System-on-Chip Key Switching for Post-Shipment Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing system on chip security systems are compromised if authentication information is leaked, necessitating a change in security functions post-shipment.
Innovation Solution
A system on chip with a non-volatile memory and authenticator that allows for changing authentication keys post-shipment by using a key storage region, key indicator region, and an authenticator to manage encryption algorithms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If authentication information is stored in non-volatile memory during manufacturing, then security function is established, but security is compromised if the information is leaked
Solution Approach 1:
The patent implements dynamic key switching capability that allows the system to change authentication keys after manufacturing. The memory device can switch between different key sets stored in separate regions, enabling the system to respond to security threats by invalidating compromised keys and activating backup keys, thus maintaining security reliability even when information leakage occurs
Solution Approach 2:
The patent changes the authentication parameter from a static key to a dynamically selectable key. By storing multiple key sets with different validity periods or conditions and selectively activating them, the system transforms the authentication mechanism from fixed to adaptive, preventing information leakage from permanently compromising security
2Reliability
If authentication information is changed after shipment, then security is maintained against leakage, but device complexity increases
Solution Approach 1:
The patent divides the authentication key storage into multiple separate regions, each containing different key sets. This segmentation allows the system to manage multiple keys independently without requiring complex key management algorithms, as each region can be accessed and switched between through simple address changes rather than complex cryptographic operations
Solution Approach 2:
The patent pre-stores multiple key sets in the memory device during manufacturing, preparing backup authentication credentials in advance. This preliminary action eliminates the need for complex key generation and distribution mechanisms after shipment, as the system can simply switch between pre-configured keys when security issues arise
Data Source
AI summary
Provided are a system on chip, a security system, and a method of performing authentication. The system-on-chip includes a non-volatile memory a key storage region and a key indicator region, and an authenticator configured to identify a storage location by using key indicator data in response to an authentication request received from an external device, obtain key data stored in the storage location from the non-volatile memory, and perform an encryption algorithm by using an input key received from the external device and an asymmetric key of the key data as inputs.


