Authentication Device Secret Provisioning via Firmware Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Root-of-Trust (RoT) devices are vulnerable to malicious provisioning, allowing attackers to compromise the Unique Device Secrets (UDS), leading to unauthorized attestation and loss of trustworthiness.

Innovation Solution

Secure provisioning of UDS is ensured by cryptographically verifying firmware using trustworthy hardware, and only allowing verified firmware to access or write UDS, with hardware ensuring that only intended firmware can derive the Composite Device Identifier (CDI).

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If firmware is allowed to provision UDS without verification, then provisioning is simple and fast, but security is compromised and malicious provisioning can occur

Engineering Contradiction:
ImprovesecurityVSAvoidprovisioning process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by verifying firmware integrity before allowing UDS provisioning. The hardware checks firmware against a known good key during the boot process, before any provisioning operations can occur. This prevents malicious firmware from executing provisioning code, while still allowing legitimate firmware to proceed with standard provisioning workflows.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary verification mechanism where hardware acts as a mediator between firmware and UDS provisioning. The hardware cryptographically verifies firmware and controls access to provisioning functions based on verification results. This intermediary layer ensures security without requiring complex changes to the overall provisioning architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If hardware hermetically provisions UDS without firmware access, then security is maximized, but firmware cannot perform necessary operations on provisioned secrets

Engineering Contradiction:
ImprovesecurityVSAvoidfirmware access capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies local quality by providing different access levels to different firmware components based on their trustworthiness. Verified firmware is granted specific access rights to perform necessary operations on provisioned secrets, while unverified or malicious firmware is denied access. This selective access control maintains both security and operational functionality.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes the state parameter of firmware from unverified to verified through cryptographic authentication. This parameter change triggers different access behaviors: unverified firmware cannot access provisioning functions, while verified firmware gains controlled access. The hardware dynamically adjusts access permissions based on the verification state.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12367288B2Securely provisioning secrets in authentication devices
Publication Date: 2025.07.22 GOOGLE LLC
  • US12367288B2 patent drawing
  • US12367288B2 patent drawing
  • US12367288B2 patent drawing

AI summary

The present disclosure provides for increased security of root of trust (RoT) chips by preventing malicious provisioning. Unique device secrets (UDS) can only be provisioned securely by trustworthy hardware or trustworthy firmware. Entities other than the trustworthy hardware and trustworthy firmware do not have access to a composite device identifier (CDI) generated using the UDS and firmware measurements.