Secure Key Exchange Protocol for Multi-Drop Bus Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Multi-drop bus interfaces, such as I3C, face security concerns due to the dynamic addition of devices, which can lead to unauthorized access and potential data snooping, compromising secure communication.
Innovation Solution
A secure key exchange protocol is implemented to authenticate devices before allowing secure communication on the bus, ensuring only trusted devices can access and participate in bus communications, using a master device to generate and verify secure keys through a polynomial code-based encryption process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If devices are dynamically added to the multi-drop bus, then the adaptability and versatility of the bus system is improved, but the security and reliability of communication deteriorates due to potential unauthorized access
Solution Approach 1:
The patent implements a preliminary authentication action by establishing a secure key exchange protocol before allowing any communication on the bus. When a device joins the bus, it must first authenticate through polynomial code-based key exchange with existing devices. This preliminary security check ensures that only authorized devices can participate in bus communications, resolving the contradiction by maintaining security reliability while allowing dynamic adaptability.
2Reliability
If authentication protocols are implemented to secure bus communication, then the security and reliability of communication is improved, but the device complexity and operational overhead increases
Solution Approach 1:
The patent changes the parameter of authentication from complex multi-step protocols to a streamlined polynomial code-based key exchange. By using mathematical polynomial codes and their roots as authentication keys, the system achieves strong security with simpler operations. The polynomial code parameters (coefficients, roots, finite field elements) provide cryptographic strength while requiring only basic arithmetic operations, thus improving security without proportionally increasing device complexity.
3Reliability
If all devices on the bus are authenticated, then the security against unauthorized access is improved, but the communication speed and productivity decreases due to authentication overhead
Solution Approach 1:
The authentication is performed as a preliminary action during device join or before secure communication sessions, not continuously during data transmission. Once a device is authenticated through the polynomial code key exchange, it can communicate freely on the bus without repeated authentication overhead. This approach ensures unauthorized access prevention while minimizing the impact on communication productivity during active data transfer.
Data Source
AI summary
In one embodiment, an apparatus includes: a processing circuit to execute instructions; and a host controller coupled to the processing circuit to perform a key exchange with a second device to couple to the apparatus via a bus to which a plurality of devices may be coupled, and in response to a successful completion of the key exchange, enable secure communication with the second device. Other embodiments are described and claimed.


