Embedded System Identity And Root Key Derivation for Secure Boot
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Embedded devices face challenges in securely managing encryption keys during the boot process to prevent unauthorized software execution and protect against malicious actors, especially when executing software from multiple parties.
Innovation Solution
A method is described for deriving silicon-specific and device-specific cryptographic identities and root keys using a key manager that implements symmetric key management, software binding, and key versioning, ensuring secure boot processes by generating keys that are static or updated based on software configurations, and storing root secrets in different components to mitigate key extraction attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If complex validation processes with various encryption keys are implemented to protect against unauthorized software execution, then security is improved, but device complexity increases
Solution Approach 1:
The patent segments the key management process into distinct phases: root key generation in secure hardware, identity key derivation for different software layers, and hierarchical key relationships. This segmentation organizes the complex validation process into manageable components while maintaining security.
Solution Approach 2:
The patent implements preliminary action by generating root keys during manufacturing in secure hardware before the device is deployed. This pre-established trust foundation enables subsequent validation processes without requiring complex real-time key generation, simplifying the operational complexity.
2Reliability
If encryption keys are managed and protected during the boot process to prevent malicious access, then security is improved, but the boot process duration increases
Solution Approach 1:
The patent performs key generation and initial validation operations during the manufacturing process and boot ROM execution phase, before the main boot process begins. This preliminary establishment of security credentials enables faster subsequent validation steps during the actual boot process.
Solution Approach 2:
The patent implements dynamic key derivation where identity keys are generated on-demand based on the validation needs of different software layers. Rather than statically managing all keys throughout the boot process, the system dynamically derives only the necessary keys at each stage, reducing overall processing time.
3Adaptability or versatility
If multiple encryption keys are used to validate software from multiple parties, then adaptability is improved, but key management complexity increases
Solution Approach 1:
The patent implements a universal hierarchical key structure where a single root key can derive multiple identity keys for different software parties (silicon designer, device manufacturer, etc.). This multi-functional key hierarchy enables the system to handle software from multiple parties using a unified management approach rather than separate key systems for each party.
Solution Approach 2:
The patent introduces identity keys as intermediary elements between the root key and specific software validation. These identity keys act as mediators that represent different software parties without requiring direct management of multiple root-level keys, simplifying the key management structure while maintaining adaptability.
Data Source
AI summary
This document describes systems and techniques for deriving identity and root keys for embedded systems. In aspects, a boot process and key manager of an embedded system may implement a secure or trusted boot process for embedded systems in which code of next-level boot loader or software image is verified using root keys or other protected information before execution of the boot process is passed to the next stage in the boot process. Alternatively or additionally, the key manager may enable sealing and attestation of various levels of root and identity keys to enable respective verification of software or hardware throughout a life cycle of a device to prevent unauthorized access to protected or private code of an embedded system. By so doing, the described aspects may enable an embedded system with a secure boot process and robust identity and root key management system.


