Cryptographic Firmware Ownership Transfer Mechanism

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computing devices lack secure mechanisms for transferring ownership control of firmware, leading to potential security risks and challenges in managing firmware updates and authenticity across different ownership entities.

Innovation Solution

Implementing a cryptographic control mechanism that separates computing system ownership from firmware ownership, allowing for a secure transfer of ownership by establishing a chain of provenance and trust between the device owner and firmware signing domains, using asymmetric cryptographic keys to manage and verify firmware ownership.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic control mechanisms are implemented to separate ownership from firmware ownership, then security is improved, but device complexity increases

Engineering Contradiction:
Improvefirmware securityVSAvoidownership transfer mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments ownership control into two distinct layers: device ownership (hardware level) and firmware ownership (software level). This is achieved by introducing separate cryptographic key pairs - device owner keys for controlling the device and firmware owner keys for controlling firmware. The segmentation allows independent management of device and firmware ownership, improving security while maintaining manageable complexity through clear separation of concerns.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces cryptographic certificates and trusted execution environments as intermediaries to facilitate secure ownership transfer. The firmware owner certificate acts as an intermediary credential that proves firmware ownership without exposing private keys. The trusted execution environment serves as an intermediary that securely stores and manages cryptographic materials, reducing the complexity burden on the overall system by centralizing security-critical functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a chain of provenance is established between device owner and firmware signing domains, then authenticity is improved, but measurement precision requirements increase

Engineering Contradiction:
Improvefirmware authenticityVSAvoidcryptographic verification
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent establishes the chain of provenance in advance through pre-computation and pre-signing operations. Firmware owners sign firmware images before deployment, and device owners pre-establish trusted firmware owner certificates. This preliminary cryptographic binding creates an immutable chain of trust that can be verified without requiring complex real-time measurements, reducing verification precision requirements while maintaining authenticity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces complex measurement and verification mechanisms with cryptographic proof mechanisms. Instead of relying on precise measurement of firmware origins and ownership, the system uses digital signatures and cryptographic certificates that provide mathematically verifiable proof of authenticity. This substitution eliminates the need for complex measurement precision while establishing robust chains of provenance through cryptographic relationships.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If multiple signing domains are allowed, then adaptability is improved, but device complexity increases

Engineering Contradiction:
Improvefirmware management flexibilityVSAvoidkey management system
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal cryptographic framework that can accommodate multiple firmware owners and signing domains through a common certificate-based architecture. The device owner can issue certificates to multiple firmware owners, and each firmware owner can sign firmware for different domains using the same underlying cryptographic primitives. This universal approach enables multi-domain support without requiring separate key management systems for each domain, reducing complexity while maintaining adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11831406B2System, devices and/or processes for secure transfer of cryptographic control of computing platform
Publication Date: 2023.11.28 ARM LTD
  • US11831406B2 patent drawing
  • US11831406B2 patent drawing
  • US11831406B2 patent drawing

AI summary

Briefly, example methods, apparatuses, and/or articles of manufacture are disclosed that may be implemented, in whole or in part, using one or more processing devices to facilitate and/or support cryptographically associating a particular computing device with a new system owner based at least in part on a new system owner public key of a new system owner public/private key pair and a current system owner private key of a current system owner public/private key pair.