Integrated Circuit RTL Key for Secure iUICC Personalization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The integration of iUICC technology within a system-on-chip (SoC) compromises control over the manufacturing process, making it vulnerable to security breaches, as device manufacturers may lack the necessary security measures to ensure secure personalization of iUICCs during the device manufacturing process.
Innovation Solution
A register-transfer level (RTL) key is embedded in the integrated circuit during fabrication, generating unique cryptographic key pairs for authentication and encryption, which are signed and validated using AES-CMAC, ensuring secure personalization of iUICCs by authenticating the ICs and encrypting sensitive information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If iUICC technology is integrated within a system-on-chip (SoC), then device functionality and integration are improved, but control over the manufacturing process is lost and security is compromised
Solution Approach 1:
A unique hardware key is generated and embedded in the iUICC during the semiconductor fabrication process, before the device leaves the factory. This preliminary key generation ensures that security credentials are established at the point of manufacture, eliminating the need for later secure provisioning steps that would require controlled physical environments.
Solution Approach 2:
The secure key generation function is extracted from the iUICC and relocated to the semiconductor fabrication process itself. The hardware key is generated as an inherent property of the chip during manufacturing, separating the security credential creation from the iUICC's operational control, thereby solving the contradiction between integration and manufacturing security.
2Volume of moving object
If traditional UICCs are replaced with integrated UICCs (iUICCs), then device footprint is reduced, but control over personalization security is lost
Solution Approach 1:
The iUICC performs self-provisioning by automatically generating its own hardware key during fabrication and using it to sign its public key. This self-service approach eliminates the need for external secure personalization facilities, allowing the device to be manufactured in standard facilities while maintaining security.
Solution Approach 2:
The hardware key is generated in advance during semiconductor fabrication, before the device is assembled or personalized. This preliminary key establishment enables secure operations without requiring controlled physical environments during later manufacturing or personalization stages.
3Ease of operation
If separate eUICC hardware elements are used, then profile updates are enabled without physical removal, but manufacturing control and security provisioning are compromised
Solution Approach 1:
The hardware key is generated during semiconductor fabrication, establishing security credentials before the device is deployed. This preliminary security setup enables the eUICC to perform secure profile updates and operations without requiring controlled physical environments or external security provisioning infrastructure.
Solution Approach 2:
The security credential generation is extracted from the operational phase and moved to the fabrication phase. This separation allows the eUICC to maintain ease of operation for profile updates while security is handled automatically through the pre-established hardware key.
Data Source
Figure 1
Figure 2
Figure 3~4
AI summary
A method for exporting sensitive information an integrated circuit, the method comprising: fabricating an integrated circuit, the integrated circuit having a register-transfer level "RTL" key fabricated in the integrated circuit, wherein the RTL key is a pre-determined cryptographic key; signing the sensitive information using the RTL key using a signature; and exporting the signed sensitive information and the signature for validation.