Hardware-Backed Key Store for Cryptographic Attestation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cryptographic key attestation technologies struggle to securely correlate application identities with a client device, as software-based solutions lack the security assurance provided by hardware-backed key stores, leading to doubts about key origins across different application servers.

Innovation Solution

Binding multiple application identities to a hardware-backed key store, which generates a device private/device public key pair and application private/application public key pairs, allowing the key store to sign attestation claims with a device private key, enabling correlation of attestation claims across remote application servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If software-based key attestation is used, then ease of operation is improved, but security reliability deteriorates

Engineering Contradiction:
Improveease of operationVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a hardware-backed key store (TPM) as an intermediary between the software applications and the cryptographic keys. This hardware module provides secure key generation and storage, enabling software-based attestation to achieve both ease of operation and security reliability by bridging the trust gap between software convenience and hardware security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple application identities are registered with different servers, then adaptability is improved, but difficulty of detecting and measuring key associations worsens

Engineering Contradiction:
ImproveadaptabilityVSAvoiddifficulty of detecting and measuring
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements a feedback mechanism where the hardware-backed key store provides attestation statements to multiple servers about the same application identity. Each server receives feedback about the key store association, enabling them to detect and measure key associations across different communication channels while maintaining adaptability to multiple servers.

Inventive Principle:
Principle #23Feedback

3Reliability

If hardware-backed key store is used, then security reliability is improved, but device complexity worsens

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the cryptographic functionality into a separate hardware-backed key store module that handles security-critical operations. This segmentation isolates the complexity of hardware security mechanisms from the software applications, allowing multiple applications to use the same secure key store without increasing individual application complexity.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12113898B2Binding with cryptographic key attestation
Publication Date: 2024.10.08 MICROSOFT TECHNOLOGY LICENSING LLC
  • US12113898B2 patent drawing
  • US12113898B2 patent drawing
  • US12113898B2 patent drawing

AI summary

Generally discussed herein are devices, systems, and methods for binding with cryptographic key attestation. A method can include generating, by hardware of a device, a device public key and a device private key, based on the device private key, signing a first attestation resulting in a signed first attestation, the first attestation claiming the device private key originated from the hardware, based on the device public key and the signed first attestation, registering the device with a trusted authority, generating, by the hardware, a first application private key and a first application public key, and based on the device private key, signing a second attestation resulting in a signed second attestation, the second attestation claiming the first application private key originated from the hardware, and based on the first application public key and the signed second attestation, registering a first application of the device to a first server.