Secure Semiconductor Key Activation via Trusted Partner

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current semiconductor devices face challenges in secure field upgrades due to reliance on cloud-based key distribution systems, which require public network connections and are not feasible for bulk access or high-value manufacturing environments, introducing security risks and latency costs.

Innovation Solution

A system that allows end-users to activate capabilities using symmetric key cryptography without a public network connection, enabling bulk access to symmetric keys by using a trusted partner and hardware security modules to manage key distribution, ensuring secure and efficient key management for multiple devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cloud-based key distribution techniques are used, then key management is enabled, but security risks increase and public network connection is required

Engineering Contradiction:
Improvekey managementVSAvoidsecurity risks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

A trusted partner acts as an intermediary between the end-user and the cloud-based key management system. The trusted partner receives bulk UID values from the end-user, requests symmetric keys from the cloud system on behalf of multiple devices, and distributes the keys locally. This intermediary approach eliminates the need for end-users to directly connect to public networks for key retrieval, reducing security risks while maintaining reliable key management.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If cloud-based key distribution is used, then key access is enabled, but latency and costs increase in manufacturing environments

Engineering Contradiction:
Improvekey accessVSAvoidtemporal latency
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system enables preliminary bulk retrieval of UID values during manufacturing before devices are deployed. The trusted partner performs bulk key requests in advance for multiple devices, storing the symmetric keys locally for subsequent distribution. This preliminary action eliminates the need for individual real-time cloud connections during device activation, significantly reducing latency and operational costs in high-volume manufacturing environments.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If individual UID retrieval is required, then unique key access is enabled, but bulk access becomes infeasible

Engineering Contradiction:
Improveunique key accessVSAvoidbulk access capability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system merges multiple individual key request operations into a single bulk request operation. The trusted partner collects UID values from multiple devices and submits a consolidated request to the cloud key management system, receiving a batch of symmetric keys that are then distributed to the corresponding devices. This merging approach maintains the security of unique key access while enabling efficient bulk processing, dramatically improving productivity in manufacturing environments.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS20240143202A1Customer-specific activation of functionality in a semiconductor device
Publication Date: 2024.05.02 LODESTAR LICENSING GROUP LLC
  • US20240143202A1 patent drawing
  • US20240143202A1 patent drawing
  • US20240143202A1 patent drawing

AI summary

The disclosed embodiments are related to securely updating a semiconductor device. In one embodiment, a method comprises receiving a command; generating, by the semiconductor device, a response code in response to the command; returning the response code to a processing device; receiving a command to replace a storage root key of the device; generating a replacement key based on the response code; and replacing an existing key with the replacement key.