Factory Data Security via Distributed Storage and Hash Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The use of dedicated nonvolatile memory devices for storing calibration and provisioning data in electronic devices increases manufacturing costs and may not be cost-effective due to limited memory capacity, necessitating a more efficient method for storing and managing factory-generated data.
Innovation Solution
A system and method for securely generating, storing, and distributing factory-generated calibration and provisioning data using a networked factory data service, where calibration data is stored on a distributed storage system and retrieved during device assembly, allowing for larger datasets and secure authentication and updating of data post-manufacturing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If dedicated nonvolatile memory devices are used to store calibration and provisioning data, then security and accessibility control are improved, but manufacturing cost increases
Solution Approach 1:
The patent creates a cryptographic copy (hash) of the calibration data and stores it in a secure region of the flash memory, while the actual calibration data can be stored elsewhere. This copying approach maintains security without requiring dedicated secure memory devices, thereby reducing manufacturing costs while preserving security requirements.
Solution Approach 2:
The patent introduces a cryptographic hash function as an intermediary mechanism. Instead of directly storing and accessing calibration data in dedicated secure memory, the system uses hash verification as an intermediate step to ensure data integrity and security, eliminating the need for expensive dedicated memory devices.
2Reliability
If dedicated nonvolatile memory devices are used to store calibration and provisioning data, then physical security is improved, but memory capacity is limited and cost-effectiveness decreases
Solution Approach 1:
The patent segments the flash memory into different regions: a secure region for storing cryptographic hashes and critical authentication data, and a non-secure region for storing the actual calibration data. This segmentation allows the system to maintain physical security for essential data while providing ample capacity for complete calibration datasets without being constrained by limited dedicated memory capacity.
Solution Approach 2:
The patent moves the security model from a spatial dimension (dedicated secure memory devices with fixed capacity) to a cryptographic dimension (hash-based verification). This dimensional shift allows unlimited storage capacity in the non-secure region while maintaining security through cryptographic mechanisms, effectively resolving the capacity limitation imposed by dedicated memory devices.
3Ease of manufacture
If calibration data is stored on the primary storage device instead of dedicated memory, then manufacturing cost is reduced, but data security and authentication challenges increase
Solution Approach 1:
The patent performs preliminary cryptographic processing during manufacturing: generating cryptographic hashes of calibration data and storing them in a secure region before the device leaves the factory. This preliminary action establishes a security foundation that simplifies post-manufacturing operations, as the hash verification mechanism is already in place and does not require complex runtime security decisions.
Solution Approach 2:
The system implements self-service security verification: the device automatically verifies the cryptographic hash of calibration data against the stored reference hash when calibration data is accessed or modified. This self-verification mechanism eliminates the need for external security management infrastructure, reducing operational complexity while maintaining strong security on the primary storage device.
Data Source
AI summary
In various embodiments, methods, devices and systems for securely generating, sealing, and restoring factory-generated calibration and provisioning data for an electronic device are described, in which calibration and provisioning data for an electronic device are generated in a distributed manner and stored on a storage system. The calibration data can be retrieved from the storage system during device assembly and finalized calibration and provisioning data for each electronic device can be stored to the storage system. In one embodiment, a sealing server, to attest to the authenticity of the factory generated data, seals the finalized calibration data. In one embodiment, an electronic device can access a data store containing the factory-generated data and can update or restore calibration or provisioning data for the device from the data store.


