Embedded Certificate Authority for IoT Device State Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Smart devices and IoT devices issued with static manufacturer certificates lack a mechanism to verify their current trusted state, making it difficult for external devices to establish secure communication channels, especially when devices are not continuously connected to a network and may be compromised with malware.

Innovation Solution

Embedding a certificate authority within the device that generates a compound certificate upon boot, chained to the manufacturer certificate, which includes measurements of the device's software and firmware state, allowing external devices to verify the device's trustworthiness and establish secure communication even without network connectivity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static manufacturer certificates are issued to smart devices, then device identification and basic security are enabled, but the ability to verify current trusted state and detect malware compromise is lost

Engineering Contradiction:
Improvedevice trust verificationVSAvoidcertificate system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent transforms the static certificate system into a dynamic one by generating a compound certificate at runtime that incorporates measurements of the device's current state (boot process, loaded code, runtime environment). This dynamic certificate reflects whether the device is running trusted code, enabling verification of the current trusted state rather than relying on a static manufacturer certificate that cannot detect malware or unauthorized modifications.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements preliminary action by measuring and recording the device state (boot process, code integrity) before generating the compound certificate. The trusted computing manager collects measurements of the runtime environment and code execution state in advance, then incorporates these measurements into the compound certificate that is presented to external devices. This preliminary measurement approach enables verification of the current trusted state without requiring continuous network connectivity to a certificate authority.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If devices are issued manufacturer certificates for secure communication, then basic authentication is enabled, but verification of current software state and detection of compromised devices is not possible

Engineering Contradiction:
Improvesecure communication verificationVSAvoidtrust verification process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges the manufacturer certificate (providing baseline authentication) with runtime measurements of the device state (providing current trust verification) into a single compound certificate. The compound certificate chains the manufacturer certificate with measurements of the boot process, loaded code, and runtime environment, allowing external devices to verify both the device's identity and its current trusted state in one authentication process, rather than requiring separate verification steps.

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If devices operate without continuous network connectivity, then device autonomy is improved, but the ability to verify trusted state and update security certificates is compromised

Engineering Contradiction:
Improvedevice autonomyVSAvoidcertificate validity verification
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements self-service by enabling devices to autonomously generate and present compound certificates that prove their trusted state without requiring continuous network connectivity to a certificate authority. The trusted computing manager on each device independently measures its own runtime state, generates the compound certificate locally, and presents it to external devices for verification. This self-service approach maintains device autonomy while enabling reliable trust verification offline.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3613192B1Device with embedded certificate authority
Publication Date: 2021.10.06 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3613192B1 patent drawingFigure 1
  • EP3613192B1 patent drawingFigure 2
  • EP3613192B1 patent drawingFigure 3

AI summary

A smart device, connected device, Internet of Things (IoT) device, etc. is configured with an embedded certificate authority. The embedded certificate authority generates a compound certificate that is signed at least by a manufacturer certificate securely stored on the device. The compound certificate includes a representation of a state of the device, which is based on one or more measurements of code executable on the device. The compound certificate may be used by an external device communicating with the smart device to determine whether the device is in a trusted state. Because the compound certificate is chained to a manufacturer certificate, the external device can communicate with the manufacturer (or an employed party) to determine whether the state of the device should be trusted.