Authentication Device Lifecycle Management via Secret Key Deletion

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The management of authentication devices becomes challenging when components are scrapped, as the authentication devices can be reused with counterfeit components or enter the market as counterfeit products, posing risks to performance and safety.

Innovation Solution

A mechanism is introduced to delete the secret key from authentication devices and generate an attestation message, ensuring the device cannot authenticate other components, which is initiated by a password and verified by an audit authority.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If authentication devices are removed from scrapped components for reuse, then resource efficiency is improved, but security is worsened as the devices may be used with counterfeit components

Engineering Contradiction:
Improveresource efficiencyVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The secret key is extracted and deleted from the authentication device's memory, separating the cryptographic credentials from the hardware. This allows the physical device to be reused while the security credentials are permanently removed, resolving the contradiction between resource efficiency and security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs preliminary destruction of the secret key before the authentication device can be reused or transferred to counterfeit components. By proactively deleting the credentials and generating attestation of deletion, the system prevents potential security misuse while allowing hardware reuse.

Inventive Principle:
Principle #9Preliminary anti-action

2Reliability

If secret keys are deleted from authentication devices to prevent counterfeit use, then security is improved, but device functionality is worsened as the device can no longer authenticate components

Engineering Contradiction:
ImprovesecurityVSAvoiddevice functionality
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The authentication device is designed with a disposable secret key that can be permanently deleted. The device itself may be reused as a generic authentication hardware platform, but the cryptographic credentials are single-use and irreversibly removed after deletion, allowing security without compromising the underlying device functionality for legitimate purposes.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The deletion operation targets specifically the secret key storage region in the device memory, leaving other functional components of the authentication device intact. This localized destruction of only the cryptographic credentials maintains device functionality for authorized operations while eliminating security risks from unauthorized reuse.

Inventive Principle:
Principle #3Local quality

3Loss of information

If attestation mechanisms are implemented to verify secret key deletion, then auditability is improved, but device complexity is worsened

Engineering Contradiction:
ImproveauditabilityVSAvoiddevice complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The system introduces an intermediary attestation mechanism that provides verifiable proof of secret key deletion without requiring complex continuous monitoring or management infrastructure. The attestation serves as a simplified mediator between the deletion operation and audit requirements, reducing overall system complexity while improving auditability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2603875B1A mechanism for managing authentication device lifecycles
Publication Date: 2016.06.15 CERTICOM CORP
  • EP2603875B1 patent drawingFigure 1
  • EP2603875B1 patent drawingFigure 2~3
  • EP2603875B1 patent drawingFigure 4

AI summary

An authentication device is used to authenticate a component to a product using a secret key. The life cycle of the authentication device is controlled by selective deletion of the secret key. An attestation message is sent by the authentication device upon deletion of the secret key. Authentication devices from faulty components or over supply of the authentication devices ma}' be rendered inoperable and audited.