Crypto-Processor Certification in Uncontrolled Environments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure devices face challenges in certifying new cryptographic keys generated in uncontrolled environments, as vulnerabilities in firmware make it difficult to distinguish between compromised and updated devices, leading to exposure risks.

Innovation Solution

A certification process that verifies a crypto-processor's identity by using a trusted application secret computed from shared secret data, allowing the crypto-processor to negotiate certification without exposing sensitive information, ensuring secure key generation and issuance of certificates in uncontrolled environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If firmware is updated to resolve security vulnerabilities, then security reliability is improved, but the ability to obtain certification outside controlled environment deteriorates because new keys are generated in uncontrolled environment

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidcertification capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a measurement value as an intermediary that represents the firmware state. This measurement value is used by the certifying entity to verify that the firmware has not been tampered with, enabling certification to proceed even when keys are generated outside the controlled environment. The measurement value acts as a mediator between the uncontrolled key generation environment and the certification requirement.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent performs preliminary measurement and hashing of the firmware before key generation. By pre-computing the measurement value of the firmware and using it during certification, the system ensures that the firmware state is verified in advance, allowing subsequent key generation to be certified even in uncontrolled environments.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If crypto-processor operates in uncontrolled environment, then ease of operation is improved, but security risk increases due to potential firmware vulnerabilities

Engineering Contradiction:
Improveoperational flexibilityVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements a feedback mechanism where the measurement value of the firmware is continuously verified during the certification process. The certifying entity uses the pre-computed measurement value to verify the current firmware state, providing feedback that confirms the firmware has not been compromised, thereby enabling secure operation in uncontrolled environments.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent applies preliminary anti-action by pre-computing and storing the measurement value of the firmware before deployment to uncontrolled environments. This pre-computed value serves as a protective measure that prevents acceptance of potentially compromised firmware, countering security risks before they can manifest during operation.

Inventive Principle:
Principle #9Preliminary anti-action

3Measurement precision

If certifying entity requires access to crypto-processor for certification, then measurement precision is improved, but device complexity increases due to controlled environment requirements

Engineering Contradiction:
Improvefirmware verification accuracyVSAvoidcertification process complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts the essential verification information (firmware measurement value) from the crypto-processor and uses it for certification purposes. By taking out this critical measurement data and using it as a standalone verification mechanism, the system eliminates the need for direct access to the crypto-processor during certification, simplifying the overall process while maintaining verification accuracy.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9225530B2Secure crypto-processor certification
Publication Date: 2015.12.29 MICROSOFT TECHNOLOGY LICENSING LLC
  • US9225530B2 patent drawing
  • US9225530B2 patent drawing
  • US9225530B2 patent drawing

AI summary

The subject disclosure is directed towards certifying cryptographic data for a crypto-processor outside of a controlled environment. The crypto-processor and a certifying entity maintain shared secret data for the purpose of verifying security of cryptographic key generation by the crypto-processor's firmware. In order to certify new cryptographic keys, the crypto-processor uses the shared secret data to verify the crypto-processor's firmware/hardware to the certifying entity. By protecting the shared secret data from exposure to compromised firmware, the shared secret data may be used to compute another secret conveying to the certifying entity whether the firmware can be trusted or not.