Semiconductor Root Key Management via External Binding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional methods for managing root keys in semiconductor products require complex logistics and significant semiconductor area for storage, and storing root keys in external devices poses security and logistical challenges.
Innovation Solution
A method where a unique key is stored in the semiconductor product, and the root key is combined with this unique key to create an initial security data structure, which is stored externally, allowing the semiconductor product to generate a boot security data structure upon receipt, thus reducing the need for permanent root key storage within the semiconductor product.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If root key is stored in semiconductor product during manufacture, then security is ensured, but semiconductor area for storage increases and logistics become complex
Solution Approach 1:
The patent extracts the root key from the semiconductor product itself and stores it externally in a secure element or hardware security module. Only a binding between the root key and the semiconductor product identifier is stored in the product, while the actual root key resides outside, reducing on-chip storage requirements while maintaining security.
Solution Approach 2:
The security architecture is segmented into multiple components: a unique identifier stored in the semiconductor product, a binding relationship stored externally, and the actual root key stored in a separate secure location. This segmentation allows each component to be optimized independently for its specific function.
2Reliability
If root key is stored in semiconductor product during manufacture, then security is ensured, but logistics complexity increases
Solution Approach 1:
By extracting the root key from the semiconductor product and storing it externally, the patent simplifies logistics. The semiconductor product can be manufactured and shipped without sensitive root key data, and the root key can be provisioned separately to the appropriate products after delivery, reducing security risks during transit and storage.
3Area of stationary object
If root key is stored in external device, then semiconductor area is reduced, but security and logistical challenges arise
Solution Approach 1:
The patent introduces a binding relationship as an intermediary between the semiconductor product identifier and the externally stored root key. This binding acts as a secure link that allows the product to access its specific root key without exposing the root key itself, maintaining security while enabling external storage.
4Area of stationary object
If root key is stored in external device, then semiconductor area is reduced, but manufacturing complexity increases
Solution Approach 1:
The patent performs preliminary actions during semiconductor manufacturing by storing the unique identifier and establishing the binding relationship structure. The actual root key provisioning is deferred to a later stage after the product is manufactured, allowing the manufacturing process itself to remain simple while enabling secure key management to be established subsequently.
Data Source
AI summary
A method which comprises storing a readable identifier, which identifies a semiconductor product, and a unique key, being unique for said semiconductor product or for a group of semiconductor products, in a memory of said semiconductor product, generating an initial security data structure, said initial security data structure depending on a root key and on said unique key, wherein both said root key and said unique key are assigned to said semiconductor product, and wherein said initial security data structure is assigned to said readable identifier, and supplying said initial security data structure to said semiconductor product for further processing.


