Hardware Security Module Remote Attestation via Digital Certificates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current solutions lack a method for remote attestation of a security module's Level of Assurance, particularly for network-connected IoT devices without human interfaces, and do not allow for the secure creation and transfer of cryptographic credentials that maintain the same assurance level as original vetted credentials.

Innovation Solution

A digital certificate is issued onto a hardware security module within a certified manufacturing environment, ensuring public key pairs are generated uniquely within the module, enabling remote verification of its identity and authentication level, and allowing secure transfer of credentials to maintain the chain of trust.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If cryptographic credentials are verified remotely for IoT devices without human interfaces, then authentication capability is improved, but the ability to verify Level of Assurance deteriorates

Engineering Contradiction:
Improveremote authentication capabilityVSAvoidLevel of Assurance verification
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent introduces a certificate authority as an intermediary that issues digital certificates containing Level of Assurance information. This mediator enables remote verification by providing a trusted third party that vouches for the security module's assurance level, allowing IoT devices to be authenticated remotely with verified LoA without human intervention.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the Level of Assurance information from the security module and embeds it into a digital certificate issued by a certificate authority. This extraction allows the LoA to be verified remotely through the certificate without requiring direct access to or physical inspection of the security module itself.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If digital certificates are issued to hardware security modules, then remote verification of identity is improved, but device complexity increases

Engineering Contradiction:
Improveremote identity verificationVSAvoidcertificate management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent enables the hardware security module to self-attest its Level of Assurance by providing cryptographic proof of its security properties. The module generates and manages its own attestation credentials and can independently verify its own security state, eliminating the need for external verification infrastructure and reducing overall system complexity.

Inventive Principle:
Principle #25Self-service

3Reliability

If public key pairs are generated within the security module boundary, then security assurance is improved, but manufacturing complexity increases

Engineering Contradiction:
Improvecryptographic key securityVSAvoidmodule provisioning
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent performs key generation and certificate issuance as preliminary actions during the manufacturing process. The hardware security module is provisioned with digital certificates and cryptographic credentials before deployment, enabling immediate remote verification upon activation. This preliminary provisioning eliminates the need for post-manufacturing verification setup and simplifies deployment.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10447486B2Remote attestation of a security module's assurance level
Publication Date: 2019.10.15 SPYRUS INC
  • US10447486B2 patent drawing
  • US10447486B2 patent drawing
  • US10447486B2 patent drawing

AI summary

A method by which a hardware security module can attest remotely to its measure of trust as determined by its security certifications and the Level of Assurance it can be relied on to support without the human witnessing elements that are currently used to validate this trust. In a further embodiment the Level of Assurance can be transported to a second hardware security module.