Secure SoC Serialization for Outsourced Feature Provisioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional methods for feature programming in System-on-Chip (SoC) manufacturing require a trusted environment, are costly to change, and lack control over proprietary data distribution, leading to revenue loss, counterfeit chips, and unauthorized feature enablement, especially in outsourced manufacturing.
Innovation Solution
The Asset Management System (AMS) provides a framework for secure, remote control of feature provisioning and data management across untrusted manufacturing locations using controllers, appliances, and agents, with hardware security modules for cryptographic operations and secure communication channels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional feature programming methods are used in outsourced manufacturing, then manufacturing flexibility and cost-effectiveness are improved, but security and control over proprietary data are lost
Solution Approach 1:
The patent introduces a trusted intermediary system consisting of a secure element in the SoC and a remote server that mediates between the manufacturing facility and the semiconductor company. This intermediary enables feature programming in outsourced facilities while maintaining security through encrypted communications and verified authentication, resolving the contradiction between manufacturing flexibility and data security.
Solution Approach 2:
The system segments the feature programming function into separate components: a secure element embedded in the SoC that stores cryptographic keys, a remote server that manages authentication and feature provisioning, and the manufacturing facility that performs the actual programming. This segmentation allows outsourced manufacturing while maintaining control and security through distributed trust architecture.
2Productivity
If feature programming is performed in distributed manufacturing locations, then production efficiency is improved, but control over proprietary data distribution is lost
Solution Approach 1:
The system implements feedback mechanisms where the remote server receives authentication responses and feature programming status from the manufacturing facility, and sends verified commands back to control the process. This feedback loop ensures that proprietary data is transmitted only through authenticated channels and that the semiconductor company maintains awareness and control over the distribution of sensitive information throughout the distributed manufacturing process.
3Ease of manufacture
If traditional feature programming methods are used, then ease of manufacturing is improved, but prevention of unauthorized feature enablement is compromised
Solution Approach 1:
The system performs preliminary authentication and verification actions before allowing any feature programming to occur. The secure element in the SoC is pre-configured with cryptographic keys and authentication mechanisms, and the remote server pre-verifies the legitimacy of any feature programming commands. This preliminary action ensures that only authorized features can be enabled, preventing unauthorized feature enablement while maintaining ease of manufacture through automated verification.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A serialization service module is provided for configuring an asset management system to provide a secure means of generating, assigning to chips (or other electronic objects or devices), and tracking unique serial numbers. To provide this service, a controller is used to define a product model, then to define one or more serialization schemas to be bound to each product model. Each serialization schema contains a range of serial numbers for a particular product. The serial number schemas are sent over a secure, encrypted connection to appliances at the manufacturer's location. Agents can then request serial number values by product name. The serial numbers are generated by the appliance, metered, and provided to the agents. The serial numbers are then injected sequentially into each die in a chip manufacturing process using the agent.