Secure Element Cryptographic Binding Without HSM

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge lies in securely binding a secure element to a host device during manufacturing, where the host key information is vulnerable to discovery during transmission, especially when the secure element and host device are manufactured at separate locations with differing security levels, making it difficult to maintain the secrecy of the host key information.

Innovation Solution

The method involves storing binding information in the secure element and a secret key in the host device, both cryptographically correlated with the host key information, allowing the host device to generate and store the host key information during an operational coupling process at a secure location, without transmitting it in the clear, thus ensuring secrecy and eliminating the need for a Hardware Security Module (HSM) at the manufacturing site.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If host key information is transmitted from secure element to host device during binding process, then the secure element and host device can be cryptographically bound, but the host key information becomes vulnerable to discovery by external entities

Engineering Contradiction:
Improvecryptographic bindingVSAvoidhost key information discovery
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The host key information is segmented into two separate components: binding information stored in the secure element and a secret key stored in the host device. Neither component alone can reveal the host key information, thus preventing discovery while enabling cryptographic binding when combined.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A third-party service provider acts as an intermediary to facilitate the binding process. The service provider receives binding information from the secure element manufacturer and secret key from the host device manufacturer, then combines them to generate the host key information without either manufacturer needing to handle the complete sensitive data.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If binding process is performed at separate manufacturing locations with differing security levels, then production flexibility is improved, but security of host key information deteriorates

Engineering Contradiction:
Improvemanufacturing location flexibilityVSAvoidhost key information secrecy
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The sensitive host key information is divided into two separate segments stored at different manufacturing locations: binding information in the secure element and secret key in the host device. This segmentation allows each component to be manufactured at different locations with different security levels while maintaining overall security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The binding information and secret key are prepared in advance at separate manufacturing locations before the final binding process. This preliminary action allows each component to be securely manufactured independently, then combined later without requiring high-security facilities at both locations.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If HSM is deployed at manufacturing site to protect host key information, then security is improved, but cost and device complexity increase

Engineering Contradiction:
Improvehost key information protectionVSAvoidHSM requirement
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The HSM functionality is extracted from the manufacturing site and distributed to the end devices themselves. The secure element and host device each contain portions of the cryptographic material needed to generate host key information, eliminating the need for HSM deployment at manufacturing facilities.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The secure element and host device perform their own cryptographic operations using their respective stored information (binding information and secret key). This self-service capability eliminates the need for external HSM infrastructure at manufacturing sites, reducing complexity and cost.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11991276B2Method and apparatus for cryptographically aligning and binding a secure element with a host device
Publication Date: 2024.05.21 STMICROELECTRONICS INC
  • US11991276B2 patent drawing
  • US11991276B2 patent drawing
  • US11991276B2 patent drawing

AI summary

A secure element device that is configured to be cryptographically bound to a host device includes a secure element host key slot configured to store host key information that allows only the host device to control the secure element, a secure memory storing binding information, and limited functionality allowing the binding information to be read from the secure memory by the host device during a binding process. The binding information is cryptographically correlated with the host key information. The host key information is generated by the host device using the binding information read from the secure element and a secret key. The secure element device further includes general functionality only accessible to the host device using the host key information that is generated by the host device. The secure memory includes prevention measures impeding unauthorized entities from obtaining information from the secure memory.