediary mechanism. The public key acts as a mediator that enables secure transmission of the control program over the wide area network without exposing the private key or the decryption capability, thus protecting the control program during distribution while maintaining production efficiency

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If control programs are encrypted and transmitted securely, then information security is improved, but device complexity increases due to encryption and decryption mechanisms

Engineering Contradiction:
Improvecontrol program securityVSAvoidintegrated circuit complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent extracts the decryption function into a dedicated integrated circuit with a specific decryption unit that contains the private key. This separation allows the main controller to focus on control functions while the IC chip handles security operations, reducing the complexity burden on the overall system by isolating the cryptographic functionality into a specialized component

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The integrated circuit performs self-service by autonomously generating the public and private key pairs, storing them securely, and handling the decryption of encrypted control programs without requiring external intervention. The IC chip independently verifies the encrypted program using its stored private key, reducing the need for complex external security management infrastructure

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11283632B2Integrated circuit, control device, information distribution method, and information distribution system
Publication Date: 2022.03.22 MITSUBISHI HEAVY IND LTD
  • US11283632B2 patent drawing
  • US11283632B2 patent drawing
  • US11283632B2 patent drawing

AI summary

The integrated circuit includes a CPU configured to operate according to a program, a PUF information output unit configured to output PUF information while power is being supplied, a key pair output unit configured to output a public key and a private key based on the PUF information while power is being supplied, a public key transmitter configured to transmit the public key output from the key pair output unit to the outside, and a shared encryption key decryption unit configured to decrypt encrypted information produced through encryption with the public key and received from the outside with the private key output from the key pair output unit.