Deployment of system-specific secrets in highly resilient computer systems
The method provides secure and persistent storage of system-specific secrets by encrypting them with component-specific keys, ensuring only trusted firmware has access, addressing the challenge of maintaining security and integrity in computing systems with redundant components.
Patent Information
- Application Number
- JP2024502495
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-08-04
- Filing Date
- 2022-07-08
- Publication Date
- 2025-11-21
- Estimated Expiration
- 2042-07-08
AI Technical Summary
Existing computing systems face challenges in ensuring the security and integrity of system-specific secrets, particularly in highly trusted environments, as hardware security modules can be compromised, and existing solutions lack redundancy and control over system-specific secrets.
A method and system for persistently storing component-specific import keys during manufacturing, encrypting system-specific secrets with auxiliary keys, and storing these in a secure manner within the computing system, ensuring only trusted firmware has access to the secrets, allowing for redundancy and replacement of components without compromising security.
Ensures secure and persistent storage of system-specific secrets, preventing unauthorized access and maintaining confidentiality even with component replacements, while adhering to high security and confidentiality requirements.
Smart Images

Figure 0007774705000001 
Figure 0007774705000002 
Figure 0007774705000003
Abstract
Description
[Technical Field]
[0001] The present invention relates generally to methods for providing system-specific secrets to a computing system, and more particularly to a computer-implemented method for providing system-specific secrets to a computing system including multiple computing components. The present invention further relates to related hardware secret deployment systems and computer program products. [Background technology]
[0002] Securing data and communications continues to occupy a high position in corporate IT (information technology) management. This is necessary not only because of government mandates (e.g., the EU's GDPR, or General Data Protection Regulation), but also because, if customer data records were to be compromised, a company's inability to protect customer data would result in a loss of trust and therefore lost revenue and profits. Data protection and providing a secure computing platform are not only software issues; it can begin with the way computer system components are manufactured and managed during deployment. This may not yet be the case for mass-market CPU chips used in microcontrollers, personal computers, mobile phones, or home automation devices. However, for highly trusted computing environments, such as those used in the financial, insurance, or government industries, it is increasingly important to prove that data breaches can be prevented with a very high probability from a technical standpoint. While this may require some additional advanced technological components and supporting processes, the associated success in data security is well worth the additional effort.
[0003] While hardware security modules have been in use for some time, ensuring that some modules within a larger computing complex cannot be compromised is a more complex challenge. Summary of the Invention
[0004] According to one aspect of the present invention, a computer-implemented method for providing a system-specific secret to a computing system having multiple computing components is provided. The method includes persistently storing a component-specific import key as part of the computing component and storing the component-specific import key in a manufacturing storage system. Upon a request for a system-specific secret for the computing system, the method includes identifying the computing components included in the computing system, retrieving records related to the identified computing components, determining a system-specific secret protected by a hardware security module, and determining a system-specific auxiliary key. The method further includes encrypting the system-specific auxiliary key with the retrieved component-specific import key to thereby create an auxiliary key bundle, encrypting the system-specific secret, and storing the auxiliary key bundle and the system record in a storage medium of the computing system.
[0005] Other embodiments of the present invention implement the functionality of the above methods in computer systems and computer program products.
[0006] Additional technical features and advantages are realized through the techniques of the present invention. Embodiments and aspects of the present invention are described in detail herein and are considered a part of the claimed subject matter. For a better understanding, reference is made to the detailed description and drawings.
[0007] It should be noted that embodiments of the present invention are described with reference to several different subject matters. In particular, some embodiments are described with reference to method-type claims, while other embodiments are described with reference to apparatus-type claims. However, those skilled in the art will recognize from the above and following description that, unless otherwise indicated, in addition to combinations of features belonging to a certain type of subject matter, combinations between features relating to different subject matters, in particular between features of method-type claims and features of apparatus-type claims, should also be considered to be disclosed in this document.
[0008] The above-defined and further aspects of the present invention will be apparent from and will be elucidated with reference to example embodiments described hereinafter, to which the invention is not limited. Embodiments of the present invention will now be described, by way of example only, with reference to the following drawings, in which: [Brief explanation of the drawings]
[0009] [Figure 1] 1 is a block diagram of one embodiment of a computer-implemented method of the present invention for providing a system-specific secret to a computing system including multiple computing components. [Figure 2] FIG. 1 is a block diagram of one embodiment of an illustrative computing system including multiple computing components. [Figure 3] 2 is a block diagram of one embodiment of an illustrative computing system 200 illustrating how system-specific secrets are made available to trusted firmware. [Figure 4] FIG. 10 illustrates one embodiment of the manufacture of a key import component of a computing component used by a computing system. [Figure 5] 1 illustrates one embodiment of the generation or production of a host import key (i.e., system-specific auxiliary key) bundle during manufacturing of a computing system and its associated key import components. [Figure 6] FIG. 1 illustrates a process for producing a host key during manufacturing of a computing system using the computing system's host import key (system-specific auxiliary key). [Figure 7] 1 is a flowchart illustrating the unpacking of system-specific secrets as part of the trusted firmware flow. [Figure 8] 1 is a flowchart detailing the flow of the Key Import component, specifically the unpacking of component-specific secrets. [Figure 9] 1 is a block diagram of one embodiment of the hardware secret deployment system of the present invention for providing system-specific secrets to a computing system. [Figure 10] FIG. 1 illustrates, at least in part, one embodiment of a computing system that may be used to perform the proposed method. DETAILED DESCRIPTION OF THE INVENTION
[0010] According to one aspect of the present invention, a computer-implemented method for providing a system-specific secret to a computing system having multiple computing components is provided. The method includes permanently storing a component-specific import key as part of the computing component upon manufacturing the computing component and storing the component-specific import key in a manufacturing storage system. Upon a request for a system-specific secret for the computing system, the method may include identifying, in the manufacturing storage system, the computing components included in the computing system, retrieving from the manufacturing storage system records related to the identified computing components, the records including the unique component-specific import key, determining a system-specific secret protected by a manufacturing hardware security module, and determining a system-specific auxiliary key protected by the manufacturing hardware security module.
[0011] Additionally, the method may further include, at the manufacturing side, encrypting the system-specific auxiliary key with the obtained component-specific import key, thereby creating an auxiliary key bundle, the auxiliary key bundle including a bundle record containing a reference to the computing component to which the component-specific import key pertains and the system-specific auxiliary key encrypted with the component-specific import key.
[0012] Additionally, the method may include encrypting the system-specific secret with a secondary system-specific key and storing the secondary key bundle and a system record containing the encrypted system-specific secret in a storage medium of the computing system.
[0013] According to another aspect of the present invention, a hardware secret deployment system may be provided for providing a system-specific secret to a computing system including a plurality of computing components for confidential computing. The system may include one or more processors and a memory communicatively coupled to the one or more processors, the memory storing one or more program code portions that, when executed by the one or more processors, enable the one or more processors to permanently store a component-specific import key as part of the computing component at the time of manufacture of the computing component and to store the component-specific import key in a manufacturing storage system.
[0014] Upon a request for a system-specific secret for the computing system, the processor may also be enabled to identify, within the manufacturing storage system, computing components included in the computing system; retrieve from the manufacturing storage system records relating to the identified computing components, the records including the unique component-specific import key; determine a system-specific secret protected by the manufacturing hardware security module; and determine a system-specific secondary key protected by the manufacturing hardware security module.
[0015] In an exemplary embodiment, the processor may be enabled at the manufacturing site to encrypt a system-specific auxiliary key with the obtained component-specific import key, thereby creating an auxiliary key bundle, the auxiliary key bundle including a bundle record including a reference to the computing component to which the component-specific import key pertains and the system-specific auxiliary key encrypted with the component-specific import key. Further, the processor may be enabled to encrypt a system-specific secret with the system-specific auxiliary key and store the auxiliary key bundle and a system record including the encrypted system-specific secret in a storage medium of the computing system.
[0016] This computer-implemented method for providing system-specific secrets to a computing system that includes multiple computing components may yield numerous advantages, technical effects, contributions, and / or improvements.
[0017] The presented solution allows the manufacturer of a computer system or its components to securely guarantee that they created the system-specific secrets, which may also include being able to invalidate system-specific secrets whose origin cannot be proven beyond doubt.
[0018] Additionally, the proposed concepts can ensure that system-specific secrets are persistent, i.e., survive system restarts. The proposed concepts also rely on and allow for redundant components in computer systems, where computing components may be manufactured independently of the system or may be added later to an already existing computing system.
[0019] This may even make it possible to replace any of such components during the system's lifetime. Furthermore, the proposed solution may ensure that the system-specific secret is inaccessible through any management interface, e.g., system management software, controls, or the like, or through operator action. Therefore, the system-specific secret is known in clear text only to the computer system's firmware, especially trusted firmware, and not to the computer system's user / owner or the manufacturer of the computer system's computing components. Damage to any component of a computer system may not affect the system-specific secret or the confidentiality of other components of the computer system. However, if a computing component of a computer system is compromised and the system-specific secret is leaked, the secret must be replaceable without modifying that particular part of the computing system, i.e., the computing component. The proposed solution may make this possible elegantly.
[0020] The concepts proposed here go far beyond maintaining secrets in a Trusted Platform Module (TPM) using randomly generated keys that do not allow for redundancy, or by providing a computing system with a manufacturing-supplied key that is unique only to the component, and overcome the disadvantage of systems in which the manufacturer cannot disable system-specific secrets because the manufacturer may not maintain control over the system-specific secrets in non-cleartext form.
[0021] Furthermore, the presented solution addresses strong RAS (reliability, availability, serviceability) requirements and allows redundancy with respect to system-specific keys, as components can be independently manufactured and independently replaceable. Furthermore, multiple systems may be equipped with the same system-specific key in a fully controllable manner.
[0022] Additionally, this concept of implementing a kind of double protection using a secondary key contained in protected form within the computing component may allow data that could be used to re-establish the original random system key or system-specific key to be deleted from any storage during manufacturing after the system records containing the encrypted system-specific secrets have been placed into the system after manufacturing, even though it may no longer be needed, thus protecting the integrity of the computing system even when replacement parts are installed for the computing system as preventative maintenance or in the event of a computing component failure.
[0023] According to one embodiment of the method, the auxiliary key bundle may include at least one, particularly a plurality of, bundle records, and the method may also include: searching, by the computing system, for a record in the auxiliary key bundle containing a reference to a computing component that matches one of the computing components of the computing system; sending the found bundle record to the computing component, the system record containing the encrypted system-specific system record and the system-specific auxiliary key encrypted by the component-specific import key; decrypting, by the computing component, the encrypted computing system-specific auxiliary key from the bundle record using a computing component-specific import key, in particular a symmetric key, stored in the computing component; decrypting, by the computing component, the encrypted system-specific secret from the system-specific record using the system-specific auxiliary key; and returning, by the computing component, the system-specific secret to the firmware of the computing system.
[0024] Thus, the firmware, and more particularly the trusted firmware, has access to system-specific secrets sent to the trusted firmware that are never available in clear text form outside of the computing component or the trusted firmware. No other computing components within the computing system were required to make the system-specific secrets available for secure computing or secure communication with, for example, other computing systems that have undergone similar procedures, i.e., have access to their own system-specific secrets.
[0025] According to one embodiment, the method may also include maintaining, by the manufacturer, a manufacturing signing key and permanently storing, in the computing system, in particular in the computing component, a verification key associated with the manufacturing signing key. Creating a bundle record may also include determining, in particular computing, a signature of a system-specific auxiliary key encrypted by a component-specific import key and a reference to the computing component having the manufacturing signing key; determining a signature of the system record; and adding the signature of the system record to the system record (hereinafter also referred to as HIKB (Host Import Key Bundle)). A manufacturing server may control the transmission of the Host Import Key Bundle to a system disk of the computing system. Each record in the HIKB may include a signature.
[0026] According to another embodiment, the method may also include verifying, by the computing system, the bundle record and the system record using a verification key stored in the computing system before accessing the auxiliary key or the system-specific secret, which verification may be controlled by firmware, more particularly by cooperation between the computing component and the firmware.
[0027] It may also be possible to store the auxiliary key bundle and / or system record on the storage medium of the computing system, and to send the auxiliary key bundle and / or system record through a system support channel, such as a call-home support mechanism, to a particular computing system for which an updated auxiliary key bundle and / or new system-specific secret is requested. This source of such new auxiliary key bundle and / or system record may be the manufacturing facility of the computing component.
[0028] In such a context, according to one embodiment of the method, storing the auxiliary key bundle may include modifying multiple computing components of a computing system and replacing an existing auxiliary key bundle on a storage medium that is part of the particular computing system, such as a system disk of the computing system, with a new auxiliary key bundle associated with an updated version of the computing system. This may be a useful feature when a computing component on a computing system needs repair. Replacing a computing component may also be useful when a computing system is updated, for example. It may also be possible to elegantly replace both the old auxiliary key and the old system-specific secret with a new one when the old system-specific auxiliary key needs to be invalidated.
[0029] According to one embodiment of the method, the firmware to which the system-specific secret may be returned (particularly from the computing component after verification and unwrapping) may be trusted firmware, whereby the system-specific secret may be stored in memory of the computing system accessible only by this trusted firmware, such that access to the system-specific secret by unauthorized personnel is never possible, either through an application interface or a command interface.
[0030] According to one embodiment of the method, the trusted firmware may be protected from access through a system management system, or an operator command of the computing system, or software not loaded onto the computing system as trusted firmware, or a combination thereof, In this manner, the computing platform may comply with the requirements necessary for classified computing platforms at the highest security and confidentiality levels.
[0031] According to one embodiment of the method, the computing component may be manufactured independently of a particular computing system. Thus, the computing component may be installed or used as an upgrade component after initial use of a particular host computer at a customer site, i.e., after initial installation after leaving manufacture. Furthermore, the system, i.e., the host system, may also be assembled from any set of pre-manufactured components.
[0032] According to one embodiment of the method, the manufacturing signing key may be protected, i.e., encrypted or wrapped, by the manufacturing hardware security module, so that no one can know the plaintext signing key at the time of manufacturing.
[0033] According to another embodiment of the method, the system-specific secret may be a cryptographic key that is generated and protected by the manufacturing hardware security module, so that it also applies to the system-specific secret that no one knows the plaintext secret at the time of manufacturing.
[0034] According to one embodiment of the method, particularly from a manufacturing perspective, the method may include generating the one, and more preferably each, component-specific import key by a true random number generator, particularly at the manufacturing side, particularly at the time of manufacturing, securely storing the component-specific import key in the computing component, and sending the component-specific import key to a manufacturing hardware security module over a secure channel.
[0035] Additionally, the method, in this context and embodiment, may include importing the component-specific import key into the manufacturing hardware security module and storing the component-specific import key in the manufacturing storage system as an object protected by the manufacturing hardware security module, so that the component-specific import key is also not available to anyone in clear text.
[0036] According to another embodiment, the method may also include storing a verification key associated with the producing signing key in the computing component, and verifying, by the computing component, the signature of each encrypted system-specific secret using the verification key before decrypting the system-specific secret, such that there can be no mismatch between a computing component of the computing system and a system secret encrypted with a component's decryption key.
[0037] According to one embodiment, the method may also include using the system-specific secret as a base secret of a trusted execution environment for confidential computing, which may be, for example, establishing a secure communication channel using the system-specific secret as a core key for encrypted or otherwise secured communication with other computing systems equipped with matching keys.
[0038] According to a further embodiment, the method may include that upon generating a new system-specific auxiliary key for the computing system, a new system-specific secret may also be determined, and the new auxiliary key bundle and a new system record containing the encrypted system-specific secret may be stored in a storage medium of the computing system. This may close the loop on secret computing with respect to maintenance activities and replacement of system components (i.e., computing components of the computing system).
[0039] According to another embodiment, the method may include deleting the system-specific secret after storing the system record containing the system-specific secret wrapped with the secondary key on a storage medium of said computing system, which may thus be performed immediately after the system record containing the encrypted system-specific secret has been stored on a storage medium of the computing system, i.e., after the secret has been distributed to the computing system to be shipped to the customer.
[0040] In the context of this description, the following conventions, terms or expressions, or combinations thereof, may be used:
[0041] The term "system-specific secret" may refer to a binary value that may be created specifically for a particular computing system to enable it to function as a secure computing platform. Specifically, a system-specific secret may be a cryptographic key, such as the private part of a symmetric key pair. A system-specific secret is never made available in clear text to either the manufacturer or to users or their software systems. A system-specific secret may be randomly generated, protected according to predetermined rules, persistently stored, and then deleted in its clear text version. Access to the clear text system-specific secret may be possible only using a predetermined protection scheme and key.
[0042] The term "auxiliary key" can refer to a cryptographic key that can be either a symmetric key or the private key of an asymmetric key pair. The ability to select a symmetric key as an auxiliary key has the advantage that symmetric keys are generally smaller than asymmetric keys. This advantage is important for those involved in quantum-safe cryptography. For each computing system, a system-specific auxiliary key is selected. The system auxiliary key is used to import system-specific secrets into the system. It is therefore also called a Host Import Key (HIK).
[0043] The term "computing system" may refer to a larger computer system that includes multiple computing components such as a central electronics complex (CEC), coprocessors, secure devices, network processors, etc.
[0044] The term "computing component" can refer to a portion of a larger computing system, where a computing component may have at least basic computing power and some memory. In addition, a computing component may include a key import component. This component may enable a system-specific key to be provided to firmware or made available on request. The key import component may have all the required capabilities as well as the password and decryption capabilities to verify the auxiliary key bundle record or system record and unwrap the auxiliary host key and system-specific secret. Each computing component may have its own key import component with a password and key unique to the key import component. As a special case, the key import component may be the only element a computing component contains.
[0045] The term "confidential computing" as used herein may refer, for example, to the use of encryption and decryption keys that are available only to trusted firmware of a computing system. The keys may not be available to any user or user software. Essentially, the keys may not be available to anyone in clear text form. However, they may be used to secure data on the computing system as well as data communicated to another computing system, enabling confidential computing.
[0046] The term "component-specific import key" can refer to a system-specific auxiliary key and possibly a decryption key, particularly a symmetric key, used to unwrap (i.e., decrypt) a system-specific secret stored, for example, on the system disk of a computing system. The use of a symmetric key pair (although an asymmetric key pair may also be possible) may have the advantage that it requires less storage space, i.e., may be faster, and may be quantum safe.
[0047] The term "as manufactured" as used herein may mean "during the process of manufacturing a computing component" at the manufacturing site. Thus, a computing component may be considered "under construction" or "as manufactured" as long as the computing component is under the control of the manufacturing site. This may also be valid when the manufacturing of the computing component may be physically complete; however, software and data may be loaded onto the computing component during this time.
[0048] The term "manufacturer storage system" may mean a database (or similar) that stores records identifiable by a component identifier, along with a protected version of a system-specific secret and, optionally, a signature providing proof that the record originated from the manufacturer.
[0049] The term "hardware security module" (HSM) can refer to a hardware element connected to or embedded in a computer system, such as a server system, e.g., a manufacturing server computer in this case. HSMs are designed to be tamper-resistant and protect secrets, i.e., software keys, from unauthorized access, as well as from physical intrusion and / or unplanned physical power loss. HSMs may be closely associated with a CPU or operate independently of the CPU. In other words, an HSM is a physical computing device that protects and manages one or more digital keys for strong authentication and provides cryptographic processing. These modules are traditionally sold as plug-in cards or external devices that can be directly installed in a computer or network server.
[0050] The term "subkey bundle" can mean at least one record, and typically multiple records, stored, for example, on the system disk of a computer system, where each record in the subkey bundle contains at least three components: a component identifier, a protected version of a system-specific subkey, and a signature.
[0051] The term "bundle record" may refer to one of the records in an auxiliary key bundle (hereafter also referred to as a "host import key bundle").
[0052] The term "storage medium" may refer to any form of memory in a computing system or computing component adapted to persistently store data.
[0053] The term "firmware" or trusted firmware can mean software that may be tightly coupled to a hardware component of a computer system, and for which users can be confident that the trusted firmware is distributed only by one particular trusted vendor and is not accessible by any software freely deployed by customers of the hardware.
[0054] The term "manufacturing signing key" can refer to the private part of a public / private key pair that provides evidence that a record, such as a record in a secondary key bundle, originated from a predetermined manufacturing facility or provider.
[0055] The term "verification key" can refer to the public part of a public / private key pair that is enabled to provide proof that a signature can be derived from a particular source, e.g., the manufacturer.
[0056] The term "trusted execution environment for confidential computing" can refer to a computing environment that allows host software to start and host some guest software, without the host software knowing details about the guest software's data while the guest software is running. Specifically, the host software can be a hypervisor, and the guest software can be a virtual machine (also called a guest). IBM® Secure Execution for Linux, AMD SEV, and Intel® SGX are examples of trusted execution environments.
[0057] A detailed description of the drawings is provided below. All instructions in the figures are schematic. First, a block diagram of one embodiment of a computer-implemented method of the present invention for providing a system-specific secret to a computing system including multiple computing components is provided. Thereafter, further embodiments are described, as well as embodiments of a hardware secret deployment system for providing a system-specific secret to a computing system.
[0058] 1 illustrates a block diagram of one embodiment of a computer-implemented method 100 for providing a system-specific secret, i.e., a host key, to a computing system that includes multiple computing components, which may include a computing execution complex (CEC), a secure appliance, a coprocessor, etc.
[0059] The method 100 includes persistently storing 102 component-specific import keys (hereinafter referred to as IK1, IK2, ..., IKn) as part of the computing component during manufacturing, for example, by using an S-EEPROM or by otherwise burning them into an associated device. The computing component may thereby comprise a processing unit and some memory. The method 100 further includes persistently storing 104 the component-specific import keys, i.e., IK1, IK2, ..., IKn, in a manufacturing storage system. Thus, the component-specific import keys may be available for use after the manufacturing process. It should also be noted that the import keys are stored in the form of HSM-protected key objects (from the manufacturing host), making clear key values completely inaccessible.
[0060] Upon receiving a request 106 for a system-specific secret for a computing system (particularly, a customer's specific computing system, an automated computing system ordering system, a hardware partner upgrade ordering system, or a security officer wishing to replace an existing system secret with a new secret), the method 100 includes identifying, within a manufacturing storage system, the computing components included in the computing system, particularly, identifying associated identifiers identifying the computing components 108. This can be done at the manufacturing site from a manufacturing database that tracks all manufactured components.
[0061] The method 100 further includes obtaining 110 a record related to the identified computing component from the manufacturing storage system, the record including the unique component-specific import key, and the method 100 further includes determining 112 a system-specific secret protected by the manufacturing hardware security module. This may be done either by retrieving a system-specific secret already generated for the computing system (e.g., when repairing or replacing a computing component in an existing computing system) or by generating a new (random) secret, for example, when manufacturing a new computing system or replacing a system secret in an existing computing system.
[0062] In a subsequent step, method 100 also includes determining a system-specific auxiliary key protected by the manufacturing hardware security module step 113. Typically, the system-specific auxiliary key is a random key generated by the hardware security module and stored in a database at the time of manufacture as an object protected by the hardware security module along with a system identifier.
[0063] The method 100 further includes, at the manufacturing side, encrypting the system-specific auxiliary key with the obtained component-specific import key, i.e., IK1, thereby creating 114 an auxiliary key bundle (containing at least one entry, but typically containing more entries / records), where the auxiliary key bundle includes at least one bundle record containing a reference to the computing component to which the component-specific import key pertains and the system-specific auxiliary key encrypted with the component-specific import key.
[0064] Method 100 further includes encrypting 115, at the manufacturing site, the system-specific secret, thereby creating a system record, and typically transferring 116, often both, the auxiliary key bundle and the system record from the manufacturing computer to the computing system, and storing 116, at the requesting site, in particular, the auxiliary key bundle and the system record on a storage medium of the computing system, which may typically be a system disk of the computing system.
[0065] FIG. 2 illustrates a block diagram of one embodiment of a specific computing system 200 including multiple computing components 201, 203 and a system disk 206. Additionally, computing system 200 includes trusted firmware (FW) 208 with associated memory or storage. Two key import components KIC1, KIC2 are also shown, each of which is an example of multiple such key import components. In addition to computing components 201, 203, computing system 200 may include multiple other components (not shown here), which may or may not be related to other key import components. That is, for each computing component included in the computing system, there may be an associated key import component.
[0066] Each computing component includes memory, shown here as memory 210 and 212 of the respective key import component 202, 204. However, because the key import components 202, 204 are integral parts of the associated computing component 201, 203, any differences between the memory 210, 212 of the respective key import component 202, 204 and the memory of the computing component 201, 203 itself may be merely artificial.
[0067] Additionally, host import key bundle 214 is shown, here with only two records 216, 218 corresponding to only two computing components 201, 203. Typically, a record 216, 218 is available in host import key bundle 214 for each computing component 201, 203 (and others) of computing system 200, i.e., for each key import component 202, 204.
[0068] As can be seen, each record 216, 218 includes a key import component identifier KIC1, KIC2, an associated protected, e.g., encrypted or otherwise secured, system-specific secondary key (also called host import key) 220, 222, which may be a symmetric key, and an associated signature 224, 226. It may be noted that the encryption of the system-specific secret is performed from a Hardware Security Module (HSM) in the manufacturing computer system.
[0069] Additionally, the encrypted system key 205 along with the associated signature 207 is stored in the form of a system record 209 on a system disk 206 .
[0070] 3 shows a block diagram 300 of one embodiment of a specific computing system 200 illustrating how the system-specific secret 312 is made available to the trusted firmware 208, i.e., the process for unpacking the system-specific secret 312. In general, diagram 300 shows roughly the same components as FIG. 2, e.g., computing system 200, key import components 202 and 204, etc. (though computing components 201 and 203 are not shown). FIG. 3 details how the unpacked secondary key 308 is used to unpack the system-specific secret 312 for only the computing components belonging to the key import component 202 in the lower left portion of FIG. 3 (not shown, compare 201 in FIG. 2).
[0071] First, a record 216 of a host key bundle 214 (or secret bundle, cf. above) is made available 302 to the key import component 202. Here, the record 216 is verified 304 using the public portion VK stored in the relevant key import component 202 and the signature component of the record 216 available to the key import component 202. If the signature verification is successful, the next step is to unwrap 306 the protected system-specific auxiliary key 220 using the system-specific import key IK1, here denoted as symmetric key IK1. Next, the key import component 202 makes the unprotected, i.e., decrypted, system-specific auxiliary key 308 available to the trusted firmware 208.
[0072] The same process may be performed by the key import component 204, but using a different set of signing and verification keys, and a different import key IK2 corresponding to record 218 in the host key bundle 214. In this way, the system-specific secret 312 may also be derived by a second computing component associated with the second key import component 204, or by another equivalent computing component in the computing system 200. It should also be mentioned that only one step is required to unpack the auxiliary key by any of one or more import components, and only one of the installed import components needs to be functional, leading to resiliency.
[0073] It should also be mentioned that the unwrapping of the system-specific secret 312 may be performed by the trusted firmware 208 as shown in FIG. 3, or alternatively may be performed in a single step by the key import component 202 (or 204).
[0074] Next, we shift our focus from the installed computing system at the user end to the manufacturing end and the processes involved in manufacturing the computing components.
[0075] 4 illustrates one embodiment 400 of a manufacturing key import component for use by a computing system (compare FIG. 2, 200). The manufacturing computing system or server (not shown) includes or controls a hardware security module 402 (HSM) that contains an HSM master key 404.
[0076] A component-specific import key IK406 is randomly generated and stored as part of the key import component 202 KIC that is manufactured with the associated computing component. Additionally, a public verification key VK associated with the private manufacturer signing key is stored in the key import component 202. The manufactured component database 410 maintains at least one record for each manufactured computing component and its associated key import component KIC. Additionally, a key import component identifier KIC is maintained as part of record 408 in the manufactured component database 410 as well as a component of record 206 in the host key bundle 214. No protection in the form of identifier encryption is required for this identifier KICx.
[0077] To ensure that the component-specific import key IK is not available in clear text to anyone during manufacturing, the import key IK is protected 412 via the HSM 402 and its master key 404. As such, it is stored in a record 408 in the manufactured component database 410. Thus, a protected version of the component-specific import key IK is available in the manufactured component database 410 after the computing component and its key import component KIC leave manufacturing.
[0078] FIG. 5 illustrates an embodiment 500 of the generation or production of a host import key bundle (compare 214, FIG. 2) or auxiliary key bundle during the production of a computing system and its associated key import component KIC. The HSM 402, along with its HSM master key 404, is used to generate and wrap auxiliary keys 504 (inside the envelope shown, identical to auxiliary keys 220 in FIG. 2) with the HSM master key 404. An auxiliary key database 514 stores the created and then encrypted system-specific auxiliary keys 504, which are protected by the HSM master key 404 (step 1). In the next step (step 2), the system-specific auxiliary keys 504 are rewrapped with the component import key 508, i.e., first unwrapped by the HSM MK 404 and then rewrapped by the component import key 508.
[0079] In the next step, the components of record 216 are signed (using HSM operations) with signing key 504, and the resulting signature 502 (derived from signing key 512, shown wrapped with an HSM master key; "Step 3") is added to record 216 as the rightmost component. As noted above, host import key bundle 214 becomes an element of the computing system's system disk, where it is distributed and installed at the user end. Therefore, using this key generation scheme, unprotected system-specific secrets 312 never appear in production communications or storage.
[0080] Similarly, the protected component-specific secret 220 is moved into the host key bundle 214. As a result, the host import key 220 is protected with the component import key 508 of the record in the manufactured component database 410 using the HSM 402 before being made a component of the record 216 in the host import key bundle 214. Thus, none of the keys are made available to anyone in clear text.
[0081] Figure 6 shows the process of host key (also called system-specific secret) production. First, a random host key 602 is generated 604, which is used 606 by HSM 402. Using the wrapped system-specific auxiliary key 503 (i.e., decrypted by HSM 404), which is protected by the master key 404 from HSM H402 and the auxiliary key database 514 (compare Figure 5), the random host key is exported 608 as a wrapped key. The random host key is thereby wrapped by the system-specific auxiliary key 503. That is, a re-encryption of the system key occurs, which may only be possible by HSM 402. Finally, the random system key 602 can be deleted, as symbolically indicated by reference numeral 610.
[0082] Figure 7 shows a flowchart 700 illustrating the unpacking of system-specific secrets as part of the trusted firmware flow. First, the auxiliary key bundle HIKB is read from the system disk of the computing system involved 702. Next, the system key record (WS,S1) is read 703. Then, the key import component list CL is read 704, which contains a list of key import component IDs of components installed in the system from a system component.
[0083] The process loops to access the next record containing the key import component identifier C, the protected component-specific secret WK, and the signature S from the host key bundle 706. It then determines if C is included in CL 708. If not, it determines if there are any more records in the host import key bundle (HIKB) 710. If so (if "Y"), the process loops back to read the next record 706. If there are no more records in the host key bundle (if "N"), an error is reported 712 that the host import key bundle (HIKB) does not contain any components included in the system.
[0084] However, if C is included in CL (decision 708), then that record, along with the system record (WS, S1), is sent 714 to the Key Import Component with identifier C. If the Key Import Component does not return an error 616 (case "N"), then the result is used 718 as the system-specific secret.
[0085] If the key import component returns an error (if "Y"), error 720 is reported, indicating a corrupted Host Import Key Bundle (HIKB) record or a corrupted system record.
[0086] Figure 8 shows a flowchart 800 detailing the flow of the Key Import component, specifically the unpacking of the system-specific secret. A record containing C, WK, and S, and a record containing WS and S1 are used as input 802. Next, a verification key VK is used 804 to verify that signature S is the signature of record (C, WK) and that S1 is the signature of WS. If that signature verification 806 is not successful (case "N"), an error is returned 808 and the process stops. WK can then represent the wrapped auxiliary key, and WS can represent the wrapped system-specific secret (or host key).
[0087] If the signature verification 806 is successful (case "Y"), the process proceeds to decrypt (unwrap) the WK using the computing component's import key IK 810, resulting in the associated host import key. Next, the WS is decrypted (i.e., unwrapped) using the host import key 811, resulting in the unwrapped host key. Finally, as a result of the decryption or unwrapping operation, a system-specific host key (312, compare with Figure 3) is returned to the trusted firmware 812.
[0088] For completeness, Figure 9 illustrates a block diagram of a possible embodiment of a hardware secret deployment system 900 for providing a system-specific secret to a computing system. The system 900 includes one or more processors 902 and a memory 904 communicatively coupled to the one or more processors 902, the memory storing one or more program code portions that, when executed by the one or more processors 902, enable the one or more processors 902 to permanently store a component-specific import key in a storage component as part of the computing component upon manufacture of the computing component, and to store the component-specific import key in a manufacturer's storage system, e.g., in manufacturer's component database 410 (compare 410, Figure 4). The processor 902, when executing the program code in the memory 904, is further enabled, in particular, upon a request for a system-specific secret for the computing system, to identify within the manufacturing storage system, in particular via the identification unit 908, a computing component included in the computing system, and to retrieve from the manufacturing storage system, in particular via the retrieval unit 910, a record relating to the identified computing component, the record including a unique component-specific import key; to determine, in particular via the first determination unit 912, a system-specific secret protected by the manufacturing hardware security module; and to determine, in particular via the second determination unit 913, a system-specific auxiliary key protected by the manufacturing hardware security module.
[0089] The processor 902, upon executing the program code in the memory 904, is further enabled to encrypt, e.g., at the manufacturing site, by the first encryption module 914, the system-specific auxiliary key with the obtained component-specific import key, thereby creating an auxiliary key bundle, whereby the auxiliary key bundle includes a bundle record containing a reference to the computing component to which the component-specific import key pertains and the system-specific auxiliary key encrypted by the component-specific import key.
[0090] Finally, but equally importantly, the processor 902, when executing the program code in the memory 904, further enables, in particular by means of a second encryption module, to encrypt the system-specific secret with a system-specific auxiliary key, and to store (206, compare with Figure 2), in particular by means of a dedicated storage module (not shown), the secret bundle on a storage medium of the computing system, in particular on a system disk.
[0091] It should also be mentioned that all functional units, modules, and functional blocks may be communicatively coupled with each other to exchange signals or messages in a selected 1:1 manner. Alternatively, the functional units, modules, and functional blocks may be connected to a common communication backbone 916 for selective signal or message exchange.
[0092] Embodiments of the present invention may be implemented in conjunction with virtually any type of computer, regardless of the platform suitable for storing and / or executing the program code. Figure 10 illustrates, by way of example, a computing system 1000 suitable for executing program code related to the proposed method.
[0093] Computing system 1000 is merely one example of a suitable computer system, and whether computer system 1000 is capable of implementing and / or performing any of the functions described above does not suggest any limitation as to the scope of use or functionality of the embodiments of the invention described herein. Computer system 1000 has components that are operable with numerous other general-purpose or special-purpose computing system environments or configurations. Examples of well-known computing systems, environments, or configurations, or combinations thereof, that may be suitable for use with computer system / server 1000 include, but are not limited to, personal computer systems, server computer systems, thin clients, thick clients, handheld or laptop devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs, minicomputer systems, mainframe computer systems, and distributed cloud computing environments that include any of the above systems or devices. The computer system / server 1000 may be described in the general context of computer system-executable instructions, such as program modules, executed by the computer system 1000. Generally, program modules may include routines, programs, objects, components, logic, data structures, etc. that perform particular tasks or implement particular abstract data types. The computer system / server 1000 may be practiced in a distributed cloud computing environment where tasks are performed by remote processing devices that are linked through a communications network. In a distributed cloud computing environment, program modules may be located in both local and remote computer system storage media, including memory storage devices.
[0094] As shown in the figure, computer system / server 1000 is depicted in the form of a general-purpose computing device. Components of computer system / server 1000 may include, but are not limited to, one or more processors or processing units 1002, a system memory 1004, and a bus 1006 that couples various system components, including the system memory 1004, to the processor 1002. Bus 1006 represents any one or more of several bus structures, including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, and a processor bus or local bus, using any of a variety of bus architectures. By way of example, and not limitation, such architectures include an Industry Standard Architecture (ISA) bus, a Micro Channel Architecture (MCA) bus, an Enhanced ISA (EISA) bus, a Video Electronics Standards Association (VESA) local bus, and a Peripheral Component Interconnects (PCI) bus. Computer system / server 1000 typically includes a variety of computer system-readable media. Such media can be any available media that can be accessed by computer system / server 1000 and includes both volatile and nonvolatile media, removable and non-removable media.
[0095] The system memory 1004 may include computer system-readable media in the form of volatile memory, such as random access memory (RAM) 1008 and / or cache memory 1010. The computer system / server 1000 may also include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, a storage system 1012 may be provided for reading from and writing to non-removable, non-volatile magnetic media (not shown, commonly referred to as a "hard drive"). Although not shown, a magnetic disk drive may be provided for reading from and writing to removable, non-volatile magnetic disks (e.g., "floppy disks"), and an optical disk drive may be provided for reading from or writing to removable, non-volatile optical disks, such as CD-ROMs, DVD-ROMs, or other optical media. In such an example, each may be connected to the bus 1006 by one or more data media interfaces. As further depicted and described below, memory 1004 may include at least one program product having a set (e.g., at least one) of program modules configured to implement the functionality of embodiments of the present invention.
[0096] A program / utility having a set (at least one) of program modules 1016 may be stored in memory 1004, by way of example and not limitation, as well as an operating system, one or more application programs, other program modules, and program data. Each of the operating system, one or more application programs, other program modules, and program data, or any combination thereof, may include an implementation of a networking environment. The program modules 1016 generally implement the functionality and / or methodology of embodiments of the present invention described herein.
[0097] The computer system / server 1000 may communicate with one or more external devices 1018, such as a keyboard, pointing device, display 1020, one or more devices that allow a user to interact with the computer system / server 1000, or any device (e.g., a network card, modem, etc.) that allows the computer system / server 1000 to communicate with one or more other computing devices, or a combination thereof. Such communication may occur via an input / output (I / O) interface 1014. Additionally, the computer system / server 1000 may communicate with one or more networks, such as a local area network (LAN), a general wide area network (WAN), or a public network (e.g., the Internet), or a combination thereof, via a network adapter 1022. As depicted, the network adapter 1022 may communicate with other components of the computer system / server 1000 via a bus 1006. While not shown, it should be understood that other hardware and / or software components may be used in conjunction with the computer system / server 1000. Examples include, but are not limited to, microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data archival storage systems.
[0098] Additionally, the portion of the hardware secret deployment system 1000 for providing system-specific secrets to computing systems may be connected to the bus system 1006. Another computer server may incorporate other portions of the hardware secret deployment system 1000, and the two computers may be in communicative contact.
[0099] The description of various embodiments of the present invention has been presented for illustrative purposes and is not intended to be exhaustive or limited to the disclosed embodiments. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the described embodiments. The terms used herein have been selected to best explain the principles, practical applications, or technical improvements over commercially available technologies of the embodiments, or to enable those skilled in the art to understand the embodiments described herein.
[0100] The present invention may be embodied as a system, method, and / or computer program product, which may include one or more computer-readable storage media having computer-readable program instructions for causing a processor to implement aspects of the present invention.
[0101] The medium may be an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system for propagation media. Examples of computer-readable media may include semiconductor solid-state memory, magnetic tape, removable computer diskettes, random access memory (RAM), read-only memory (ROM), rigid magnetic disks, and optical disks. Current examples of optical disks include compact disk read-only memory (CD-ROM), compact disk read / write (CD R / W), DVD, and Blu-Ray disk.
[0102] A computer-readable storage medium may be a tangible device capable of retaining and storing instructions for use by an instruction execution device. A computer-readable storage medium may be, for example, but not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the above. A non-exhaustive list of more specific examples of computer-readable storage media includes portable computer diskettes, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), portable compact disc read-only memory (CD-ROM), digital versatile disc (DVD), memory sticks, floppy disks, mechanically encoded devices such as punch cards or ridge structures in grooves in which instructions are recorded, or any suitable combination of the above. The computer-readable storage medium used in this invention should not be construed as a transitory signal itself, such as an electric wave or other freely propagating electromagnetic wave, an electromagnetic wave propagating through a waveguide or other transmission medium (e.g., an optical pulse through a fiber optic cable), or an electrical signal transmitted over an electrical wire.
[0103] The computer-readable program instructions described herein may be downloaded from a computer-readable storage medium to each computing / processing device or to an external computer or storage device via a network, such as the Internet, a local area network, a wide area network, or a wireless network, or a combination thereof. The network may include copper transmission cables, optical fiber transmissions, wireless transmissions, routers, firewalls, switches, gateway computers, or edge servers, or a combination thereof. A network adapter card or network interface within each computing / processing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions to a computer-readable storage medium within the respective computing / processing device for storage.
[0104] Computer-readable program instructions for carrying out the operations of the present invention may be assembler instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state setting data, integrated circuit configuration data, or either source code or object code written in any combination of one or more programming languages, including object-oriented programming languages such as Smalltalk®, C++, and the like, and conventional procedural programming languages such as the C programming language or similar programming languages. The computer-readable program instructions may execute entirely on the user's computer, partially on the user's computer, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server, as a standalone software package. In the latter scenario, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection may be made to an external computer (e.g., through the Internet using an Internet Service Provider). In some embodiments, electronic circuitry including, for example, a programmable logic circuit, a field programmable gate array (FPGA), or a programmable logic array (PLA) may execute computer readable program instructions by utilizing state information of the computer readable program instructions to personalize the electronic circuitry to implement aspects of the present invention.
[0105] Aspects of the present invention are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-readable program instructions.
[0106] These computer-readable program instructions may be provided to a processor of a computer or other programmable data processing apparatus to produce a machine, the instructions of which, when executed by the processor of the computer or other programmable data processing apparatus, create means for performing the functions / acts specified in one or more blocks of the flowcharts and / or block diagrams. These computer-readable program instructions may be stored on a computer-readable storage medium capable of directing a computer, programmable data processing apparatus, or other device, or combination thereof, to function in a particular manner, such that the computer-readable storage medium on which the instructions are stored comprises an article of manufacture containing instructions that implement aspects of the functions / acts specified in one or more blocks of the flowcharts and / or block diagrams.
[0107] The computer-readable program instructions may be loaded into a computer, other programmable data processing apparatus, or other device to cause a series of operational steps on the computer, other programmable apparatus, or other device to produce a computer-implemented process, such that the instructions, which execute on the computer, other programmable apparatus, or other device, perform the functions / operations specified in one or more blocks of the flowcharts and / or block diagrams.
[0108] The flowcharts and block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in the flowcharts or block diagrams may represent a module, segment, or portion of an instruction set, which comprises one or more executable instructions for implementing the specified logical function(s). In some alternative implementations, the functions noted in the blocks may occur out of the order noted in the figures. For example, two blocks shown in succession may in fact be executed substantially concurrently, or the blocks may sometimes be executed in the reverse order, depending on the functionality involved. It will also be noted that each block of the block diagrams and / or flowchart diagrams, and combinations of blocks in the block diagrams and / or flowchart diagrams, may be implemented by special-purpose hardware-based systems that perform the specified functions or that operate or implement a combination of special-purpose hardware and computer instructions.
[0109] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of the invention. As used herein, the singular forms "a," "an," and "the" are intended to include the plural forms as well, unless the context clearly dictates otherwise. Furthermore, it will be understood that the terms "including" and / or "comprising," when used herein, specify the presence of stated features, integers, steps, operations, elements, or components, or combinations thereof, but do not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, or groups thereof, or combinations thereof.
[0110] Corresponding structures, materials, acts, and equivalents of all means- or step-function-added elements in the following claims are intended to encompass any structure, material, or act for performing a function in combination with other claimed elements as specifically claimed. The description of the present invention has been presented for purposes of illustration and description and is not intended to be exhaustive or limited to the invention in the form disclosed. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the described embodiments. The embodiments were chosen and described to best explain the principles and practical application of the invention and to enable those skilled in the art to understand the invention in relation to various embodiments, along with various modifications suitable for the particular uses contemplated.
Claims
1. 1. A computer-implemented method for providing a system-specific secret to a computing system having multiple computing components for secure computing, comprising: permanently storing a component-specific import key as part of a computing component upon manufacture of the computing component; storing the component-specific import key in a producing storage system; Upon receiving a request for said system-specific secret for a computing system, identifying, within the manufacturing storage system, the computing components included in the computing system; obtaining a record related to the identified computing component from the manufacturing storage system, the record including an import key specific to the component; determining the system-specific secret protected by a manufacturing hardware security module; determining a system-specific auxiliary key protected by a manufacturing hardware security module; encrypting, at the manufacturing site, the system-specific auxiliary key with the obtained component-specific import key, thereby creating an auxiliary key bundle, the auxiliary key bundle including a bundle record containing a reference to the computing component to which the component-specific import key pertains, and the system-specific auxiliary key encrypted with the component-specific import key; encrypting said system-specific secret with said system-specific auxiliary key; storing the auxiliary key bundle and a system record containing the encrypted system-specific secret in a storage medium of the computing system.
2. the auxiliary key bundle includes at least one bundle record, and the method comprises: searching, by the computing system, in the auxiliary key bundle for a bundle record containing the reference to the computing component that matches one of the computing components of the computing system; sending the system record containing the encrypted system-specific record and the found bundle record containing the system-specific auxiliary key encrypted with the component-specific import key to the computing component; decrypting, by the computing component, the encrypted computing system specific auxiliary key from the bundle record using the computing component specific import key stored on the computing component; decrypting the encrypted system-specific secret from the system-specific record using the system-specific secondary key; returning, by said computing component, said system-specific secret to firmware of said computing system; The method of claim 1 further comprising:
3. maintaining, by the manufacturer, a manufacturer signing key; Permanently storing a verification key associated with a producer signing key on the computing system, creating the bundle record, determining a signature of the system-specific secondary key encrypted with the component-specific import key and the reference to the computing component having a manufacturing signing key; determining a signature of said system record; and adding the signature of the system record to the system record; said storing including: The method of claim 2 further comprising:
4. 4. The method of claim 2 or 3, further comprising verifying, by the computing system, the bundle record and system record using the verification key stored on the computing system before accessing the system-specific secret.
5. Storing the auxiliary key bundle includes: modifying the plurality of computing components of the computing system; replacing an existing auxiliary key bundle on a storage medium that is part of the particular computing system with a new auxiliary key bundle associated with the updated version of the computing system; 4. The method according to claim 1, comprising:
6. 3. The method of claim 2, wherein the firmware to which the system-specific secret is returned is trusted firmware, and the system-specific secret is stored in memory of the computing system accessible only by this trusted firmware.
7. 7. The method of claim 6, wherein the trusted firmware is protected from access through a system management system, or an operator command of the computing system, or software not loaded onto the computing system as trusted firmware, or a combination thereof.
8. The method of claim 2 , wherein the manufacturing signing key is protected by a manufacturing hardware security module.
9. The method of claim 2 or 8, wherein the system-specific secret is a key generated and protected by a manufacturing Hardware Security Module.
10. generating said component-specific import key with a true random number generator; securely storing the component-specific import key on the computing component; sending the component-specific import key to a manufacturing hardware security module over a secure channel; importing the component-specific import key into the manufacturing hardware security module; storing the component-specific import key in the producing storage system as an object protected by the producing hardware security module; 9. The method of claim 2 or 8, further comprising:
11. storing the verification key associated with the producer signing key in the computing component; verifying, by the computing component, the signature of each encrypted system-specific secret using the verification key before decrypting the system-specific secret; The method of claim 3 further comprising:
12. The method of claim 2 or claim 8, further comprising using the system-specific secret as a base secret of a trusted execution environment for confidential computing.
13. 9. The method of claim 2 or claim 8, wherein generating a new system-specific auxiliary key for the computing system also determines a new system-specific secret, and stores a new auxiliary key bundle and a new system record containing the encrypted system-specific secret on the storage medium of the computing system.
14. 9. The method of claim 2 or claim 8, further comprising deleting the system-specific secret after storing the system record containing the system-specific secret wrapped with the secondary key on a storage medium of the computing system.
15. 1. A hardware secret deployment system for providing system-specific secrets to a computing system including a plurality of computing components for confidential computing, the system comprising: one or more processors; and a memory communicatively coupled to the one or more processors, wherein the memory stores one or more program code portions that, when executed by the one or more processors, cause the one or more processors to: permanently storing a component-specific import key as part of a computing component upon manufacture of the computing component; storing the component-specific import key in a producing storage system; Upon receiving a request for said system-specific secret for a computing system, identifying, within the manufacturing storage system, the computing components included in the computing system; obtaining a record related to the identified computing component from the manufacturing storage system, the record including a unique component-specific import key; determining the system-specific secret protected by a manufacturing hardware security module; determining a system-specific auxiliary key protected by a manufacturing hardware security module; encrypting, at the manufacturing site, the system-specific auxiliary key with the obtained component-specific import key, thereby creating an auxiliary key bundle, the auxiliary key bundle including a bundle record containing a reference to the computing component to which the component-specific import key pertains, and the system-specific auxiliary key encrypted with the component-specific import key; encrypting said system-specific secret with said system-specific auxiliary key; storing the auxiliary key bundle and a system record containing the encrypted system-specific secret on a storage medium of the computing system; This allows for a hardware covert deployment system.
16. the secret sub-key includes at least one bundle record, and the one or more program code portions, when executed by the one or more processors, cause the one or more processors to: searching, by the computing system, for a record in the auxiliary key bundle containing the reference to the computing component that matches one of the computing components of the computing system; sending the system record containing the encrypted system-specific system record and the found bundle record containing the system-specific auxiliary key encrypted with the component-specific import key to the computing component; decrypting, by the computing component, the encrypted computing system specific auxiliary key from the bundle record using the computing component specific import key stored on the computing component; decrypting the encrypted system-specific secret from the system-specific record using the system-specific secondary key; returning, by said computing component, said system-specific secret to firmware of said computing system; The system of claim 15, further comprising:
17. The one or more program code portions, when executed by the one or more processors, cause the one or more processors to: maintaining, by the manufacturer, a manufacturer signing key; and permanently storing a verification key associated with a producer signing key on the computing system, and creating the bundle record further comprises: determining a signature of the system-specific secondary key encrypted with the component-specific import key and the reference to the computing component having a manufacturing signing key; adding said signature to said bundle record; determining a signature of the system record; adding the signature of the system record to the system record; The system of claim 16 , further comprising:
18. 20. The system of claim 17, wherein the one or more program code portions, when executed by the one or more processors, also enable the one or more processors to verify the bundle record by the computing system using the verification key stored on the computing system before accessing the system-specific secret.
19. Storing the auxiliary key bundle includes: modifying the plurality of computing components of the computing system; replacing an existing auxiliary key bundle on a storage medium that is part of the particular computing system with a new auxiliary key bundle associated with the updated version of the computing system; 19. The system of claim 17 or 18, comprising:
20. 1. A computer program for providing system specific secrets to a computing system including a plurality of computing components for confidential computing, the computer program comprising: storing the component-specific import key in a producing storage system; Upon receiving a request for said system-specific secret for a computing system, identifying, within the manufacturing storage system, the computing components included in the computing system; obtaining a record related to the identified computing component from the manufacturing storage system, the record including a unique component-specific import key; determining the system-specific secret protected by a manufacturing hardware security module; determining a system-specific auxiliary key protected by a manufacturing hardware security module; encrypting, at the manufacturing site, the system-specific auxiliary key with the obtained component-specific import key, thereby creating an auxiliary key bundle, the auxiliary key bundle including a bundle record containing a reference to the computing component to which the component-specific import key pertains, and the system-specific auxiliary key encrypted with the component-specific import key; encrypting said system-specific secret with said system-specific auxiliary key; storing the auxiliary key bundle and a system record containing the encrypted system-specific secret on a storage medium of the computing system; A computer program that performs the following:
Citation Information
Patent Citations
Key setting method and key setting system
JP2009060528A
Information processing system and information processing method
JP2012142901A
Method and apparatus for key provisioning of hardware devices
JP2013545388A