Distributed Device Certificate Enrollment via Secure Execution Environment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing public key infrastructure (PKI) for issuing device certificates is complex and costly, requiring multiple certificate authorities (CAs) and constraining certificate creation to manufacturing and repair facilities, making it difficult to manage cryptographic keys and issue certificates for large numbers of devices.
Innovation Solution
A processor-based apparatus with a secure execution environment that generates device certificates using a hardware unique key and a class key, allowing for the derivation of a device key pair and certificate signing key, enabling devices to self-issue certificates validated by a certificate authority without needing to return to a manufacturing or repair facility.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a traditional PKI with multiple CAs is used to issue device certificates, then certificate security and trust are improved, but system complexity and cost increase significantly
Solution Approach 1:
The patent segments the certificate issuance function by separating the CA private key from the certificate signing operation. The CA private key remains securely stored in the root CA system, while authorized devices can perform certificate signing operations locally using derived signing keys that do not require the master CA private key. This segmentation allows distributed certificate issuance while maintaining centralised trust.
Solution Approach 2:
The patent enables devices to self-issue certificates by providing them with the capability to derive certificate signing keys locally and sign certificates autonomously. Devices can generate their own device key pairs, derive signing keys from the CA public key and device identity, and create valid certificates without requiring physical presence at a CA facility or communication with the root CA system.
2Ease of manufacture
If CAs are located only at manufacturing and repair facilities, then certificate issuance control is improved, but device lifecycle management becomes complicated and costly
Solution Approach 1:
The patent applies preliminary action by embedding the CA public key and certificate issuance algorithms into devices during manufacturing. This preliminary configuration enables devices to perform self-signed certificate operations throughout their entire lifecycle without requiring subsequent physical visits to CA facilities. The device is pre-equipped with all necessary cryptographic materials and algorithms to autonomously manage its certificates.
Solution Approach 2:
The patent makes the device universally capable of certificate issuance by integrating the CA public key and signing algorithms into the device itself. The device can perform multiple functions including key pair generation, certificate signing, and certificate validation, eliminating the need for specialised CA facilities. This multi-functionality allows any device to act as its own certificate authority for device-to-device communications.
3Ease of operation
If distributed certificate enrollment is implemented, then operational simplicity and cost are improved, but cryptographic security requirements increase
Solution Approach 1:
The patent segments cryptographic functions by separating key generation, key storage, and certificate signing operations. The CA public key is stored securely in the device, while the CA private key remains in the root CA system. Signing keys are derived locally from the CA public key and device identity without exposing the master private key. This segmentation enables distributed operations while maintaining strong cryptographic security through proper key management.
Data Source
AI summary
An apparatus including a processor and a memory, where the processor and the memory are configured to provide a secure execution environment and the memory stores a hardware unique key and a class key. The processor is configured to recover, in the secure execution environment, a certificate signing key based on the class key, where the certificate signing key is associated with a certificate authority. The processor is further configured to derive a device key pair based on the hardware unique key, where the device key pair includes a device public key and a device private key, and generate a device certificate based on the device public key and the certificate signing key. The generated device certificate is configured to be validated based on a public key associated with the certificate authority.


