Device Certificate Update for Bootloader Authentication Continuity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for updating device certificates face challenges when a bootloader is changed, leading to potential errors and disruptions in device operation.
Innovation Solution
A method and device configuration involving a device identify certificate engine, first and second layers, and secure storage to generate and verify device certificates, ensuring normal operation even when the bootloader is updated, by generating unique endorsement IDs and certificate signing requests.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the bootloader is updated by the subject of usage, then the device can be modified and improved, but an error occurs while the device is driven
Solution Approach 1:
The patent applies preliminary action by generating a certificate signing request and obtaining a new certificate before the bootloader update is actually performed. The measurement value of the new bootloader is hashed and included in the certificate signing request, so that when the update occurs, the certificate chain is already prepared to verify the new bootloader's authenticity, preventing operation errors.
Solution Approach 2:
The patent implements feedback through the verification process where the measurement value of the bootloader is hashed and used to verify certificate authenticity. After bootloader update, the system verifies the new bootloader by checking if its measurement value matches the one in the certificate chain, providing feedback that confirms the update's validity and maintains operational reliability.
2Adaptability or versatility
If the first layer sub-circuit is modified, then new functionality can be implemented, but certificate verification fails
Solution Approach 1:
The patent applies preliminary action by obtaining a new certificate that includes the measurement value of the modified first layer sub-circuit before the modification is finalized. The certificate signing request contains the hash of the new measurement value, ensuring that when verification occurs, the certificate chain already reflects the modified state, allowing both modifiability and verification success.
Solution Approach 2:
The patent uses parameter changes by updating the measurement value parameter in the certificate chain to reflect the new first layer sub-circuit configuration. The measurement value is hashed and incorporated into the certificate, allowing the system to accept parameter changes (modifications) while maintaining verification integrity through the updated parameter values.
3Adaptability or versatility
If a new endorsement key is generated, then the device can be re-authenticated, but the certificate chain must be updated
Solution Approach 1:
The patent applies merging by combining the new endorsement key generation with the certificate chain update process. The measurement value of the new first layer sub-circuit (which uses the new endorsement key) is included in the certificate signing request, so that obtaining the new certificate automatically updates the certificate chain with the new endorsement key information, reducing overall complexity.
Data Source
AI summary
A device may include processing circuitry configured to, generate a device identifier associated with the device, and generate a unique endorsement identity (ID) associated with the device identifier, a first layer sub-circuit configured to, receive the device identifier, and generate a first certificate and a second certificate based on the device identifier and the unique endorsement ID, the first certificate and the second certificate including information to authenticate the device, and the processing circuitry is further configured to, receive the first certificate and the second certificate, and verify whether the device has been modified based on the first certificate and the second certificate, wherein, in response to the first layer sub-circuit being modified, the first layer sub-circuit is further configured to, generate an endorsement key based on a new unique endorsement ID, and generate a certificate signing request for the new unique endorsement ID based on the endorsement key.


