Cryptographic Co-Dependency Across Multiple Roots of Trust for IoT Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a growing need for robust security measures in IoT devices deployed at public locations to protect against electronic attacks and misuse, as adversaries can potentially gain physical access over their deployment lifetime, necessitating secure cryptographic defenses.

Innovation Solution

Implementing multiple roots of trust with cryptographic co-dependency, using a trusted execution environment (TEE) and a cryptographic subsystem, where each root attests to authorize sensitive operations, ensuring security even if one is compromised.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple roots of trust with cryptographic co-dependency are implemented, then security reliability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides the root of trust into multiple independent segments (first root of trust and second root of trust), each residing in separate hardware modules. This segmentation allows each root to independently generate digital signatures, and the system requires both signatures for sensitive operations, thereby improving security reliability while managing complexity through modular architecture

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a composite security architecture by combining multiple roots of trust with different cryptographic capabilities. The first root of trust and second root of trust work together as a composite system, where each provides unique cryptographic functions and both are required for authorization, achieving enhanced security through composition rather than single-component solutions

Inventive Principle:
Principle #40Composite materials

2Object-affected harmful factors

If cryptographic co-dependency is enforced across multiple roots of trust, then security against physical access is improved, but operational complexity increases

Engineering Contradiction:
Improveprotection against physical accessVSAvoidoperational complexity
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system preemptively counteracts potential physical access attacks by requiring cryptographic signatures from multiple independent roots of trust before allowing sensitive operations. This preliminary anti-action ensures that even if an adversary gains physical access to the device, they cannot perform operations without compromising both roots of trust simultaneously, which is designed to be infeasible

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent introduces a backend system as an intermediary that coordinates the cryptographic verification process. The backend system receives requests, validates digital signatures from both roots of trust, and authorizes operations based on the co-dependent verification results, thereby managing operational complexity centrally rather than requiring complex local coordination

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12411938B1Systems and methods for utilizing cryptographic co-dependency across multiple roots of trust
Publication Date: 2025.09.09 AMAZON TECH INC
  • US12411938B1 patent drawing
  • US12411938B1 patent drawing
  • US12411938B1 patent drawing

AI summary

Systems, devices, and methods are provided for cryptographic co-dependent across multiple roots of trust. A device may comprise two or more co-dependent roots of trust, such as a trusted execution environment (TEE) of a main application processor and a cryptographic subsystem comprising a cryptographic processor. A server may validate digital signatures generated by each co-dependent root of trust that is known for the device and then provide the device with cryptographic material that can be used to establish a shared secret. The shared secret may be used by the device to request the performance of a sensitive operation.