Secure IC Provisioning via Remote Key Exchange
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing methods for provisioning integrated circuits (ICs) with cryptographic keys are costly and time-consuming, as they require inventorying and provisioning individual ICs with customer-owned keys, leading to high liability and operational expenses for IC manufacturers and their customers.
Innovation Solution
A method where ICs are initially provisioned with manufacturer-owned security values, allowing secure communication with a provisioning server to enable customer-owned security values to be stored in non-volatile locations, thereby enabling secure operation and disabling manufacturer keys after provisioning, facilitating secure communication channels and feature access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If ICs are provisioned with customer-owned cryptographic keys during manufacturing, then secure communication capability is provided, but inventory costs and liability costs increase
Solution Approach 1:
The IC is pre-provisioned with manufacturer-owned security values during manufacturing, which enables the IC to later securely receive and store customer-owned security values. This preliminary action allows the IC to be sold without customer-specific keys, reducing inventory costs while maintaining future secure communication capability through remote provisioning.
2Reliability
If ICs are provisioned with customer-owned cryptographic keys during manufacturing, then secure communication capability is provided, but provisioning time and operational expenses increase
Solution Approach 1:
Security infrastructure is built during manufacturing by provisioning manufacturer-owned keys and establishing secure communication channels with a provisioning server. This preliminary setup eliminates the need for time-consuming individual key provisioning after sale, allowing customers to receive their custom security values remotely and quickly.
Solution Approach 2:
A provisioning server acts as an intermediary between the IC and the customer's security requirements. The server securely receives customer-owned security values and transfers them to the IC through a pre-established secure channel, enabling remote provisioning without direct manual intervention and significantly reducing provisioning time.
3Reliability
If manufacturer-owned security values are stored in non-volatile locations, then secure operation is enabled, but key exposure risk increases
Solution Approach 1:
Security values are segmented into two distinct categories: manufacturer-owned security values stored in non-volatile locations for enabling secure operation, and customer-owned security values stored in volatile memory for active use. This segmentation limits key exposure risk by ensuring that customer-specific keys are not permanently stored in non-volatile memory, reducing the impact of potential security breaches.
Data Source
AI summary
An integrated circuit is provisioned after the integrated circuit has been sold and integrated into a customer's product. During provisioning, the integrated circuit is booted in a secure manner using a security value, such as a cryptographic key, owned by a manufacturer of the integrated circuit, or by a purchaser of the integrated circuit, to establish a secure communications channel with a provisioning server. Once the secure communications channel is established, the integrated circuit can be provisioned with a security value that is owned by the purchaser of the integrated circuit and the manufacturer's security value is disabled.


