Fault Tolerant Cryptographic Key Provisioning Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The proliferation of electronic computing systems with proprietary information for multiple competing parties leads to increased costs and complexity, as each system must be customized to maintain secure access and verify proper storage of cryptographic keys without back office intervention.
Innovation Solution
A method and apparatus for verifying the loading, exporting, and storage of cryptographic keys using precomputed verification data, where keys are loaded into a secure peripheral as plaintext, encrypted, and stored outside the peripheral, with a processor ensuring proper storage by matching generated verification data, and employing a unique identifier for secure key generation and provisioning.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If individual systems are created for each customer to maintain secure access and verify proper storage of cryptographic keys, then security and verification reliability are improved, but system complexity and cost increase
Solution Approach 1:
The electronic controller performs self-verification of cryptographic key storage by generating verification data locally and comparing it with pre-computed verification data, eliminating the need for complex back office intervention and reducing system complexity while maintaining security reliability
Solution Approach 2:
Verification data is pre-computed and stored with the cryptographic keys before the controller needs to verify storage, allowing the controller to independently perform verification without requiring complex real-time verification systems or back office involvement
2Measurement precision
If back office intervention is used to verify key storage, then verification accuracy is improved, but time loss and operational complexity increase
Solution Approach 1:
The electronic controller independently verifies its own key storage by generating verification data locally and comparing it with pre-computed verification data, eliminating time-consuming back office intervention while maintaining verification accuracy through cryptographic verification
Solution Approach 2:
Verification data is pre-computed and stored with the cryptographic keys before verification is needed, allowing instant local verification without requiring time-consuming back office processing or intervention
Data Source
AI summary
The present application relates to a method and apparatus for providing fault tolerant provisioning verification for cryptographic keys including receiving, via an interface, a first security key, a second security key, and a first verification data generated in response to the first security key and the second security key, coupling, by a processor, the first security key and the second security key to an electronic controller, receiving, by the processor, a second verification data generated by the electronic controller in response to the first security key and the second security key, and marking, by the processor, the controller as provisioned in response to the first verification data matching the second verification data.


