Semiconductor Cryptosystem Using Layered Customer Key Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cryptosystems face challenges in managing customer keys across multiple manufacturing locations, particularly abroad, leading to potential key leakage and increased costs due to the need for high-security management by semiconductor manufacturers.
Innovation Solution
A cryptosystem where the semiconductor manufacturer generates a manufacturer encryption key and decryption key, installs the decryption key in the device, and the customer generates a customer encryption and decryption key, encrypts the customer key with the customer key, which is then encrypted by the manufacturer key and supplied back to the customer for installation, allowing decryption by the manufacturer key in the device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the customer key is supplied to the semiconductor manufacturer for encryption and management, then the customer key can be securely installed in the semiconductor device, but the risk of key leakage increases and the cost of high-security management increases
Solution Approach 1:
The patent introduces an intermediary encryption key (first encryption key) that the semiconductor manufacturer generates and uses to encrypt the customer key. The manufacturer never handles or stores the plaintext customer key, only its encrypted form. This intermediary mechanism allows the manufacturer to participate in key installation while eliminating the security risk of the manufacturer accessing or leaking the customer key.
Solution Approach 2:
The patent segments the key management process into distinct cryptographic operations: the customer generates the customer key and encrypts it with a customer encryption key, then sends only the encrypted form to the manufacturer. The manufacturer encrypts this further with a manufacturer encryption key and installs it in the device. This segmentation ensures no single party possesses both the plaintext customer key and the decryption capability.
2Reliability
If the customer key is supplied to the semiconductor manufacturer for management, then the key can be installed in the device, but the cost of managing the customer key with high security increases
Solution Approach 1:
By using the intermediary encryption key mechanism, the patent eliminates the need for expensive high-security key management infrastructure at the manufacturer's facility. The manufacturer only needs to store and process encrypted data, not plaintext cryptographic keys, significantly reducing security infrastructure costs while maintaining installation reliability.
Solution Approach 2:
The patent employs disposable or easily replaceable encryption keys at the manufacturer level (first encryption key, first decryption key) that do not require long-term secure storage. These intermediary keys can be generated, used, and discarded without compromising the permanent customer key, reducing the cost burden of key management.
3Reliability
If the customer key is encrypted by the first encryption key at the semiconductor manufacturer, then the key can be securely installed in the device, but the customer must supply the customer key to the manufacturer which reduces customer security control
Solution Approach 1:
The patent resolves this contradiction by having the customer encrypt their own customer key with a customer encryption key before sending it to the manufacturer. The manufacturer then encrypts this already-encrypted data with a manufacturer encryption key. The customer never loses control because they retain the customer encryption key and can decrypt the data before it leaves their secure environment.
Solution Approach 2:
The customer performs preliminary encryption of the customer key with their own encryption key before supplying it to the manufacturer. This preliminary action ensures that the customer maintains security control throughout the process, as the data is already protected when it enters the manufacturer's system.
Data Source
AI summary
A semiconductor manufacturer generates a manufacturer encryption key and a manufacturer decryption key corresponding to the manufacturer decryption key, installs the manufacturer decryption key in a semiconductor device, and provides a customer with the manufacturer decryption key, the customer generates a customer encryption key and a customer decryption key corresponding to the customer decryption key, decrypts, by the customer decryption key, a customer key to be installed in the semiconductor device, and supplies the encrypted customer key to the semiconductor manufacturer, the semiconductor manufacturer encrypts the supplied customer key by the manufacturer encryption key without decryption, and supplies the encrypted customer key to the customer, the customer decrypts the customer key by the customer decryption key, and installs the decrypted customer key in the semiconductor device, and in the semiconductor device, the installed customer key is decrypted by the manufacturer decryption key installed by the semiconductor manufacturer.


