HTTPS Boot Decryption Key Generation and Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a lack of secure methods to protect decryption keys for devices from hackers between manufacturing and end-user usage, posing a technological challenge in ensuring the security of encrypted storage areas.
Innovation Solution
A method is developed to generate a key based on hardware component identifiers and firmware code, using a hash including TPM data and a salt, which is stored in an HTTPS-based cloud storage area, allowing secure encryption and decryption of device storage, and facilitating secure booting and authentication processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If decryption keys are stored securely during manufacturing and transit, then device storage security is improved, but key management complexity increases
Solution Approach 1:
The decryption key is generated and stored in HTTPS-based cloud storage before the device is provided to the end user. This preliminary action ensures the key is securely positioned in advance, eliminating the need for complex key management during device transit and initial setup.
Solution Approach 2:
HTTPS-based cloud storage acts as an intermediary between key generation and device deployment. This intermediary securely holds the key during manufacturing and transit, simplifying key management by centralizing security responsibilities in a dedicated secure storage system rather than distributing complexity across multiple devices and processes.
2Reliability
If decryption keys are transmitted securely to devices, then security against hackers is improved, but transmission and authentication time increases
Solution Approach 1:
Authentication credentials and device identity verification are completed before the decryption key is transmitted. This preliminary authentication ensures that only authorized devices receive keys, securing the transmission process while establishing trust in advance to streamline subsequent key delivery without repeated authentication delays.
Solution Approach 2:
The device independently verifies its own identity and authentication credentials during the boot process before receiving the decryption key. This self-service authentication mechanism reduces reliance on continuous external verification, minimizing authentication time while maintaining security through device-initiated identity proofing.
3Reliability
If device identity and integrity are verified during booting, then unauthorized access is prevented, but boot process complexity increases
Solution Approach 1:
Device identity and integrity verification are performed as preliminary steps during the boot process before the decryption key is released. This preliminary verification ensures unauthorized access is prevented at the earliest opportunity, establishing security credentials in advance that simplify subsequent decryption operations.
Solution Approach 2:
The HTTPS-based cloud storage system acts as an intermediary that coordinates device verification and key release. This intermediary manages the verification process centrally, reducing the complexity burden on individual devices by handling verification coordination and key distribution logic in a dedicated secure system.
Data Source
AI summary
Systems and methods are disclosed for generating a key based on at least one hardware component identifier for hardware of a first device and/or at least one piece of firmware code of the first device. The key may then be stored at a storage area accessible to the first device via hypertext transfer protocol secure (HTTPS) communication and the key may also be used to encrypt storage of the first device. Booting of the first device may then be facilitated based on HTTPS communication with a second device and using an extensible firmware interface (EFI) file and/or an IMG file stored at the second device. Then subsequent to at least partially facilitating the booting of the first device and based on verifying authentication credentials, the key may be transmitted to the first device to decrypt the storage of the first device.


