Active Root of Trust for IoT Security Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing IoT devices lack robust security mechanisms, making them vulnerable to sophisticated attacks, and traditional roots of trust primarily function as passive components, limiting their ability to actively secure distributed devices.

Innovation Solution

A device with an active root of trust that controls and observes the control unit, enabling it to initiate security functions, communicate directly with a security computer network, and update security applications to maintain high security levels, thereby preventing obsolescence and enhancing protection against evolving threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the root of trust functions as a passive subordinate advisor, then the device complexity is reduced, but the security level deteriorates

Engineering Contradiction:
Improvesecurity levelVSAvoidcontrol structure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent inverts the traditional hierarchical relationship by making the root of trust the active controlling entity rather than the controlled subordinate. The root of trust now controls and observes the control unit, reversing the conventional architecture where the control unit dominates. This inversion enables the root of trust to actively initiate security functions and enforce security policies, thereby achieving high security levels without excessive complexity.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The root of trust acts as an intermediary between the control unit and the security computer network. It mediates security-related operations by controlling and observing the control unit while maintaining direct communication with the security computer network. This intermediary role allows the root of trust to enforce security policies and update security applications without requiring the control unit to have direct access to security mechanisms, thus maintaining security while managing complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If the root of trust is designed with fixed security functions, then the device complexity is minimized, but the adaptability to changing security requirements deteriorates

Engineering Contradiction:
Improveadaptability to security requirementsVSAvoidsystem architecture complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamics by enabling the root of trust to communicate directly with the security computer network, allowing security applications to be updated remotely. This dynamic capability means the security functions can evolve and adapt to new threats without requiring physical access to the device or complex reconfiguration. The root of trust maintains a relatively simple structure while achieving high adaptability through its connection to the external security network.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The root of trust serves multiple functions: it controls the control unit, observes device operations, initiates security functions, and receives security updates from the security computer network. This multi-functionality allows a single component to provide comprehensive security adaptability without requiring multiple specialized security modules, thereby maintaining relatively simple device architecture while achieving versatile security capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If the control unit has full control over device functions, then the ease of operation is improved, but the security control deteriorates

Engineering Contradiction:
Improvesecurity controlVSAvoidcontrol unit autonomy
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The root of trust continuously observes and controls the control unit, creating a feedback mechanism where security policies are enforced in real-time. The control unit operates autonomously for device functions but receives ongoing monitoring and control inputs from the root of trust regarding security matters. This feedback loop ensures security control is maintained without completely restricting the control unit's operational autonomy, balancing security requirements with ease of operation.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11552998B2Device and system with a root of trust
Publication Date: 2023.01.10 INFINEON TECHNOLOGIES AG
  • US11552998B2 patent drawing
  • US11552998B2 patent drawing
  • US11552998B2 patent drawing

AI summary

A device includes a root of trust and a controller to perform a device function of the device using the root of trust. The root of trust is designed to control and/or observe the controller at least partially for the performance of the device function.