Secure Circuit Key Provisioning in Untrusted Manufacturing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Original equipment manufacturers (OEMs) face challenges in securely outsourcing manufacturing to contract manufacturers they do not fully trust, as there is a risk of over-production and unauthorized release of sensitive design secrets, especially when chips are purchased from distributors and not directly from fabricators, requiring secure provisioning and authentication mechanisms.
Innovation Solution
The implementation of an electronic circuit with private key derivation logic, public key generation logic, and message signing logic that uses immutable values and trust anchors to securely derive and manage keys, ensuring only authorized production and preventing unauthorized access or modification of sensitive data, even in untrusted environments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If chips are purchased from distributors and manufactured by contract manufacturers, then manufacturing flexibility and cost efficiency are improved, but security risks increase due to potential over-production and unauthorized release of sensitive design secrets
Solution Approach 1:
The patent segments the key management process into multiple independent components: key generation occurs in a secure environment, keys are divided into multiple parts using secret sharing schemes, and each part is distributed to different parties. This segmentation ensures that no single contract manufacturer can access the complete key, thereby maintaining security while enabling flexible outsourcing of manufacturing.
Solution Approach 2:
The patent introduces a trusted intermediary (such as a key management server or secure enclave) that facilitates key distribution and verification between the OEM and contract manufacturers. This intermediary acts as a mediator that enables secure collaboration without requiring direct trust between the OEM and multiple contract manufacturers, thus improving both manufacturing flexibility and security assurance.
2Productivity
If complete cryptographic keys are provided to contract manufacturers for chip provisioning, then provisioning efficiency is improved, but the risk of key compromise and unauthorized production increases
Solution Approach 1:
The patent applies segmentation by dividing cryptographic keys into multiple key parts or shares using secret sharing schemes. Instead of providing the complete key to contract manufacturers, only partial key information is distributed. This maintains provisioning efficiency through automated processes while significantly reducing the risk of key compromise, as no single party possesses the complete key.
Solution Approach 2:
The patent implements partial action by providing contract manufacturers with only the necessary portion of key material required for their specific provisioning tasks, rather than the complete key. This partial key information is sufficient for efficient provisioning operations but insufficient for unauthorized key recovery or malicious activities, thus balancing productivity with security.
3Reliability
If trust anchors and immutable values are embedded in circuits, then authentication security is improved, but device complexity and provisioning costs increase
Solution Approach 1:
The patent applies preliminary action by pre-embedding trust anchors and immutable values into circuits during the manufacturing process. These security credentials are provisioned in advance before the devices are deployed to contract manufacturers. This preliminary provisioning establishes strong authentication security from the outset while avoiding the need for complex runtime key management mechanisms.
Solution Approach 2:
The patent enables self-service by designing circuits that automatically perform authentication operations using their embedded trust anchors and immutable values. The devices can independently verify their identity and authenticate with key management systems without requiring external assistance, thereby improving authentication security while minimizing the operational complexity burden on users.
4Reliability
If multiple key parts are distributed to different parties, then security against single-point compromise is improved, but coordination complexity and provisioning time increase
Solution Approach 1:
The patent implements feedback mechanisms that automatically monitor and track the distribution and usage of key parts across different parties. This feedback system enables real-time verification of key assembly status and coordinates the recombination process, thereby maintaining high key security through distributed storage while significantly reducing coordination complexity and provisioning time through automated status tracking and triggering.
Data Source
AI summary
Embodiments of electronic circuits enable security of sensitive data in a design and manufacturing process that includes multiple parties. An embodiment of an electronic circuit can include a private key embedded within the electronic circuit that is derived from a plurality of components including at least one component known only to the electronic circuit and at least one immutable value cryptographically bound into messages and residing on the electronic circuit, public key generation logic that generates a public key to match the private key, and message signing logic that signs messages with the private key.


