Credential Security via Multi-Party Computation Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The challenge in securing IoT devices lies in protecting sensitive cryptographic credentials throughout the supply chain, where existing methods like software obfuscation offer limited protection, and hardware-based solutions are costly and complex, especially when dealing with a diverse range of devices and platforms.
Innovation Solution
A computerized system and method for securely distributing and managing cryptographic credentials using multi-party computation, where credentials are divided into shares stored on both the device and a security server, allowing authentication without ever consolidating the entire credential, and enabling remote or on-site distribution via communication modules, including internet and intermediate entity support.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If hardware-based protection is used to secure credentials, then security reliability is improved, but device complexity and manufacturing cost increase
Solution Approach 1:
The patent replaces hardware-based protection mechanisms with a software-based credential sharing system. Instead of using dedicated hardware security modules or encrypted storage, the invention uses software modules that distribute credential shares across multiple components (device memory, server, intermediate entities), eliminating the need for complex hardware modifications while maintaining security through distributed access control
Solution Approach 2:
The patent segments the credential into multiple shares that are distributed across different storage locations and system components. The full credential is never stored in a single location but is reconstructed only when needed through coordinated access by authorized parties, thereby reducing the security impact of any single point of failure without requiring enhanced hardware protection
2Reliability
If dedicated hardware is introduced for credential protection, then authentication security is improved, but manufacturing cost and board layout complexity increase
Solution Approach 1:
The patent substitutes physical hardware security measures with a software-based credential sharing architecture. The system uses standard communication interfaces and memory resources already present in IoT devices, eliminating the need for additional hardware components, board layout modifications, or specialized security chips, thereby reducing manufacturing costs while maintaining authentication security
Solution Approach 2:
The patent makes the credential sharing system universally applicable across different IoT device types and manufacturers. The software module can operate on existing device architectures without requiring model-specific hardware modifications, allowing the same credential protection mechanism to be deployed across diverse device platforms without increasing manufacturing complexity
3Ease of operation
If credentials are stored on the device, then authentication capability is improved, but vulnerability to credential compromise increases
Solution Approach 1:
The patent divides the credential into multiple shares stored at different locations (device memory, server, intermediate entities). The device stores only a portion of the credential and cannot function without the additional shares from other sources. This segmentation ensures that even if the device is compromised, the attacker cannot obtain the full credential, thereby reducing the harmful impact of credential compromise while maintaining authentication capability
Solution Approach 2:
The patent introduces intermediate entities that act as mediators in the credential sharing process. These intermediaries hold additional credential shares and facilitate the reconstruction of the full credential only when authorized. This intermediary layer adds an additional security dimension, ensuring that credentials are not solely dependent on device storage and reducing the risk of complete credential compromise
Data Source
AI summary
The subject matter discloses a method and a system for securely distributing a credential and encryption keys for physical devices. The system comprises a security server and a physical device. the physical device comprises a memory module configured to store a share of the credential, a communication module configured to exchange signals, and a processing module configured to execute calculations upon request received on a wireless manner via the communication module from the security server, the calculations are transmitted to the security server to execute a multi-party computation process. The multi-party computation process outputs two shares of the credential, a first share is stored in the physical device. The physical device does not have access to the credential.


