Device Identity Provisioning via External Trust Authority
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing digital security systems for devices lack the ability to obtain and update identity data from external trust authorities, particularly in scenarios where digital certificates expire or need replacement, often requiring device recall for updates, which disrupts services and lacks secure encryption mechanisms.
Innovation Solution
A flexible identity data management system that allows device vendors and network operators to update identity data on devices before or after deployment by using a One Time Programmable Key (OTP Key) bound to a component identifier, enabling secure encryption and decryption of new identity data through an External Trust Authority, ensuring only authorized devices can access and install the updates.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If identity data is provisioned on devices before deployment in factory, then device security is established, but device recall is required for updates which disrupts service
Solution Approach 1:
The system performs preliminary actions by provisioning devices with cryptographic materials (OTP keys, component identifiers) and establishing update infrastructure before deployment. This allows seamless over-the-air updates without service disruption, as the device recall problem is preemptively solved by preparing the update mechanism in advance.
Solution Approach 2:
An external trust authority acts as an intermediary between device vendors and deployed devices. This intermediary provides secure identity data and updates over-the-air, eliminating the need for physical device recall while maintaining security. The intermediary enables updates to be pushed remotely to deployed devices.
2Productivity
If identity data is updated after device deployment, then service continuity is maintained, but secure encryption mechanism is lacking
Solution Approach 1:
Each device is provisioned with unique local cryptographic materials including OTP keys and component identifiers that are specific to that device. This local quality ensures that encryption security is device-specific and cannot be compromised by updates to other devices, maintaining security while enabling post-deployment updates.
Solution Approach 2:
Cryptographic materials are preliminarily provisioned on devices before deployment, including OTP keys and component identifiers. This preliminary setup establishes a secure foundation that enables encrypted over-the-air updates later, combining the benefits of pre-deployment security with post-deployment update capability.
3Adaptability or versatility
If external trust authority is used to provide identity data, then identity data freshness is improved, but device complexity increases
Solution Approach 1:
An external trust authority serves as a centralized intermediary that manages identity data for multiple devices. This approach improves identity data freshness and adaptability while avoiding the need for each device to have complex self-management capabilities. The complexity is centralized in the trust authority rather than distributed to devices.
Data Source
AI summary
A method is provided for updating identity data on devices. The method provides for acquiring a device comprising a component associated with a component identifier and having a One Time Programmable Key installed on the component, submitting the component identifier and the One Time Programmable Key to an External Trust Authority, receiving new identity data tied to the component identifier from the External Trust Authority that is encrypted with the One Time Programmable Key, loading the new identity data onto an Update Server, receiving a request at the Update Server from the device that requests new identity data, and providing the new identity data upon receipt of the request, upon which the device decrypts and installs the identity data using the One Time Programmable Key installed on the component within the device.


