Secure IC Provisioning Without HSM Using Extracted Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing trust provisioning methods for electronic devices require expensive hardware security modules (HSMs) and secure provisioning equipment to ensure security in untrusted contract manufacturer facilities, which can be costly and risky due to the need for secure environments and the risk of key leakage.

Innovation Solution

A method for trust provisioning that uses a provisioning device and software to generate and protect intermediate assets such as keys and key shares, allowing secure provisioning of devices without an online connection or HSM, thereby reducing costs and security risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If expensive HSMs and secure provisioning equipment are used, then security and reliability are improved, but device complexity and cost increase

Engineering Contradiction:
ImprovesecurityVSAvoidprovisioning equipment
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security-critical functions from expensive external HSMs and secure provisioning equipment, relocating them into the device itself through built-in cryptographic processors and secure key storage. This eliminates the need for external security infrastructure while maintaining security requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The device performs its own trust provisioning operations using integrated cryptographic capabilities. The device can generate, store, and manage its own cryptographic keys and certificates without requiring external HSMs or secure provisioning equipment, enabling self-service security operations.

Inventive Principle:
Principle #25Self-service

2Reliability

If online HSM and secure provisioning equipment are deployed, then security is improved, but cost increases

Engineering Contradiction:
ImprovesecurityVSAvoidcost
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent replaces expensive, long-lived external HSM infrastructure with inexpensive, integrated cryptographic components that are built into each device. This substitution dramatically reduces the cost of trust provisioning while maintaining security through device-level cryptographic operations.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Ease of operation

If secrets are stored in untrusted CM facilities, then ease of operation is improved, but security deteriorates due to potential key leakage

Engineering Contradiction:
Improveprovisioning operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts secret key material from untrusted external storage locations and relocates it into secure, device-internal cryptographic processors and key storage. This ensures that sensitive cryptographic assets never reside in untrusted CM facilities, eliminating key leakage risks while maintaining operational capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces secure, device-internal cryptographic processors as intermediaries between the device and external environments. These intermediaries handle all cryptographic operations locally, preventing direct exposure of secrets to untrusted CM facilities while still enabling provisioning operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP4142214B1Method for securely provisioning a device incorporating an integrated circuit without using a secure environment
Publication Date: 2025.04.09 NXP BV
  • EP4142214B1 patent drawingFigure 1
  • EP4142214B1 patent drawingFigure 2
  • EP4142214B1 patent drawingFigure 3

AI summary

A method is provided for secure provisioning of a device. In the method, a plurality of integrated circuit (IC) devices is manufactured by a first entity for use in the device. The first entity provides signed provisioning software and stores in at least one provisioning IC device one or more keys used for provisioning the plurality of ICs. The provisioning device with the signed provisioning software is provided to a second entity. The second entity verifies the provisioning software using a stored key. The provisioning software encrypts provisioning assets provided by the second entity and provides the encrypted provisioning assets to the third entity. The signed provisioning software is provided to a third entity by the first entity. During manufacturing of the manufactured products by the third entity, the provisioning software verifies and decrypts the encrypted provisioning assets of the second entity to provision all the plurality of IC devices.