HTTPS Boot Decryption Key Generation and Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a lack of secure methods to protect decryption keys for devices from hackers between manufacturing and end-user usage, posing a technological challenge in ensuring the security of encrypted storage areas.

Innovation Solution

A method is developed to generate a key based on hardware component identifiers and firmware code, using a hash including TPM data and a salt, which is stored in an HTTPS-based cloud storage area, allowing secure encryption and decryption of device storage, and facilitating secure booting and authentication processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If decryption keys are stored securely during manufacturing and transit, then device storage security is improved, but key management complexity increases

Engineering Contradiction:
Improvedevice storage securityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The decryption key is generated and stored in HTTPS-based cloud storage before the device is provided to the end user. This preliminary action ensures the key is securely positioned in advance, eliminating the need for complex key management during device transit and initial setup.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

HTTPS-based cloud storage acts as an intermediary between key generation and device deployment. This intermediary securely holds the key during manufacturing and transit, simplifying key management by centralizing security responsibilities in a dedicated secure storage system rather than distributing complexity across multiple devices and processes.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If decryption keys are transmitted securely to devices, then security against hackers is improved, but transmission and authentication time increases

Engineering Contradiction:
Improvekey transmission securityVSAvoidauthentication and boot time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Authentication credentials and device identity verification are completed before the decryption key is transmitted. This preliminary authentication ensures that only authorized devices receive keys, securing the transmission process while establishing trust in advance to streamline subsequent key delivery without repeated authentication delays.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The device independently verifies its own identity and authentication credentials during the boot process before receiving the decryption key. This self-service authentication mechanism reduces reliance on continuous external verification, minimizing authentication time while maintaining security through device-initiated identity proofing.

Inventive Principle:
Principle #25Self-service

3Reliability

If device identity and integrity are verified during booting, then unauthorized access is prevented, but boot process complexity increases

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidboot process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Device identity and integrity verification are performed as preliminary steps during the boot process before the decryption key is released. This preliminary verification ensures unauthorized access is prevented at the earliest opportunity, establishing security credentials in advance that simplify subsequent decryption operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The HTTPS-based cloud storage system acts as an intermediary that coordinates device verification and key release. This intermediary manages the verification process centrally, reducing the complexity burden on individual devices by handling verification coordination and key distribution logic in a dedicated secure system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11531761B2HTTPS boot to provide decryption key
Publication Date: 2022.12.20 LENOVO SWITZERLAND INTERNATIONAL GMBH
  • US11531761B2 patent drawing
  • US11531761B2 patent drawing
  • US11531761B2 patent drawing

AI summary

Systems and methods are disclosed for generating a key based on at least one hardware component identifier for hardware of a first device and/or at least one piece of firmware code of the first device. The key may then be stored at a storage area accessible to the first device via hypertext transfer protocol secure (HTTPS) communication and the key may also be used to encrypt storage of the first device. Booting of the first device may then be facilitated based on HTTPS communication with a second device and using an extensible firmware interface (EFI) file and/or an IMG file stored at the second device. Then subsequent to at least partially facilitating the booting of the first device and based on verifying authentication credentials, the key may be transmitted to the first device to decrypt the storage of the first device.