Secure Data Provisioning Component for OEM Key Integrity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In the manufacturing of electronic devices, the insecure environment of Original Design Manufacturers (ODMs) poses a risk to the secure provisioning of cryptographic keys, compromising the integrity and security of these keys when stored in device memories, as OEMs lack trust in the ODMs' manufacturing facilities.

Innovation Solution

A secure data provisioning component is integrated into the device, which verifies and securely stores cryptographic keys by ensuring that each instruction in a sequence corresponds to the previously stored data, using a combination of OEM ID, public key hash, and cryptographic key, preventing unauthorized key provisioning.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If cryptographic keys are provisioned in ODM manufacturing facilities, then device production efficiency is improved, but security and integrity of cryptographic keys deteriorate due to lack of trust in ODM environment

Engineering Contradiction:
Improvedevice production efficiencyVSAvoidsecurity and integrity of cryptographic keys
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces a secure provisioning component as an intermediary between the ODM manufacturing environment and the cryptographic key storage. This component acts as a trusted mediator that verifies and validates provisioning instructions, ensuring that only authorized keys from verified OEM sources can be provisioned, thereby maintaining security while enabling ODM manufacturing

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary verification of provisioning instructions before actual key provisioning occurs. The secure provisioning component validates instructions, checks digital signatures, and verifies OEM authorization in advance, preventing unauthorized key provisioning while maintaining efficient production flow

Inventive Principle:
Principle #10Preliminary action

2Reliability

If verification and validation steps are added to secure key provisioning, then security and integrity are improved, but provisioning process complexity increases

Engineering Contradiction:
Improveintegrity of cryptographic keysVSAvoidprovisioning process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple verification and validation functions into a single integrated secure provisioning component. This component consolidates instruction verification, digital signature validation, OEM authorization checking, and key provisioning operations, reducing overall system complexity while maintaining comprehensive security

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The secure provisioning component performs self-verification of provisioning instructions by checking digital signatures and validating against stored OEM credentials. This self-service capability eliminates the need for external verification systems, simplifying the overall provisioning process while ensuring integrity

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11765149B2Secure data provisioning
Publication Date: 2023.09.19 CRYPTOGRAPHY RESEARCH INC
  • US11765149B2 patent drawing
  • US11765149B2 patent drawing
  • US11765149B2 patent drawing

AI summary

A first instruction to store an entity identification (ID) in a memory of a device may be received. The entity ID may be stored in the memory in response to receiving the first instruction. Furthermore, a second instruction to store a value based on a key in the memory of the device may be received. A determination may be made as to whether the value based on the key that is to be stored in the memory corresponds to the entity ID that is stored in the memory. The value based on the key may be stored in the memory of the device when the value based on the key corresponds to the entity ID.