DICE 3-Layer Key Architecture for Firmware Updates Without DeviceID Change

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Issuing a new DeviceID certificate during firmware updates in a DICE architecture can waste resources and increase deployment complexity, and ad hoc issuance may cause security issues.

Innovation Solution

Implementing a DICE 3-layer architecture that separates firmware updates between DICE layer 0 and DICE layer 1, where updates occur at layer 1 without changing the DeviceID or associated DICE identity key, maintaining an intact Chain of Trust.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a new DeviceID certificate is issued during firmware updates, then the firmware can be updated with new features or security fixes, but resources are wasted and deployment complexity increases

Engineering Contradiction:
Improvefirmware update capabilityVSAvoiddeployment complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the DICE architecture into multiple layers (DICE layer 0, DICE layer 1, and DICE layer 2) with different update characteristics. DICE layer 0 contains the immutable DeviceID and DICE identity key, while DICE layers 1 and 2 contain updatable firmware components. This segmentation allows firmware updates without requiring new DeviceID certificates, reducing deployment complexity while maintaining update capability.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If a new DeviceID certificate is issued during firmware updates, then the firmware can be updated, but security issues may arise from ad hoc issuance

Engineering Contradiction:
Improvefirmware update capabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

By segmenting the DICE architecture into immutable layer 0 (DeviceID) and updatable layers 1-2, the patent eliminates the need for ad hoc DeviceID certificate issuance. The Chain of Trust remains intact because the immutable DeviceID in layer 0 continues to verify the updated firmware in layers 1-2 through the established measurement and verification process, maintaining security while enabling updates.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary actions by establishing the Chain of Trust and DeviceID verification mechanisms during device provisioning before any firmware updates occur. The DICE layer 0 is provisioned with the DeviceID and DICE identity key in advance, creating a stable foundation that can verify future firmware updates without requiring new certificates, thus preventing security issues from ad hoc issuance.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If the DeviceID is changed during firmware updates, then the firmware can be updated, but the Chain of Trust is disrupted

Engineering Contradiction:
Improvefirmware update capabilityVSAvoidChain of Trust integrity
Core Design Contradiction:
Adaptability or versatilityVSStability of the object's composition

Solution Approach 1:

The patent segments the DICE architecture so that DICE layer 0 (containing the DeviceID) is separated from DICE layers 1-2 (containing updatable firmware). This segmentation allows the Chain of Trust to remain stable because the immutable DeviceID in layer 0 continues to serve as the root of trust, while updates in layers 1-2 are verified through measurements against this stable foundation, enabling updates without disrupting the Chain of Trust.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20260046144A1Device identifier composition engine 3-layer architecture
Publication Date: 2026.02.12 MICRON TECHNOLOGY INC
  • US20260046144A1 patent drawing
  • US20260046144A1 patent drawing
  • US20260046144A1 patent drawing

AI summary

Implementations described herein relate to a device identifier composition engine (DICE) 3-layer architecture. In some implementations, a device may include a secure computing environment including a hardware root of trust (HRoT) DICE component. The secure computing environment may include a DICE layer 0 component configured to derive a DICE identity key. The secure computing environment may include a DICE layer 1 component configured to derive a DICE alias key based on the DICE identity key. The secure computing environment may include a controller configured to receive an update to firmware of a component. The controller may be configured to update the firmware of the component based on receiving the update. The controller may be configured to update one or more keys of the component or one or more keys of one or more components above the component in a layer stack.