In-Field Trust Provisioning for Post-Quantum Key Reprovisioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing devices in the field are vulnerable to quantum computer attacks, and provisioning post-quantum cryptography (PQC) keys is challenging due to uncertainty in standardization and space constraints, making over-the-air updates risky and impractical.
Innovation Solution
A system and method using a dedicated device to generate and upload PQC keys and data to update devices in the field, ensuring flexibility and security by reserving space for PQC algorithms and employing symmetric cryptography with optional hybrid approaches.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If post-quantum cryptography keys are provisioned now, then future security against quantum attacks is improved, but device storage space is consumed and flexibility to adapt to future standards is reduced
Solution Approach 1:
The patent performs preliminary provisioning of both classical and post-quantum cryptographic keys during device manufacturing. This preliminary action ensures devices are ready for future quantum threats while maintaining the ability to update or revoke keys later through the reprovisioning mechanism.
Solution Approach 2:
The patent implements dynamic key management where cryptographic keys can be updated, revoked, or replaced through secure reprovisioning channels. This dynamic approach allows the system to adapt to evolving cryptographic standards and quantum computing developments without being locked into initial key choices.
2Ease of operation
If over-the-air updates are used to provision PQC keys, then device updates become convenient, but security risks increase due to potential interception or tampering
Solution Approach 1:
The patent introduces a trusted reprovisioning server as an intermediary that securely manages key distribution. This intermediary establishes authenticated communication channels between devices and key provisioning sources, enabling convenient over-the-air updates while maintaining security through mutual authentication and encrypted channels.
Solution Approach 2:
The patent implements preliminary security measures including device authentication, channel encryption, and signature verification before key provisioning occurs. These preliminary anti-actions prevent interception or tampering during the update process while maintaining operational convenience.
3Reliability
If device storage is allocated for PQC algorithms and keys, then future quantum security is enabled, but available space for other functions is reduced
Solution Approach 1:
The patent segments cryptographic functionality into separate modules, allocating specific storage regions for classical and post-quantum keys and algorithms. This segmentation allows efficient space utilization and enables selective activation of cryptographic functions based on actual security requirements.
Solution Approach 2:
The patent implements configurable cryptographic parameters that allow optimization of key sizes and algorithm selections based on available storage space. This enables adaptation of security parameters to match device constraints while maintaining adequate protection against quantum threats.
4Reliability
If a dedicated reprovisioning device is used, then security and control over key updates are improved, but device complexity increases
Solution Approach 1:
The patent designs the reprovisioning device to perform multiple functions including key generation, key distribution, device authentication, and update management. This multi-functionality consolidates security operations into a single device, improving control while managing complexity through functional integration.
Data Source
AI summary
A method for provisioning a plurality of IC devices, the method including: providing, by a first entity, the plurality of IC devices; storing, by the first entity, in one of the plurality of IC devices used as a provisioning device, one or more keys, and a public key, wherein the one or more keys include a reprovisioning key for reprovisioning the remaining IC devices; installing, by the first entity, provisioning software in the provisioning device; signing, by the first entity, provisioning software using a private key, the private key corresponding to the public key; provisioning the remaining IC devices by the provisioning device including providing cryptographic assets to the remaining IC devices, wherein the cryptographic assets include cryptographic code and keys; and reserving space in the remaining IC devices for reprovisioning the remaining IC devices with updated cryptographic assets.
