Hardware-Backed Key Store for Cryptographic Attestation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cryptographic key attestation technologies struggle to securely correlate application identities with a client device, as software-based solutions lack the security assurance provided by hardware-backed key stores, leading to doubts about key origins across different application servers.
Innovation Solution
Binding multiple application identities to a hardware-backed key store, which generates a device private/device public key pair and application private/application public key pairs, allowing the key store to sign attestation claims with a device private key, enabling correlation of attestation claims across remote application servers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If software-based key attestation is used, then ease of operation is improved, but security reliability deteriorates
Solution Approach 1:
The patent introduces a hardware-backed key store (TPM) as an intermediary between the software applications and the cryptographic keys. This hardware module provides secure key generation and storage, enabling software-based attestation to achieve both ease of operation and security reliability by bridging the trust gap between software convenience and hardware security.
2Adaptability or versatility
If multiple application identities are registered with different servers, then adaptability is improved, but difficulty of detecting and measuring key associations worsens
Solution Approach 1:
The patent implements a feedback mechanism where the hardware-backed key store provides attestation statements to multiple servers about the same application identity. Each server receives feedback about the key store association, enabling them to detect and measure key associations across different communication channels while maintaining adaptability to multiple servers.
3Reliability
If hardware-backed key store is used, then security reliability is improved, but device complexity worsens
Solution Approach 1:
The patent segments the cryptographic functionality into a separate hardware-backed key store module that handles security-critical operations. This segmentation isolates the complexity of hardware security mechanisms from the software applications, allowing multiple applications to use the same secure key store without increasing individual application complexity.
Data Source
AI summary
Generally discussed herein are devices, systems, and methods for binding with cryptographic key attestation. A method can include generating, by hardware of a device, a device public key and a device private key, based on the device private key, signing a first attestation resulting in a signed first attestation, the first attestation claiming the device private key originated from the hardware, based on the device public key and the signed first attestation, registering the device with a trusted authority, generating, by the hardware, a first application private key and a first application public key, and based on the device private key, signing a second attestation resulting in a signed second attestation, the second attestation claiming the first application private key originated from the hardware, and based on the first application public key and the signed second attestation, registering a first application of the device to a first server.


