Session Key Management for MIPI CSI-2 Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing MIPI CSI-2 standard faces issues with timing visibility of session key updates, vulnerability to replay and falsification attacks, and message authentication challenges in control-system and image-system communications.

Innovation Solution

An information processor, mobile body apparatus, and communication system that include a protection section to derive and manage session keys, ensuring secure encryption, decryption, and message authentication by deriving a first session key, using it for initial communication, and receiving and using a second session key for subsequent communication, with distinct communication data handling.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a session key is transmitted or received using an SPDM session for control-system or image-system communication, then communication between devices is enabled, but timing visibility of session key updates becomes unperceivable and security vulnerabilities arise

Engineering Contradiction:
Improvesession key usage capabilityVSAvoidtiming visibility and security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the communication into distinct phases: SPDM session establishment phase (for key exchange) and MIPI CSI-2 communication phase (for data transmission). This segmentation allows the session key to be securely obtained through SPDM while maintaining clear timing visibility when the key is activated in the MIPI communication, resolving the ambiguity of key timing visibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism where the reception side actively requests and confirms the session key timing through specific communication protocols. The transmission side provides key information at defined intervals, and the reception side verifies when to start using the key, creating a coordinated intermediary process that ensures both security and timing visibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If session key is used for protecting communication, then encryption and message authentication are enabled, but replay attacks and falsification attacks can still be performed

Engineering Contradiction:
Improveencryption and message authenticationVSAvoidreplay attack and falsification attack
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic session key management where the session key is not static but is updated and refreshed during the communication process. The key timing is dynamically adjusted based on communication progress, and the protection section actively monitors and updates keys to prevent replay attacks, transforming the static key system into a dynamic one that adapts to communication state.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces feedback mechanisms where the reception side sends confirmation signals to the transmission side about key receipt and activation timing. This feedback loop allows both sides to synchronize their understanding of when the session key becomes effective, preventing replay attacks by ensuring both parties are aware of the exact timing and state of key usage.

Inventive Principle:
Principle #23Feedback

3Reliability

If message authentication and encryption are performed on control-system or image-system communication, then security is improved, but implementation issues and complexity arise

Engineering Contradiction:
Improvemessage authentication and encryptionVSAvoidimplementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal protection section that handles multiple security functions (encryption, decryption, message authentication) through a single integrated component. This multi-functional design consolidates what would otherwise be separate complex subsystems into one coordinated unit, reducing overall implementation complexity while maintaining comprehensive security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent manages implementation complexity by dynamically changing operational parameters such as key timing, protection activation points, and communication modes based on the specific communication scenario. The protection section adapts its behavior based on whether it's handling control-system or image-system communication, adjusting parameters to simplify implementation for each specific case while maintaining security.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20240007295A1Information processor, mobile body apparatus, and communication system
Publication Date: 2024.01.04 SONY SEMICON SOLUTIONS CORP
  • US20240007295A1 patent drawing
  • US20240007295A1 patent drawing
  • US20240007295A1 patent drawing

AI summary

An information processor of an aspect of the disclosure includes a protection section protecting first communication between a first device and a second device and second communication between a third device and the second device. The protection section executes the following (1) to (4):(1) deriving or receiving a first session key;(2) using the first session key for encryption or decryption and message authentication of the first communication;(3) using the first communication protected by the first session key to receive a second session key; and(4) using the second session key for encryption, decryption, or message authentication of the second communication.Here, the total number of times of communication or the total amount of communication data from the start of use to the end of the use of the second session key differs between the first communication and third communication between the first device and the third device.