Erasing Cryptographic Items for Secure Mode Switching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Devices operating in restricted modes, such as those conforming to Federal Information Processing Standard (FIPS) 140, face challenges when switching to non-restricted modes, as modifications made during the switch can persist, causing the device to no longer meet standard requirements upon returning to the restricted mode, compromising security.
Innovation Solution
Erase a cryptographic item, specifically a signed device identification, from the device's memory when switching from a restricted to a non-restricted operating mode, ensuring the device cannot revert to the restricted mode without external reset, thus maintaining compliance with security standards.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the device switches from restricted mode to non-restricted mode to provide enhanced functionality, then the device can perform more operations, but modifications made during the switch persist and cause the device to no longer meet standard requirements when returning to restricted mode
Solution Approach 1:
The patent applies preliminary action by erasing the cryptographic item from memory before the device switches from restricted mode to non-restricted mode. This proactive measure ensures that no residual cryptographic data remains that could compromise security compliance when the device later returns to restricted mode, thus preventing the persistence problem described in the contradiction.
Solution Approach 2:
The patent utilizes parameter changes by modifying the state of the cryptographic item in memory based on the operating mode. When switching modes, the system changes the presence state of the cryptographic item (from present to erased), creating a detectable parameter change that indicates mode transition and prevents ambiguity about the device's compliance status.
2Reliability
If the device maintains cryptographic items in memory for restricted mode operation, then security compliance is ensured, but the device cannot safely switch to non-restricted mode without risking future compliance violations
Solution Approach 1:
The patent applies preliminary action by erasing the cryptographic item from memory before the device switches from restricted mode to non-restricted mode. This proactive measure ensures that no residual cryptographic data remains that could compromise security compliance when the device later returns to restricted mode, thus preventing the persistence problem described in the contradiction.
Solution Approach 2:
The patent applies preliminary anti-action by erasing the cryptographic item before mode switching occurs. This counter-action prevents the potential harmful effect of residual cryptographic data persisting in memory, which would otherwise prevent safe mode switching and compromise future security compliance.
3Reliability
If the device erases cryptographic items when switching modes, then security compliance is maintained, but the device loses the ability to verify its identity and cryptographic operations cannot be performed
Solution Approach 1:
The patent applies preliminary action by erasing the cryptographic item from memory before the device switches from restricted mode to non-restricted mode. This proactive measure ensures that no residual cryptographic data remains that could compromise security compliance when the device later returns to restricted mode, thus preventing the persistence problem described in the contradiction.
Solution Approach 2:
The patent applies dynamics by making the presence of the cryptographic item in memory dynamic rather than static. The cryptographic item is present in memory during restricted mode operations but is erased when switching to non-restricted mode, allowing the system to adapt its cryptographic capabilities based on the current operating mode while maintaining security compliance.
Data Source
AI summary
The technology disclosed herein enables a method to receive an indication of a change to an operating mode of a device from a first operating mode to a second operating mode, and identify a cryptographic item stored at a memory of the device, wherein the cryptographic item corresponds to an identification of the device signed with a digital signature, and wherein the digital signature is based on a private key that is inaccessible to the device. On response to receiving the indication of the change to the operating mode of the device, the method can modify the cryptographic item stored at the memory, and operate the device in the second operating mode based on the modified cryptographic item. The indication of the change to the operating mode of the device can correspond to a detection of a change in a function of the device.


