Cryptographic Hardware-Software Binding for Anti-Cloning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Original equipment manufacturers (OEMs) face revenue loss and brand equity degradation due to device cloning and unauthorized production, as well as hacking that disrupts their business models, as existing security measures like TPMs cannot control software execution or report running applications.
Innovation Solution
A cryptographically secure technique that associates authenticated OEM hardware with authenticated OEM program code, ensuring the hardware runs only authorized program code, preventing replication or alteration, and provides mechanisms for authentication, ownership transfer, and security key updates.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If TPM is used for security processes, then digital signature and key exchange are protected, but the system cannot control software execution or report running applications
Solution Approach 1:
The patent combines the TPM hardware security module with a software execution control mechanism. The TPM provides cryptographic protection while the integrated control mechanism monitors and manages software execution, creating a unified system that delivers both security process protection and software execution control capabilities
Solution Approach 2:
The invention creates a multi-functional security system that performs multiple roles: cryptographic operations (digital signature and key exchange), software execution control, and system status reporting. This universal system addresses the limitation of TPM by adding software execution control and monitoring capabilities to the existing security functions
2Ease of manufacture
If hardware designs are copied for clone systems, then lower cost systems are produced, but revenue and brand equity are lost
Solution Approach 1:
The patent implements asymmetric cryptographic association between hardware and software, where each OEM system has unique cryptographic credentials. This asymmetric security model prevents cloning because copied hardware cannot replicate the unique cryptographic relationship, thereby protecting OEM revenue while allowing legitimate manufacturing
Solution Approach 2:
The invention uses cryptographic copying protection by associating software licenses with specific hardware identifiers. While physical hardware can be copied, the cryptographic association prevents unauthorized software from running on cloned hardware, maintaining revenue protection even when manufacturing ease increases
3Productivity
If software is copied for non-branded systems, then complete systems are offered at very low cost, but brand equity is degraded
Solution Approach 1:
The patent introduces cryptographic authentication as an intermediary layer between hardware and software. This intermediary verification mechanism ensures that even low-cost systems can only run authenticated software, preventing brand equity degradation while allowing affordable system deployment through legitimate licensing
Data Source
AI summary
Authenticated hardware and authenticated software are cryptographically associated using symmetric and asymmetric cryptography. Cryptographically binding the hardware and software ensures that original equipment manufacturer (OEM) hardware will only run OEM software. Cryptographically binding the hardware and software protects the OEM binary code so it will only run on the OEM hardware and cannot be replicated or altered to operate on unauthorized hardware. In one embodiment, critical security information associated with the equipment is loaded from a memory at startup time. The critical security information is stored in the memory, in encrypted form, using a unique secret value. The secret value is used to retrieve a chip encryption key and one or more image authentication keys that can be used to associate program code with an original equipment manufacturer. These keys are used to authenticate the program code.


