Cryptographic Hardware-Software Binding for Anti-Cloning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Original equipment manufacturers (OEMs) face revenue loss and brand equity degradation due to device cloning and unauthorized production, as well as hacking that disrupts their business models, as existing security measures like TPMs cannot control software execution or report running applications.

Innovation Solution

A cryptographically secure technique that associates authenticated OEM hardware with authenticated OEM program code, ensuring the hardware runs only authorized program code, preventing replication or alteration, and provides mechanisms for authentication, ownership transfer, and security key updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If TPM is used for security processes, then digital signature and key exchange are protected, but the system cannot control software execution or report running applications

Engineering Contradiction:
Improvesecurity process protectionVSAvoidsoftware execution control capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent combines the TPM hardware security module with a software execution control mechanism. The TPM provides cryptographic protection while the integrated control mechanism monitors and manages software execution, creating a unified system that delivers both security process protection and software execution control capabilities

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The invention creates a multi-functional security system that performs multiple roles: cryptographic operations (digital signature and key exchange), software execution control, and system status reporting. This universal system addresses the limitation of TPM by adding software execution control and monitoring capabilities to the existing security functions

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of manufacture

If hardware designs are copied for clone systems, then lower cost systems are produced, but revenue and brand equity are lost

Engineering Contradiction:
Improveclone system productionVSAvoidOEM revenue protection
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent implements asymmetric cryptographic association between hardware and software, where each OEM system has unique cryptographic credentials. This asymmetric security model prevents cloning because copied hardware cannot replicate the unique cryptographic relationship, thereby protecting OEM revenue while allowing legitimate manufacturing

Inventive Principle:
Principle #4Asymmetry

Solution Approach 2:

The invention uses cryptographic copying protection by associating software licenses with specific hardware identifiers. While physical hardware can be copied, the cryptographic association prevents unauthorized software from running on cloned hardware, maintaining revenue protection even when manufacturing ease increases

Inventive Principle:
Principle #26Copying

3Productivity

If software is copied for non-branded systems, then complete systems are offered at very low cost, but brand equity is degraded

Engineering Contradiction:
Improvesystem deployment costVSAvoidbrand equity degradation
Core Design Contradiction:
ProductivityVSObject-generated harmful factors

Solution Approach 1:

The patent introduces cryptographic authentication as an intermediary layer between hardware and software. This intermediary verification mechanism ensures that even low-cost systems can only run authenticated software, preventing brand equity degradation while allowing affordable system deployment through legitimate licensing

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9602282B2Secure software and hardware association technique
Publication Date: 2017.03.21 MARVELL ASIA PTE LTD
  • US9602282B2 patent drawing
  • US9602282B2 patent drawing
  • US9602282B2 patent drawing

AI summary

Authenticated hardware and authenticated software are cryptographically associated using symmetric and asymmetric cryptography. Cryptographically binding the hardware and software ensures that original equipment manufacturer (OEM) hardware will only run OEM software. Cryptographically binding the hardware and software protects the OEM binary code so it will only run on the OEM hardware and cannot be replicated or altered to operate on unauthorized hardware. In one embodiment, critical security information associated with the equipment is loaded from a memory at startup time. The critical security information is stored in the memory, in encrypted form, using a unique secret value. The secret value is used to retrieve a chip encryption key and one or more image authentication keys that can be used to associate program code with an original equipment manufacturer. These keys are used to authenticate the program code.