Secure Non-Volatile Memory Download Using Unique Device Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional secure embedded devices face challenges in securely downloading code and data into secure non-volatile memory during manufacturing or personalization processes, as existing methods require pre-processing and often use the same scrambling or ciphering algorithms across devices, which can compromise security.

Innovation Solution

The system and method allow for the direct downloading of code and data into secure non-volatile memory without pre-processing, using unique scramble or cipher keys for each device, enabling secure storage and execution by generating and initializing these keys within the device or associated equipment, and employing different scrambling or ciphering algorithms to enhance security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If pre-processing (scrambling/ciphering) is performed before downloading code and data into secure non-volatile memory, then security is enhanced through encryption, but the manufacturing process complexity increases and requires additional processing steps

Engineering Contradiction:
ImprovesecurityVSAvoidmanufacturing process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Instead of pre-processing code and data with scrambling or ciphering algorithms before downloading into secure non-volatile memory, the patent inverts the approach by downloading unprocessed code and data first, then applying the scrambling or ciphering algorithms during the manufacturing or personalization stage. This eliminates the need for complex pre-processing steps while maintaining security through post-download encryption.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent performs the scrambling or ciphering operation as a preliminary action during manufacturing or personalization, before the device is deployed. This timing allows security to be established upfront without requiring complex real-time processing during normal operation, and enables unique keys to be assigned to each device in advance.

Inventive Principle:
Principle #10Preliminary action

2Ease of manufacture

If the same scrambling or ciphering algorithms are used across all devices, then manufacturing and personalization processes are simplified, but security is compromised due to lack of uniqueness

Engineering Contradiction:
Improvemanufacturing simplicityVSAvoidsecurity
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent applies local quality by assigning unique scrambling or ciphering keys to each individual device during manufacturing or personalization. Instead of using a uniform algorithm across all devices, each device receives customized cryptographic parameters, ensuring that compromise of one device does not affect others while maintaining manufacturing efficiency through automated key generation.

Inventive Principle:
Principle #3Local quality

3Reliability

If unique scramble or cipher keys are generated and initialized for each device, then security is significantly enhanced, but the manufacturing process requires additional key generation and initialization steps

Engineering Contradiction:
ImprovesecurityVSAvoidmanufacturing process steps
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling devices to generate their own unique scramble or cipher keys during the manufacturing or personalization process. This automated key generation eliminates the need for manual key distribution and reduces the complexity of key management infrastructure, while still providing the security benefits of unique cryptographic parameters for each device.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11063768B2Systems and methods for downloading code and data into a secure non-volatile memory
Publication Date: 2021.07.13 INFINEON TECHNOLOGIES AMERICAS CORP
  • US11063768B2 patent drawing
  • US11063768B2 patent drawing
  • US11063768B2 patent drawing

AI summary

An example secure embedded device includes a secure non-volatile memory coupled to a processor. The processor provides a scramble or cipher key and uses a scramble algorithm or a cipher algorithm to scramble or cipher information received from an external device into transformed information. The processor writes a least a portion of the transformed information to a plurality of memory locations of the secure non-volatile memory. The plurality of memory locations is based on the scramble or cipher key.