Secure Ranging Key Derivation Cascade
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Secure ranging systems are vulnerable to side channel attacks, which compromise security by correlating physical measurements of computing devices with internal states, leading to potential exposure of cryptographic keys, and existing countermeasures increase resource intensity, complexity, and cost.
Innovation Solution
The generation of cryptographic material for ranging operations is enhanced by using ranging codes derived from keys and inputs, with a key derivation cascade that includes a sparse ranging input and anti-replay counter value to reduce correlations between leaked and secret information, thereby encrypting data transmitted during ranging sessions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cryptographic techniques are applied during secure ranging operations, then security against relay attacks is improved, but the system becomes vulnerable to side channel attacks that expose cryptographic keys
Solution Approach 1:
The cryptographic key material is segmented into multiple components: a secret key stored securely in the secure element and non-secret diversification data that can be publicly transmitted. This segmentation allows the system to maintain security while enabling the ranging functionality, as the secret key alone cannot be used to reconstruct the full cryptographic material without the diversification data.
Solution Approach 2:
A secure element acts as an intermediary between the application processor and the wireless communication interface. The secure element generates and protects the cryptographic key material, performing key derivation operations in a secure environment while allowing the application processor to access only the results, not the sensitive key material itself.
2Reliability
If countermeasures are implemented to protect against side channel attacks, then security is improved, but resource intensity and device complexity increase
Solution Approach 1:
The most sensitive cryptographic operations (key generation and key derivation) are extracted from the application processor and performed exclusively within the secure element. This extraction eliminates the need for complex shielding and countermeasures on the application processor, as the secure element is designed with inherent physical security protections.
Solution Approach 2:
Different parts of the system have different security requirements. The secure element implements high-security cryptographic operations with physical protection, while the application processor handles non-sensitive tasks. This local differentiation of security quality allows the system to achieve overall security without requiring every component to be equally complex and resource-intensive.
Data Source
AI summary
Embodiments described herein enable the generation of cryptographic material for ranging operations in a manner that reduces and obfuscates potential correlations between leaked and secret information. One embodiment provides for an apparatus including a ranging module having one or more ranging sensors. The ranging module is coupled to a secure processing system through a hardware interface to receive at least one encrypted ranging session key, the ranging module to decrypt the at least one encrypted ranging session key to generate a ranging session key, generate a sparse ranging input, derive a message session key based on the ranging session key, and derive a derived ranging key via a key derivation cascade applied to the message session key and the sparse ranging input, the derived ranging key to encrypt data transmitted during a ranging session.


