Hardware Management Controller for Secure Device Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional computer security management systems rely on software-based agents that require operating system functionality, making them vulnerable to security threats from unmanaged devices and challenging to integrate with diverse hardware platforms, especially as more devices become 'smart' and network-capable.

Innovation Solution

Implementing hardware-based management controllers that generate secure identifiers and communicate directly with backend services outside the operating system's control, enabling secure, hardware-to-hardware transactions and management across various domains and platforms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software-based agents are used for device management, then device control and monitoring can be achieved, but security vulnerabilities increase and compatibility with diverse hardware platforms decreases

Engineering Contradiction:
ImprovesecurityVSAvoidhardware platform compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a hardware-based management controller as an intermediary component that operates independently from the operating system. This controller serves as a mediator between the device hardware and management services, enabling secure device identification and communication without relying on software-based agents. The management controller includes a secure identifier generation module that creates unique device identifiers stored in secure memory, allowing the device to be managed across diverse hardware platforms while maintaining high security standards.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If software-based agents are installed through the operating system, then device management tasks can be performed, but management becomes dependent on operating system presence and operability

Engineering Contradiction:
Improvedevice management capabilityVSAvoidmanagement availability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the device management functionality from the operating system environment by implementing a hardware-based management controller that operates independently. The management controller can perform device identification, generate secure identifiers, and communicate with backend services directly through hardware interfaces, bypassing the need for operating system mediation. This extraction ensures that device management capabilities remain available even when the operating system is absent, compromised, or unable to execute software agents.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If hardware-based management controllers are implemented, then security and hardware platform compatibility are improved, but device complexity increases

Engineering Contradiction:
Improvehardware platform compatibilityVSAvoidhardware architecture
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges the management controller functionality directly into the device's hardware architecture, integrating it with existing system components rather than adding separate external modules. The management controller is coupled to system memory and can interact with the memory controller hub, allowing it to access secure memory regions and communicate with backend services using existing hardware interfaces. This integration approach minimizes additional hardware complexity while enabling cross-platform compatibility and enhanced security capabilities.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP2936372B1Hardware-based device authentication
Publication Date: 2019.08.21 MCAFEE LLC
  • EP2936372B1 patent drawingFigure 1
  • EP2936372B1 patent drawingFigure 2
  • EP2936372B1 patent drawingFigure 3~4A

AI summary

An opportunity for a computing device to participate in a secure session with a particular domain is identified. A domain identifier of the particular domain is received and a secured microcontroller of the computing device is used to identify a secured, persistent hardware identifier of the computing device stored in secured memory of the computing device. A secure identifier is derived for a pairing of the computing device and the particular domain based on the hardware identifier and domain identifier of the particular domain and the secure identifier is transmitted over a secured channel to the particular domain. The particular domain can verify identity of the computing device from the secure identifier and apply security policies to transactions involving the computing device and the particular domain based at least in part on the secure identifier.