Hardware Reference Key Attestation via Certificate Authority

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computing devices are unable to attest to the validity of their own hardware reference keys, which is crucial for secure operations and identity verification in electronic commerce and communications.

Innovation Solution

A computing device generates hardware reference keys and corresponding attestation keys that attest to the authenticity of these keys, including processor type and operating system version, which can be verified by a privacy certificate authority to generate an X509 certificate for secure access to services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If hardware reference keys are used to identify computing devices, then device identification capability is improved, but the ability to attest to key validity deteriorates

Engineering Contradiction:
Improvedevice identification capabilityVSAvoidkey validity attestation
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent introduces a certificate authority as an intermediary that issues digital certificates attesting to the validity of hardware reference keys. The CA verifies the key generation process and provides third-party validation, resolving the contradiction between identification capability and attestation reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The computing device performs self-attestation by generating cryptographic proofs that demonstrate the key was created by a trusted hardware module. The device uses its own hardware resources to verify and sign attestation data, enabling self-validation without external intervention.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If hardware reference keys are stored centrally, then authentication convenience is improved, but security risks increase

Engineering Contradiction:
Improveauthentication convenienceVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication credentials from centralized storage and embeds them directly in the hardware reference key stored locally on the device. This eliminates the need to store sensitive authentication data on servers, reducing the attack surface while maintaining convenient authentication.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements local key storage and processing, where each device maintains its own hardware reference key in a secure element. The key never leaves the device in plaintext form, providing localized security that prevents centralized storage vulnerabilities while enabling convenient authentication through the stored key.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10536271B1Silicon key attestation
Publication Date: 2020.01.14 APPLE INC
  • US10536271B1 patent drawing
  • US10536271B1 patent drawing
  • US10536271B1 patent drawing

AI summary

Systems and methods are disclosed for generating one or more hardware reference keys (HRK) on a computing device, and for attesting to the validity of the hardware reference keys. An initial hardware reference key can be a silicon attestation key (SIK) generated during manufacture of a computing system, such as a system-on-a-chip. The SIK can comprise an asymmetric key pair based at least in part on an identifier of the processing system type and a unique identifier of the processing system. The SIK can be signed by the computing system and stored thereon. The SIK can be used to generate further HRKs on the computing device that can attest to the processing system type of the computing device and an operating system version that was running when the HRK was generated. The computing device can generate an HRK attestation (HRKA) for each HRK generated on the computing system.