Compounded Intrinsic Identity for IHS Tamper Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Selecting a single semiconductor device to represent the identity of an Information Handling System (IHS) can lead to security issues, such as when the identity of the IHS is compromised or misconfigured, as it can facilitate unauthorized access and tampering, and existing systems fail to provide a comprehensive solution for managing and verifying the identity of the IHS.
Innovation Solution
The system and method produce a Compounded Intrinsic Identity (CIIS) for IHSs, which involves receiving indications of unique physical or electrical aspects of multiple components, combining them through one-way mathematical operations and Key Derivation Functions (KDFs) to create a cryptographic key pair, including immutable and mutable variables, to uniquely identify the IHS and detect tampering.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a single semiconductor device is selected to represent the IHS identity, then the identity management is simplified, but security is compromised because the device can be removed and transferred to another IHS
Solution Approach 1:
The patent divides the IHS identity into multiple segments, each tied to different semiconductor devices within the system. Instead of relying on a single device, the identity is distributed across multiple components, making it impossible for one device to represent the entire system's identity alone. This segmentation prevents device theft and unauthorized transfer while maintaining manageable identity verification through collective validation.
2Reliability
If multiple components are combined to create a compounded identity, then security is improved, but the system complexity increases
Solution Approach 1:
The patent introduces a management controller as an intermediary that handles the complexity of compounded identity management. This controller collects identity information from multiple semiconductor devices, processes it through deterministic algorithms, and manages the verification process. By placing this intermediary in charge, the system achieves high security through multiple components while the intermediary absorbs and manages the operational complexity.
Solution Approach 2:
The patent creates a deterministic copy or representation of the compounded identity from multiple physical devices. Instead of directly managing the complexity of multiple hardware components, the system generates a unified identity representation that can be verified without repeatedly accessing all original components. This copying mechanism simplifies verification while maintaining the security benefits of multi-component identity.
Data Source
AI summary
Systems and methods for producing, using, and managing Compounded Intrinsic Identities (CIIS) for Information Handling Systems (IHSs) are described. In an illustrative, non-limiting embodiment, an IHS may include a processor and a memory coupled to the processor, the memory having program instructions stored thereon that, upon execution by the processor, cause the IHS to: receive a first indication of a first variable associated with a unique physical or electrical aspect of a first IHS component, receive a second indication of a second variable associated with a unique physical or electrical aspect of a second IHS component, and produce at least one identity seed associated with the IHS based, at least in part, upon a combination of the first and second indications.


