Semiconductor Device Authentication Using Asymmetric Cryptography

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing semiconductor device authentication methods in supply chains are vulnerable to counterfeiting and unauthorized use, as initial test data can be altered and go undetected, compromising supply chain integrity and intellectual property security.

Innovation Solution

Implementing asymmetric cryptography security applications at semiconductor devices, which involve generating and verifying cryptographic keys and security certificates using public and private key pairs, and employing a secure authentication protocol to ensure the authenticity of semiconductor devices throughout the supply chain, including initial testing and subsequent assembly and deployment stages.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If asymmetric cryptography security applications are implemented at semiconductor devices, then supply chain integrity and device authenticity are improved, but device complexity increases

Engineering Contradiction:
Improvesupply chain integrityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Cryptographic keys and security certificates are generated and embedded in semiconductor devices during the initial fabrication and testing phase, before the devices enter the supply chain. This preliminary action ensures that authentication mechanisms are already in place, allowing for reliable verification of device authenticity throughout the supply chain without adding complexity to subsequent operations.

Inventive Principle:
Principle #10Preliminary action

2Object-affected harmful factors

If cryptographic key pairs and security certificates are used for device authentication, then resistance to counterfeiting is improved, but manufacturing process complexity increases

Engineering Contradiction:
Improvecounterfeiting resistanceVSAvoidmanufacturing process complexity
Core Design Contradiction:
Object-affected harmful factorsVSEase of manufacture

Solution Approach 1:

Security certificates and cryptographic keys are generated and embedded during the initial device fabrication and testing phase, before devices enter the supply chain. This preliminary action integrates security measures into the manufacturing process itself, ensuring that only authentic devices with valid cryptographic credentials can enter the supply chain, thereby preventing counterfeiting without requiring complex verification systems at later stages.

Inventive Principle:
Principle #10Preliminary action

3Loss of information

If initial test data is stored in non-volatile memory for authentication, then device identification capability is improved, but vulnerability to data alteration increases

Engineering Contradiction:
Improvedevice identification capabilityVSAvoiddata integrity
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The patent transforms the authentication mechanism from relying on stored test data to using cryptographic key pairs. During initial testing, a private key is generated and stored in secure non-volatile memory, with its corresponding public key stored elsewhere. This parameter change from data-based authentication to cryptography-based authentication ensures that even if data is altered, the cryptographic signatures will not validate, thus maintaining data integrity while preserving device identification capability.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12088695B2Systems and methods for device authentication in supply chain
Publication Date: 2024.09.10 ALTERA CORP
  • US12088695B2 patent drawing
  • US12088695B2 patent drawing
  • US12088695B2 patent drawing

AI summary

A first semiconductor device includes a processor configured to generate a random number at initial test of a second semiconductor device after fabrication of the second semiconductor device in a supply chain related to the second semiconductor device, and send the generated random number to the second semiconductor device. The processor is further configured to receive a first signature that is signed over the sent random number by the second semiconductor device using a first private key that is stored in the second semiconductor device, among a first private and public key pair, and test the received first signature, using a first public key that is stored in the first semiconductor device, among the first private and public key pair, to determine whether the second semiconductor device is authenticated.