Selectable Device Identity Keys for Multi-Issuer Secure Boot
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current approaches for managing device identity keys in integrated-circuit devices are inadequate when multiple parties are involved, increasing the risk of key compromise and compromising security.
Innovation Solution
An integrated-circuit device with a hardware-based key generation system that outputs selectable device identity keys based on the software issuer, using a one-time programmable memory to store public cryptographic keys and control which identity key is used depending on the software's origin, allowing multiple parties to manage devices securely.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a single device identity key is used for all devices, then device recognition and management is simplified, but security is compromised when multiple parties need to manage devices
Solution Approach 1:
The patent segments the single device identity key into multiple selectable identity keys (first device identity key and second device identity key). Each key is associated with different software issuers, allowing the hardware-based key generation system to output different identity keys based on the software being executed. This segmentation enables both simplified management (each party manages their own key) and enhanced security (keys are isolated by software origin).
Solution Approach 2:
The patent introduces dynamic selection of device identity keys based on the software issuer. The hardware-based key generation system dynamically determines which identity key to output based on whether the software is from a first or second issuer. This dynamic behavior allows the same hardware to serve multiple management parties securely without requiring manual reconfiguration.
2Reliability
If device identity keys are generated on the device itself using PUF units, then security is maximized, but the risk of key compromise increases when multiple parties need access
Solution Approach 1:
The PUF-based key generation system is segmented to support multiple identity keys. Instead of a single PUF output, the system has multiple PUF units or a configurable PUF system that can generate different identity keys based on the software issuer. This maintains the security benefits of on-device generation while enabling multi-party management through key segmentation.
Solution Approach 2:
Different regions or configurations of the PUF system are allocated to different software issuers. The hardware-based key generation system exhibits local quality by having different PUF pathways or configurations that are activated depending on the software origin. This ensures that each party's keys are generated from isolated PUF resources, maintaining security while enabling versatility.
3Reliability
If public cryptographic keys are stored in one-time programmable memory, then key integrity is ensured, but flexibility to update keys is reduced
Solution Approach 1:
The one-time programmable memory is segmented into multiple key storage regions, each associated with different software issuers. The system can programmatically select which key region to use based on the software being executed. This segmentation maintains the integrity benefits of OTP memory (keys cannot be altered once programmed) while providing flexibility through selective activation of different key regions.
Solution Approach 2:
Multiple public cryptographic keys are pre-programmed into the OTP memory during device manufacturing or initial setup, with each key associated with a specific software issuer. The system then selects the appropriate pre-programmed key based on the software origin. This preliminary action ensures key integrity is established before use while providing flexibility through pre-configured multi-key support.
Data Source
AI summary
An integrated-circuit device comprises a processor, a program memory, a hardware-based key generation system that outputs a selectable device identity key of a plurality of predetermined device identity keys, and a one-time programmable (OTP) memory for storing one or more public cryptographic keys. When a public cryptographic key is stored in the OTP memory, and when software is stored in the program memory, the device uses the public cryptographic key to determine whether the software stored in the program memory is validly signed by a private cryptographic key associated with the public cryptographic key, before the software is executed by the processor. The device controls which device identity key of the plurality of predetermined device identity keys is output by the hardware-based key generation system at least partly in dependence on the outcome of this determination.


