Session Key Management for MIPI CSI-2 Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing MIPI CSI-2 standard faces issues with timing visibility of session key updates, vulnerability to replay and falsification attacks, and message authentication challenges in control-system and image-system communications.
Innovation Solution
An information processor, mobile body apparatus, and communication system that include a protection section to derive and manage session keys, ensuring secure encryption, decryption, and message authentication by deriving a first session key, using it for initial communication, and receiving and using a second session key for subsequent communication, with distinct communication data handling.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a session key is transmitted or received using an SPDM session for control-system or image-system communication, then communication between devices is enabled, but timing visibility of session key updates becomes unperceivable and security vulnerabilities arise
Solution Approach 1:
The patent segments the communication into distinct phases: SPDM session establishment phase (for key exchange) and MIPI CSI-2 communication phase (for data transmission). This segmentation allows the session key to be securely obtained through SPDM while maintaining clear timing visibility when the key is activated in the MIPI communication, resolving the ambiguity of key timing visibility.
Solution Approach 2:
The patent introduces an intermediary mechanism where the reception side actively requests and confirms the session key timing through specific communication protocols. The transmission side provides key information at defined intervals, and the reception side verifies when to start using the key, creating a coordinated intermediary process that ensures both security and timing visibility.
2Reliability
If session key is used for protecting communication, then encryption and message authentication are enabled, but replay attacks and falsification attacks can still be performed
Solution Approach 1:
The patent implements dynamic session key management where the session key is not static but is updated and refreshed during the communication process. The key timing is dynamically adjusted based on communication progress, and the protection section actively monitors and updates keys to prevent replay attacks, transforming the static key system into a dynamic one that adapts to communication state.
Solution Approach 2:
The patent introduces feedback mechanisms where the reception side sends confirmation signals to the transmission side about key receipt and activation timing. This feedback loop allows both sides to synchronize their understanding of when the session key becomes effective, preventing replay attacks by ensuring both parties are aware of the exact timing and state of key usage.
3Reliability
If message authentication and encryption are performed on control-system or image-system communication, then security is improved, but implementation issues and complexity arise
Solution Approach 1:
The patent creates a universal protection section that handles multiple security functions (encryption, decryption, message authentication) through a single integrated component. This multi-functional design consolidates what would otherwise be separate complex subsystems into one coordinated unit, reducing overall implementation complexity while maintaining comprehensive security.
Solution Approach 2:
The patent manages implementation complexity by dynamically changing operational parameters such as key timing, protection activation points, and communication modes based on the specific communication scenario. The protection section adapts its behavior based on whether it's handling control-system or image-system communication, adjusting parameters to simplify implementation for each specific case while maintaining security.
Data Source
AI summary
An information processor of an aspect of the disclosure includes a protection section protecting first communication between a first device and a second device and second communication between a third device and the second device. The protection section executes the following (1) to (4):(1) deriving or receiving a first session key;(2) using the first session key for encryption or decryption and message authentication of the first communication;(3) using the first communication protected by the first session key to receive a second session key; and(4) using the second session key for encryption, decryption, or message authentication of the second communication.Here, the total number of times of communication or the total amount of communication data from the start of use to the end of the use of the second session key differs between the first communication and third communication between the first device and the third device.


