Security Chip One-Time Programmable Slots Multi-Entity Trusts

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing information handling systems face challenges in supporting multiple independent silicon-rooted trusts, limiting the ability of end users to have total control over firmware, identity, and keys without compromising supply-chain assurances, often requiring different SoCs or motherboards for various products.

Innovation Solution

A security chip with a programmable read-only memory featuring one-time programmable slots and a counter that allows for the creation and invalidation of multiple independent trusts, enabling a single security chip to be used across multiple business lines with different firmware, identity, and keys, while maintaining ownership and renter entity privileges.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple independent silicon-rooted trusts are supported, then the ability of end users to have total control over firmware, identity, and keys is improved, but the system complexity increases requiring different SoCs or motherboards for various products

Engineering Contradiction:
Improveability to support multiple independent trustsVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The security chip is designed with multiple one-time programmable slots that can store different groups of keys for different entities, allowing a single chip design to serve multiple business lines and applications. The chip can function as different silicon-rooted trusts by programming different slots with different key groups, eliminating the need for different SoC designs for different products.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Device complexity

If a single security chip is used across multiple business lines, then device complexity is reduced, but the ability to maintain both ownership and renter entity privileges simultaneously is challenged

Engineering Contradiction:
Improvesecurity chip varietyVSAvoidmulti-entity trust support
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The security chip's key storage is segmented into multiple one-time programmable slots, with each slot capable of storing a separate group of keys for a different entity. This segmentation allows the chip to maintain distinct key groups for owner entities and renter entities simultaneously, with each slot operating as an independent trust domain while being managed through a unified counter mechanism.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A one-time programmable counter is introduced as an intermediary mechanism to manage the validity state of different key groups. The counter tracks which slots are active and can be programmed only once, providing a controlled mechanism to switch between different entity privileges (owner or renter) without compromising the security of stored key groups.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If one-time programmable slots are used to store key groups, then security is improved, but the flexibility to modify keys after programming is lost

Engineering Contradiction:
Improvekey storage securityVSAvoidkey modification flexibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary programming of key groups into one-time programmable slots during manufacturing or initial setup. The one-time programmable nature ensures that once keys are written, they cannot be modified or tampered with, providing strong security guarantees. The counter mechanism is also preliminarily set to track which slots have been programmed, preventing any future modification attempts.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11775690B2System and method for supporting multiple independent silicon-rooted trusts per system-on-a-chip
Publication Date: 2023.10.03 DELL PROD LP
  • US11775690B2 patent drawing
  • US11775690B2 patent drawing
  • US11775690B2 patent drawing

AI summary

A compute device of an information handling system includes a security chip. The security chip includes a programmable read only memory, which in turn includes multiple one-time programmable slots and a one-time programmable slot counter. A first slot of the one-time programmable slots stores a first group of keys associated with a first entity of the security chip. A second slot of the one-time programmable slots stores a second group of keys associated with a second entity of the security chip. The one-time programmable slot counter includes multiple entries. Each of the entries is associated with a different one of the one-time programmable slots. Each of the entries is preset to a first value. The one-time programmable slot counter is only able to count in one direction. A first entry of the entries is updated to invalidate the second group of keys associated with the second entity.