Attestation Device Security via Volatile Secret Erasure

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge lies in providing effective security solutions for portable computing devices, particularly in scenarios where high-powered devices are not justified by the value of the payload, and simplified devices lack the memory and processing power to support traditional security measures, making them vulnerable to malicious attacks and data integrity compromises.

Innovation Solution

A system comprising attestation devices with volatile memory segments for secure secret storage, gateway devices for communication and data forwarding, and a backend management system for verifying integrity through attestation data, which ensures that devices remain secure even if power is lost, using cryptographic hashes and custody transfer protocols to maintain data integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security measures are implemented in simplified devices, then security protection is improved, but device complexity and resource requirements increase beyond what simplified devices can support

Engineering Contradiction:
Improvesecurity protectionVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security-critical secret data from the simplified device and stores it in a separate secure element or hardware module. This allows the main device to remain simple while the extracted security function provides robust protection. The secret is provisioned once and then used for cryptographic operations without being stored in plain text or requiring complex security management in the simplified device.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary secure element or hardware module that acts as a mediator between the simplified device and the security requirements. This intermediary handles the complex cryptographic operations and secret management, allowing the simplified device to achieve strong security without directly implementing complex security mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If high-powered devices with traditional security measures are used, then security is improved, but cost and computational resources increase making them unjustified for low-value payloads

Engineering Contradiction:
Improvesecurity protectionVSAvoidcomputational resources
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent employs lightweight cryptographic algorithms and simplified security mechanisms that can be implemented in low-cost, resource-constrained devices. The security solution is designed to be disposable or single-use in many cases, where the device can be replaced rather than secured against sophisticated attacks, reducing the need for expensive security hardware while maintaining adequate protection for low-value payloads.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The patent changes the cryptographic parameters and algorithms used from traditional heavy-weight methods to lightweight variants optimized for resource-constrained environments. This includes using elliptic curve cryptography instead of RSA, implementing simplified key management protocols, and using cryptographic hash functions designed for embedded systems, thereby achieving acceptable security with minimal computational resources.

Inventive Principle:
Principle #35Parameter changes

3Object-affected harmful factors

If volatile memory is used for secret storage, then security against persistent attacks is improved (secrets are erased on power loss), but reliability under power interruptions is worsened

Engineering Contradiction:
Improveprotection against persistent attacksVSAvoidreliability under power interruptions
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent implements prior cushioning by provisioning the secret data once in a secure manner and then using cryptographic techniques to derive multiple keys and credentials from that single secret. This way, even if power is lost and the volatile memory is cleared, the system can reconstruct necessary cryptographic material through key derivation functions, cushioning against the harmful effect of power interruptions while maintaining security.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Solution Approach 2:

The patent performs preliminary action by pre-computing and storing cryptographic parameters, key derivation seeds, and authentication credentials in secure non-volatile storage before power loss can occur. The actual secret remains in volatile memory for security, but the preliminary cryptographic setup allows the system to recover functionality after power restoration without exposing the core secret.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10044696B2Simplified sensor integrity
Publication Date: 2018.08.07 MCAFEE LLC
  • US10044696B2 patent drawing
  • US10044696B2 patent drawing
  • US10044696B2 patent drawing

AI summary

An apparatus is provided that includes at least one processor device, an energy storage module to power the apparatus, memory to store a secret such that powering down and restarting the apparatus causes the secret to be lost, logic executable by the at least one processor device to generate attestation data using the secret that data abstracts the secret, and a communications interface to send the attestation data to another device.