Hardware Authentication via Signed Certificates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Information Handling Systems (IHSs) lack effective mechanisms for validating the authenticity of hardware components, especially during transfers of control or ownership, which can compromise security and integrity.

Innovation Solution

Incorporating a security processor with a logic unit and memory that stores signed certificates for hardware components, allowing for validation of replaceable hardware through factory provisioning, transfer of ownership, and trusted administration, using embedded certificate authorities to generate and sign certificates for authenticity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If hardware components are made replaceable to improve adaptability, then the system can be configured for different users and applications, but the ability to validate authenticity and maintain security is compromised

Engineering Contradiction:
Improvereplaceable hardware componentsVSAvoidhardware authenticity validation
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs factory provisioning in advance, where the security processor stores signed certificates identifying the original replaceable hardware components before the system is deployed. This preliminary action creates a baseline of trust that enables later validation of hardware authenticity without restricting replaceability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security processor acts as an intermediary between the replaceable hardware components and the system's security requirements. It stores and validates signed certificates, serving as a mediator that enables hardware replacement while maintaining authentication capability through cryptographic verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of repair

If the system allows hardware replacement to improve ease of repair and maintenance, then components can be upgraded or fixed, but security integrity may be compromised

Engineering Contradiction:
Improvehardware replacementVSAvoidsecurity compromise
Core Design Contradiction:
Ease of repairVSObject-affected harmful factors

Solution Approach 1:

The system implements a feedback mechanism where the security processor continuously validates the authenticity of replaceable hardware components by checking their signed certificates against the stored factory provisioning data. This feedback loop ensures that any unauthorized replacement is detected and can be prevented from compromising system security.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

Signed certificates are pre-stored in the security processor during factory provisioning, creating a baseline of expected hardware identities before any replacement occurs. This preliminary preparation enables rapid authentication of replacement components without requiring complex real-time verification processes.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If ownership transfer is enabled to improve adaptability for different users, then the system can be leased or sold, but validating that the same hardware remains authenticated becomes difficult

Engineering Contradiction:
Improveownership transferVSAvoidhardware identity verification
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The security processor serves as a persistent intermediary that maintains the chain of trust across ownership transfers. It stores the signed certificates and performs validation independently of the main system software, ensuring that hardware identity verification remains precise and reliable even when control and ownership of the system change hands.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11843707B2Systems and methods for authenticating hardware of an information handling system
Publication Date: 2023.12.12 DELL PROD LP
  • US11843707B2 patent drawing
  • US11843707B2 patent drawing
  • US11843707B2 patent drawing

AI summary

As part of a factory provisioning of an Information Handling System (IHS), a signed replaceable hardware certificate is stored that identifies any replaceable hardware components coupled to the IHS during the factory provisioning. Upon a transfer of control or ownership of the IHS, replaceable hardware components that are coupled to the IHS are detected, and the replaceable hardware certificate is utilized to validate that the identified replaceable hardware components detected as coupled to the IHS are the same replaceable hardware components coupled to the IHS during the factory provisioning. A security processor of the IHS may support boot code operations for generating additional replaceable hardware certificates that can be used to validate the integrity of any changes the replaceable hardware of the IHS, such as upon its next power cycle.