Secure Ranging Key Derivation Cascade

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Secure ranging systems are vulnerable to side channel attacks, which compromise security by correlating physical measurements of computing devices with internal states, leading to potential exposure of cryptographic keys, and existing countermeasures increase resource intensity, complexity, and cost.

Innovation Solution

The generation of cryptographic material for ranging operations is enhanced by using ranging codes derived from keys and inputs, with a key derivation cascade that includes a sparse ranging input and anti-replay counter value to reduce correlations between leaked and secret information, thereby encrypting data transmitted during ranging sessions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic techniques are applied during secure ranging operations, then security against relay attacks is improved, but the system becomes vulnerable to side channel attacks that expose cryptographic keys

Engineering Contradiction:
Improvesecurity against relay attacksVSAvoidvulnerability to side channel attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The cryptographic key material is segmented into multiple components: a secret key stored securely in the secure element and non-secret diversification data that can be publicly transmitted. This segmentation allows the system to maintain security while enabling the ranging functionality, as the secret key alone cannot be used to reconstruct the full cryptographic material without the diversification data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A secure element acts as an intermediary between the application processor and the wireless communication interface. The secure element generates and protects the cryptographic key material, performing key derivation operations in a secure environment while allowing the application processor to access only the results, not the sensitive key material itself.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If countermeasures are implemented to protect against side channel attacks, then security is improved, but resource intensity and device complexity increase

Engineering Contradiction:
Improveprotection against side channel attacksVSAvoidcomplexity of shielding cryptographic accelerators
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The most sensitive cryptographic operations (key generation and key derivation) are extracted from the application processor and performed exclusively within the secure element. This extraction eliminates the need for complex shielding and countermeasures on the application processor, as the secure element is designed with inherent physical security protections.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Different parts of the system have different security requirements. The secure element implements high-security cryptographic operations with physical protection, while the application processor handles non-sensitive tasks. This local differentiation of security quality allows the system to achieve overall security without requiring every component to be equally complex and resource-intensive.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11728972B2Methods and architectures for secure ranging
Publication Date: 2023.08.15 APPLE INC
  • US11728972B2 patent drawing
  • US11728972B2 patent drawing
  • US11728972B2 patent drawing

AI summary

Embodiments described herein enable the generation of cryptographic material for ranging operations in a manner that reduces and obfuscates potential correlations between leaked and secret information. One embodiment provides for an apparatus including a ranging module having one or more ranging sensors. The ranging module is coupled to a secure processing system through a hardware interface to receive at least one encrypted ranging session key, the ranging module to decrypt the at least one encrypted ranging session key to generate a ranging session key, generate a sparse ranging input, derive a message session key based on the ranging session key, and derive a derived ranging key via a key derivation cascade applied to the message session key and the sparse ranging input, the derived ranging key to encrypt data transmitted during a ranging session.