SoC Trust Provisioning Validation via Key Comparison

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing system-on-chip (SoC) trust provisioning methods are vulnerable to security compromises due to the leakage of secure assets during testing, allowing compromised keys and assets to be written at secure locations, thereby bypassing the trust provisioning operation and compromising the security of the SoC.

Innovation Solution

A system and method that includes a first memory, a trust provisioning system, a one-time programmable (OTP) element, and a comparator to validate the trust provisioning operation by comparing secret keys, ensuring that only validated secure assets are accessed, thereby preventing unauthorized access and maintaining security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If secure assets are stored at secure memory locations and trust provisioning operation is executed, then the security of the SoC is improved, but during testing the location of secure assets may be leaked and compromised keys may be written at secure locations

Engineering Contradiction:
Improvesecurity of SoCVSAvoidleakage of secure assets during testing
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by storing a first secret key in a first memory before the trust provisioning operation is executed. This pre-stored key is used later to validate the integrity of secure assets after they are provisioned to the OTP element, preventing compromised assets from being used without detection.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback through a comparator that compares the first secret key (stored before provisioning) with a second secret key (stored after provisioning in OTP). This comparison provides feedback on whether the trust provisioning operation maintained security, generating a valid signal that indicates whether secure assets are compromised.

Inventive Principle:
Principle #23Feedback

2Manufacturing precision

If testing is performed on secure memory locations to check erase and program functionalities, then the manufacturing quality is improved, but the location of secure assets may be leaked and compromised assets may bypass trust provisioning operation

Engineering Contradiction:
Improvetesting of secure memory locationsVSAvoidleakage of secure assets location
Core Design Contradiction:
Manufacturing precisionVSLoss of information

Solution Approach 1:

The patent segments the secret key storage and validation process into distinct phases: a first secret key is stored in a first memory before provisioning, and a second secret key is stored in an OTP element after provisioning. This segmentation allows testing of memory locations while maintaining security through the comparator validation mechanism.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The comparator acts as an intermediary between the first memory and the OTP element, comparing secret keys without exposing secure asset locations during testing. This intermediary mechanism enables quality testing while preventing information leakage about secure asset locations.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If compromised keys are written at secure locations during testing, then the device complexity is reduced by allowing writing operations, but the trust provisioning operation is bypassed and security is compromised

Engineering Contradiction:
Improvewriting operations during testingVSAvoidvalidation of trust provisioning operation
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary anti-action by pre-storing a first secret key before trust provisioning operation. This pre-stored key serves as a reference to detect and prevent compromised keys from being written during testing, counteracting potential security breaches before they can affect system operation.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The comparator provides feedback by comparing the first secret key with the second secret key stored in OTP. This feedback mechanism detects whether compromised keys were written during testing, generating a valid signal that indicates the integrity of the trust provisioning operation and preventing unauthorized access.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11768963B2System and method for validating trust provisioning operation on system-on-chip
Publication Date: 2023.09.26 NXP USA INC
  • US11768963B2 patent drawing
  • US11768963B2 patent drawing
  • US11768963B2 patent drawing

AI summary

A system-on-chip (SoC) includes a memory, a trust provisioning system, a one-time programmable (OTP) element, and a comparator. The memory is configured to store a first secret key before an execution of a trust provisioning operation. The trust provisioning system is configured to receive an encrypted version of a first set of secure assets and one of a second secret key and an encrypted version of the second secret key, and execute the trust provisioning operation on the SoC to store the first set of secure assets and the second secret key in the OTP element. The comparator is configured to compare the first and second secret keys to generate a valid signal that is indicative of a validation of the trust provisioning operation. The first set of secure assets and a second set of secure assets associated with the SoC are accessible based on the valid signal.