Security Chipset Integrity Proof via Preliminary Key Injection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

When electronic devices are produced through outsourcing, it is challenging to inject unique information and a security key securely, leading to difficulties in proving the integrity of the device, which hinders the provision of various security-related services.

Innovation Solution

An electronic device equipped with a security chipset that stores a certificate and a pair of security keys, along with a processor and memory, injects authentication keys and unique information through a boot loader to generate signature data, ensuring secure storage and transmission of this information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If security key is provided to outsourcing company for device production, then device can be produced through outsourcing, but security risk increases and managing cost increases

Engineering Contradiction:
Improveoutsourcing capabilityVSAvoidsecurity risk
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The security key is injected into the device before being shipped to the outsourcing company for production. This preliminary action ensures that the security key remains under the control of the trusted party (device manufacturer or authorized entity) throughout the outsourcing process, eliminating the need to provide the key to the outsourcing company while still enabling them to produce the device with proper security credentials.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If unique information and security key are injected during process step, then certificate can be generated bound with unique information and security key, but it becomes difficult when produced through outsourcing

Engineering Contradiction:
Improveintegrity proofVSAvoidoutsourcing compatibility
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The security key is injected into the device before being shipped to the outsourcing company for production. This preliminary action ensures that the security key remains under the control of the trusted party (device manufacturer or authorized entity) throughout the outsourcing process, eliminating the need to provide the key to the outsourcing company while still enabling them to produce the device with proper security credentials.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If security key is not provided to outsourcing company, then security risk decreases, but it becomes difficult to inject unique information and security key into device produced through outsourcing

Engineering Contradiction:
Improvesecurity riskVSAvoidinjection capability
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The security key is injected into the device before being shipped to the outsourcing company for production. This preliminary action ensures that the security key remains under the control of the trusted party (device manufacturer or authorized entity) throughout the outsourcing process, eliminating the need to provide the key to the outsourcing company while still enabling them to produce the device with proper security credentials.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4044500B1Electronic device for ensuring integrity of electronic device intrinsic information, and operating method therefor
Publication Date: 2023.08.16 SAMSUNG ELECTRONICS CO LTD
  • EP4044500B1 patent drawingFigure 1
  • EP4044500B1 patent drawingFigure 2
  • EP4044500B1 patent drawingFigure 3

AI summary

Various embodiments of the present invention relate to an electronic device for ensuring the integrity of electronic device intrinsic information, and an operating method therefor. The electronic device comprises: a security chipset for storing certificates and pairs of security keys corresponding to the certificates; a processor operatively connected to the security keys corresponding to the certificates; a processor operatively connected to the security chipset; and a memory operatively connected to the processor, wherein the memory can store instructions for allowing, when executed, the processor to control the security chipset so that at least one authentication key and electronic device intrinsic information are inputted into the security chipset by using a boot loader, and signature data is generated using at least one from among the inputted authentication key, the inputted electronic device intrinsic information, and the pairs of security keys. Other embodiments are also possible.