Integrated Device Signing Model for HSM-Free Key Provisioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing device manufacturing processes rely on separate hardware security modules (HSMs) for signing and provisioning certificates, which incur ongoing costs and risks of key corruption, loss, or leakage, leading to reduced production capacity and revoked certificates.
Innovation Solution
Implement a device signing model where model-specific keys are stored in a trusted execution environment or secure element, using fuses to encode model information, allowing the device to function as its own HSM for generating and transmitting signed device-unique public keys for authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate hardware security modules (HSMs) are used for signing and provisioning certificates, then device authentication security is improved, but manufacturing complexity and ongoing costs increase
Solution Approach 1:
The patent extracts the HSM functionality from a separate external hardware module and integrates it directly into the device's processor system. The processor now includes built-in secure key generation, signing, and authentication capabilities, eliminating the need for separate HSM hardware while maintaining security functions.
Solution Approach 2:
The patent combines the HSM functions (key generation, signing, authentication) with the device's processor and memory systems. The secure element is integrated within the device architecture, merging previously separate security hardware with the main device components to reduce manufacturing complexity.
2Reliability
If separate hardware security modules (HSMs) are used for signing and provisioning certificates, then device authentication security is improved, but ongoing costs and key corruption risks increase
Solution Approach 1:
The device performs its own authentication and signing operations using integrated secure elements within the processor. The device self-provisions certificates and manages its own cryptographic keys without requiring external HSM services, eliminating ongoing service costs and reducing key management risks.
3Reliability
If custom software and hardware are used for provisioning devices with certificates, then security measures are improved, but manufacturing complexity increases
Solution Approach 1:
The device's processor and secure elements are pre-configured with cryptographic capabilities during device fabrication. Model-specific keys are generated and stored in secure memory during manufacturing, and fuses are blown to encode model information, enabling the device to perform self-provisioning without requiring complex custom provisioning hardware or software.
4Reliability
If model-specific keys are stored in external HSMs, then key security is improved, but device autonomy and authentication efficiency are reduced
Solution Approach 1:
The patent segments the key storage and processing functions by creating model-specific keys that are unique to each device model and storing them in dedicated secure memory regions within the processor. Each device has its own isolated secure element, enabling autonomous operation while maintaining key security through architectural isolation rather than external HSM dependency.
Data Source
AI summary
Systems and techniques are provided for secure processing. For instance, a process can include generating a model signing key, wherein the device is associated with a device model, and wherein the model signing key is shared by apparatuses of the device model; obtaining a certificate for a device-unique public key of the apparatus; signing the device-unique public key based on the model signing key; and transmitting the signed device-unique public key for authentication.


