Hardware Detection via Notarization Certificates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing prevalence of hardware-related attacks, such as counterfeiting and replacement, poses a significant threat to device security, as existing technologies lack effective methods for verifying the authenticity and integrity of hardware components.

Innovation Solution

A hardware detection method that involves encrypting verification data using unique keys generated by each hardware component, establishing a binding relationship, and verifying this relationship through a notarization certificate with a digital signature, ensuring the security and authenticity of the hardware by preventing unauthorized substitution or tampering.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware components are verified using traditional methods, then the verification process is simple, but hardware security against replacement and counterfeiting attacks is insufficient

Engineering Contradiction:
Improvehardware securityVSAvoidverification system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by establishing binding relationships between hardware components and their identifiers before the hardware is deployed. Notarization certificates are pre-generated that cryptographically bind hardware identifiers together, so that when verification is needed, the hardware itself can provide proof of its authorized configuration without requiring complex real-time analysis. This pre-computation of trust relationships simplifies the actual verification process while ensuring security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces notarization certificates as an intermediary mechanism that mediates between hardware components and the verification system. These certificates contain cryptographic bindings of hardware identifiers and act as trusted intermediaries that prove the authorized relationship between components. This intermediary approach avoids the need for direct complex verification of hardware relationships, as the notarization certificate serves as a pre-validated proof of authenticity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If hardware authenticity is verified through cryptographic methods, then hardware replacement and counterfeiting are prevented, but the verification process becomes more complex

Engineering Contradiction:
Improvehardware authenticityVSAvoidverification difficulty
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent extracts the complex cryptographic verification logic from the real-time detection process and places it into pre-generated notarization certificates. The certificates contain the essential cryptographic bindings of hardware identifiers that can be verified through relatively simple cryptographic operations. This extraction separates the difficult cryptographic computations (done beforehand) from the simpler verification operations (performed during detection), reducing the difficulty of real-time hardware authenticity verification.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs preliminary cryptographic operations to generate notarization certificates that bind hardware identifiers together before verification is needed. These pre-computed certificates contain all the necessary cryptographic proofs of hardware relationships, so that during actual verification, the system only needs to check the validity of these pre-established bindings rather than performing complex real-time cryptographic analysis of hardware relationships.

Inventive Principle:
Principle #10Preliminary action

3Stability of the object's composition

If binding relationships between hardware components are established and verified, then hardware integrity is ensured, but the system requires more complex cryptographic operations

Engineering Contradiction:
Improvehardware integrityVSAvoidcryptographic system complexity
Core Design Contradiction:
Stability of the object's compositionVSDevice complexity

Solution Approach 1:

The patent merges multiple hardware identifiers and their binding relationships into a single notarization certificate structure. Instead of maintaining separate verification mechanisms for each hardware component relationship, the certificate combines all relevant identifier bindings into one unified cryptographic object. This merging reduces the overall system complexity by consolidating multiple verification requirements into a single verifiable unit while maintaining hardware integrity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent performs preliminary establishment of binding relationships between hardware identifiers and embeds these relationships into notarization certificates before verification is needed. This pre-establishment of trust relationships means that the complex cryptographic bindings are computed once in advance rather than being recalculated during verification. The certificates serve as pre-packaged proofs of hardware integrity that can be validated through standardized cryptographic operations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12047388B2Hardware detection method and apparatus, device, and storage medium
Publication Date: 2024.07.23 HUAWEI TECH CO LTD
  • US12047388B2 patent drawing
  • US12047388B2 patent drawing
  • US12047388B2 patent drawing

AI summary

A hardware detection method includes sending first verification data to a physical carrier, where the physical carrier carries a plurality of pieces of hardware; receiving a ciphertext and binding relationship information from the physical carrier, where the ciphertext is obtained after at least two of the pieces of hardware respectively encrypt the first verification data using respective keys, and where the binding relationship information indicates a binding relationship between the at least two pieces of hardware; verifying the ciphertext and the binding relationship information; and determining security of the at least two pieces of hardware based on a verification result.