Firmware Security Descriptor Generation for IoT Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The deployment of IoT devices requires complex and costly processes for authentication, especially when multiple devices are involved, as manufacturers need to input device-specific information, leading to deployment delays and increased costs.

Innovation Solution

An FSD generator injects a unique device-specific secret into memory devices, using publicly-available data such as time, location, and other information to create a firmware security descriptor (FSD) for authentication, eliminating the need for direct user input and simplifying the authentication process for multiple devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If device-specific information is manually input for each IoT device during authentication, then authentication security is improved, but deployment complexity and time increase

Engineering Contradiction:
Improveauthentication securityVSAvoiddeployment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent pre-generates security descriptors for multiple IoT devices during manufacturing before deployment. This preliminary action eliminates the need for manual information input during authentication, reducing deployment time while maintaining security through pre-configured device-specific credentials

Inventive Principle:
Principle #10Preliminary action

2Reliability

If device-specific information is manually input for each IoT device during authentication, then authentication security is improved, but deployment costs increase

Engineering Contradiction:
Improveauthentication securityVSAvoiddeployment cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent performs security descriptor generation during the manufacturing process rather than during deployment. This shifts the cost from operational deployment phase to manufacturing phase, reducing overall deployment costs while maintaining authentication security through pre-configured device credentials

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If authentication processes are simplified for multiple IoT devices, then deployment complexity is reduced, but authentication security may be compromised

Engineering Contradiction:
Improvedeployment complexityVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent enables automated authentication where devices present pre-configured security descriptors and servers automatically verify them using stored public keys. This self-service mechanism simplifies deployment operations while maintaining security through cryptographic verification without manual intervention

Inventive Principle:
Principle #25Self-service

4Ease of operation

If security descriptors are generated using publicly-available information, then authentication process is simplified, but device-specific security may be reduced

Engineering Contradiction:
Improveauthentication processVSAvoiddevice-specific security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent combines publicly-available device information (such as device identifiers) with manufacturer-specific secret keys to generate security descriptors. This merging approach maintains device-specific security by incorporating unique manufacturer secrets while simplifying the authentication process through automated descriptor generation and verification

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11870918B2Security descriptor generation
Publication Date: 2024.01.09 MICRON TECHNOLOGY INC
  • US11870918B2 patent drawing
  • US11870918B2 patent drawing
  • US11870918B2 patent drawing

AI summary

Methods, systems, and devices for security descriptor generation are described. An end device may be authenticated based on a certificate and a device key based on a security descriptor. The security descriptor may be generated based on publicly-available information such as time of day information, geographical information, or a default set of information. The security descriptor may be used for generation of a certificate accessible by a server used for authenticating the device and also may be used by an end device to generate a device key for verification by the server authenticating the device.