Immutable DICE Certificate for Mutable Layer 0 Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing DICE architectures face challenges in updating mutable code of the DICE layer 0 without breaking the Chain of Trust (CoT), leading to security vulnerabilities, resource wastage, and increased deployment complexity, as well as the need for physical return to manufacturers for certificate issuance.

Innovation Solution

Implementing an immutable certificate for the DICE architecture, allowing the DICE layer 0 to be updated independently by generating a CDI based on immutable device data and a UDS, maintaining the CoT integrity and enabling local re-generation of the DICE layer 0 CDI without manufacturer intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the DICE layer 0 mutable code is updated to fix security vulnerabilities or improve functionality, then the device security and functionality are improved, but the Chain of Trust is broken requiring manufacturer intervention and physical return

Engineering Contradiction:
Improvedevice securityVSAvoidupdate process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the device identity into two independent parts: an immutable root identity stored in hardware and a mutable DICE layer 0 code. This segmentation allows the mutable code to be updated without affecting the immutable root identity, thus maintaining the Chain of Trust while enabling security updates. The immutable certificate serves as the anchor that remains constant while the DICE layer 0 can evolve independently.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by pre-storing an immutable certificate in the device that is derived from the immutable root identity. This certificate is generated before any potential updates to DICE layer 0 and serves as a pre-established trust anchor. When updates are needed, this pre-stored certificate allows the device to re-establish the Chain of Trust locally without requiring manufacturer intervention, thus preparing the system in advance for future updates.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the device returns to manufacturer for certificate issuance after DICE layer 0 updates, then the Chain of Trust is restored, but resource waste and deployment complexity increase

Engineering Contradiction:
ImproveChain of Trust integrityVSAvoidresource waste
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent enables self-service by allowing the device to autonomously re-generate its DICE layer 0 identity and re-establish the Chain of Trust using its own immutable certificate and root identity, without requiring manufacturer intervention. The device can perform self-diagnosis and self-recovery operations locally, eliminating the need for physical returns and associated resource waste in logistics, manufacturing, and deployment processes.

Inventive Principle:
Principle #25Self-service

3Reliability

If the DICE layer 0 code is restricted from updating, then the Chain of Trust remains intact, but security vulnerabilities cannot be addressed and functionality cannot be improved

Engineering Contradiction:
ImproveChain of Trust stabilityVSAvoidcode update capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamics by creating a hierarchical identity structure where the immutable root identity provides stability while the DICE layer 0 identity can dynamically change. The system transitions from a static all-or-nothing update model to a dynamic partial update model where only the mutable portion needs to be updated. This dynamic structure allows the device to adapt to new security requirements and functionality while maintaining the stable trust anchor.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12411997B2Immutable certificate for device identifier composition engine
Publication Date: 2025.09.09 MICRON TECHNOLOGY INC
  • US12411997B2 patent drawing
  • US12411997B2 patent drawing
  • US12411997B2 patent drawing

AI summary

Implementations described herein relate to an immutable certificate for a device identifier composition engine (DICE). In some implementations, a device may include a secure computing environment. The secure component environment may include a hardware root of trust (HRoT) DICE component, a DICE layer 0 (L0) component configured to derive a DICE identity key, wherein the DICE L0 component is above the HRoT DICE component in a layer stack, a DICE layer 1 (L1) component configured to derive a DICE alias key based on the DICE identity key, wherein the DICE L1 component is above the DICE L0 component in the layer stack, wherein the DICE L1 component and the DICE L0 component are implemented as mutable code, and a controller. The controller may be configured to generate a set of certificates based on a compound device identifier (CDI).