In-Field Trust Provisioning for Post-Quantum Key Reprovisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing devices in the field are vulnerable to quantum computer attacks, and provisioning post-quantum cryptography (PQC) keys is challenging due to uncertainty in standardization and space constraints, making over-the-air updates risky and impractical.

Innovation Solution

A system and method using a dedicated device to generate and upload PQC keys and data to update devices in the field, ensuring flexibility and security by reserving space for PQC algorithms and employing symmetric cryptography with optional hybrid approaches.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If post-quantum cryptography keys are provisioned now, then future security against quantum attacks is improved, but device storage space is consumed and flexibility to adapt to future standards is reduced

Engineering Contradiction:
Improvefuture securityVSAvoidflexibility to adapt to standards
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent performs preliminary provisioning of both classical and post-quantum cryptographic keys during device manufacturing. This preliminary action ensures devices are ready for future quantum threats while maintaining the ability to update or revoke keys later through the reprovisioning mechanism.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements dynamic key management where cryptographic keys can be updated, revoked, or replaced through secure reprovisioning channels. This dynamic approach allows the system to adapt to evolving cryptographic standards and quantum computing developments without being locked into initial key choices.

Inventive Principle:
Principle #15Dynamics

2Ease of operation

If over-the-air updates are used to provision PQC keys, then device updates become convenient, but security risks increase due to potential interception or tampering

Engineering Contradiction:
Improveconvenience of updatesVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a trusted reprovisioning server as an intermediary that securely manages key distribution. This intermediary establishes authenticated communication channels between devices and key provisioning sources, enabling convenient over-the-air updates while maintaining security through mutual authentication and encrypted channels.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary security measures including device authentication, channel encryption, and signature verification before key provisioning occurs. These preliminary anti-actions prevent interception or tampering during the update process while maintaining operational convenience.

Inventive Principle:
Principle #9Preliminary anti-action

3Reliability

If device storage is allocated for PQC algorithms and keys, then future quantum security is enabled, but available space for other functions is reduced

Engineering Contradiction:
Improvequantum security capabilityVSAvoidavailable storage space
Core Design Contradiction:
ReliabilityVSArea of stationary object

Solution Approach 1:

The patent segments cryptographic functionality into separate modules, allocating specific storage regions for classical and post-quantum keys and algorithms. This segmentation allows efficient space utilization and enables selective activation of cryptographic functions based on actual security requirements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements configurable cryptographic parameters that allow optimization of key sizes and algorithm selections based on available storage space. This enables adaptation of security parameters to match device constraints while maintaining adequate protection against quantum threats.

Inventive Principle:
Principle #35Parameter changes

4Reliability

If a dedicated reprovisioning device is used, then security and control over key updates are improved, but device complexity increases

Engineering Contradiction:
Improvecontrol over updatesVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent designs the reprovisioning device to perform multiple functions including key generation, key distribution, device authentication, and update management. This multi-functionality consolidates security operations into a single device, improving control while managing complexity through functional integration.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12567962B2Method for post-quantum secure in-the-field trust provisioning
Publication Date: 2026.03.03 NXP BV
  • US12567962B2 patent drawing

AI summary

A method for provisioning a plurality of IC devices, the method including: providing, by a first entity, the plurality of IC devices; storing, by the first entity, in one of the plurality of IC devices used as a provisioning device, one or more keys, and a public key, wherein the one or more keys include a reprovisioning key for reprovisioning the remaining IC devices; installing, by the first entity, provisioning software in the provisioning device; signing, by the first entity, provisioning software using a private key, the private key corresponding to the public key; provisioning the remaining IC devices by the provisioning device including providing cryptographic assets to the remaining IC devices, wherein the cryptographic assets include cryptographic code and keys; and reserving space in the remaining IC devices for reprovisioning the remaining IC devices with updated cryptographic assets.