Secure IC Provisioning via Remote Key Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing methods for provisioning integrated circuits (ICs) with cryptographic keys are costly and time-consuming, as they require inventorying and provisioning individual ICs with customer-owned keys, leading to high liability and operational expenses for IC manufacturers and their customers.

Innovation Solution

A method where ICs are initially provisioned with manufacturer-owned security values, allowing secure communication with a provisioning server to enable customer-owned security values to be stored in non-volatile locations, thereby enabling secure operation and disabling manufacturer keys after provisioning, facilitating secure communication channels and feature access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If ICs are provisioned with customer-owned cryptographic keys during manufacturing, then secure communication capability is provided, but inventory costs and liability costs increase

Engineering Contradiction:
Improvesecure communication capabilityVSAvoidinventory costs
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The IC is pre-provisioned with manufacturer-owned security values during manufacturing, which enables the IC to later securely receive and store customer-owned security values. This preliminary action allows the IC to be sold without customer-specific keys, reducing inventory costs while maintaining future secure communication capability through remote provisioning.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If ICs are provisioned with customer-owned cryptographic keys during manufacturing, then secure communication capability is provided, but provisioning time and operational expenses increase

Engineering Contradiction:
Improvesecure communication capabilityVSAvoidprovisioning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Security infrastructure is built during manufacturing by provisioning manufacturer-owned keys and establishing secure communication channels with a provisioning server. This preliminary setup eliminates the need for time-consuming individual key provisioning after sale, allowing customers to receive their custom security values remotely and quickly.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A provisioning server acts as an intermediary between the IC and the customer's security requirements. The server securely receives customer-owned security values and transfers them to the IC through a pre-established secure channel, enabling remote provisioning without direct manual intervention and significantly reducing provisioning time.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If manufacturer-owned security values are stored in non-volatile locations, then secure operation is enabled, but key exposure risk increases

Engineering Contradiction:
Improvesecure operationVSAvoidkey exposure risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

Security values are segmented into two distinct categories: manufacturer-owned security values stored in non-volatile locations for enabling secure operation, and customer-owned security values stored in volatile memory for active use. This segmentation limits key exposure risk by ensuring that customer-specific keys are not permanently stored in non-volatile memory, reducing the impact of potential security breaches.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9203617B2Secure provisioning of integrated circuits at various states of deployment, methods thereof
Publication Date: 2015.12.01 BITHARMONY LLC
  • US9203617B2 patent drawing
  • US9203617B2 patent drawing
  • US9203617B2 patent drawing

AI summary

An integrated circuit is provisioned after the integrated circuit has been sold and integrated into a customer's product. During provisioning, the integrated circuit is booted in a secure manner using a security value, such as a cryptographic key, owned by a manufacturer of the integrated circuit, or by a purchaser of the integrated circuit, to establish a secure communications channel with a provisioning server. Once the secure communications channel is established, the integrated circuit can be provisioned with a security value that is owned by the purchaser of the integrated circuit and the manufacturer's security value is disabled.