Device Authenticity via Hardware Secret Binding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial automation systems face challenges in reliably authenticating technical devices using digital certificates, requiring both the integrity of the presented proof of authorization and the authenticity of the entity presenting the certificate to be ensured.

Innovation Solution

A method involving two-factor authentication, where the integrity of identity information is checked using a digital signature, and the affiliation of the credential with the device is proven using hardware authentication information integrated into an attribute certificate, which refers to a further proof of authorization, ensuring the authenticity of the device through a hardware secret.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If digital certificates are used for device authentication, then device identity can be verified, but the integrity of the presented proof of authorization cannot be ensured

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidauthentication mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication mechanism is segmented into two distinct parts: a digital certificate for identity verification and a separate hardware authentication information (hardware secret) for integrity verification. This segmentation allows each component to fulfill its specific function without compromising the other, resolving the contradiction between authentication reliability and mechanism complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Hardware authentication information acts as an intermediary element that binds the digital certificate to the physical device. This intermediary ensures that the certificate cannot be transferred or replicated without the corresponding hardware secret, thereby ensuring integrity while maintaining a manageable authentication structure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If digital certificates are stored and used for authentication, then device identification is enabled, but the authenticity of the entity presenting the certificate cannot be ensured

Engineering Contradiction:
Improveentity authenticityVSAvoidverification process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The verification process is segmented into two steps: first verifying the digital signature of the credential issuer on the certificate, then separately verifying the hardware authentication information. This segmentation enables comprehensive authenticity verification while keeping each verification step relatively simple and manageable.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The hardware authentication information is pre-integrated into the device during manufacturing, establishing a permanent binding between the device hardware and its identity credentials. This preliminary action ensures that authenticity verification can be performed reliably without adding complex runtime verification mechanisms.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If hardware authentication information is integrated into an attribute certificate, then tamper-proof binding is achieved, but the system complexity increases

Engineering Contradiction:
Improvecertificate binding integrityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The hardware authentication information is merged with the attribute certificate structure, creating a unified authentication object that combines both identity verification and integrity verification capabilities. This merging achieves tamper-proof binding while avoiding the need for completely separate authentication systems, thereby limiting the increase in system complexity.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP3417395B1Proving authenticity of a device with the aid of proof of authorization
Publication Date: 2023.03.29 SIEMENS AG
  • EP3417395B1 patent drawingFigure 1~2
  • EP3417395B1 patent drawing
  • EP3417395B1 patent drawing

AI summary

The invention relates to a method for proving authenticity of a device with the aid of a proof of authorization of the device, wherein the proof of authorization is provided in a first step and the integrity of identity details of the proof of authorization can be checked on the basis of a digital signature of a proof of authorization issuer, and wherein the proof of authorization has an item of hardware authentication information, and affiliation of the proof of authorization to the device is proved in a second step by means of a hardware secret of the device associated with the hardware authentication information. Two-factor authentication is therefore enabled, which authentication ties authentication of the device, in particular, to the fact that a hardware-specific secret is used for the check.