Integrated Key Revocation with OTP Checks for Asset Field Loading
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional security techniques for digital assets are inadequate in addressing cyberattacks, leading to compromised private keys, increased downtime, and decreased performance due to the need for physical reprogramming of hardware units at factories for key revocation.
Innovation Solution
A key revocation computing system that enables secure and real-time revocation of compromised keys, utilizing a cryptographic service component, OTP memory programming, and a key revocation list to authenticate and update keys without physical transportation, ensuring secure boot processes and integrated safety checks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If physical reprogramming of hardware units at factories is performed for key revocation, then security of digital assets is improved, but downtime and maintenance overhead increase
Solution Approach 1:
The patent replaces the mechanical/physical process of transporting hardware units to factories for reprogramming with an electronic/digital process. The key revocation is performed remotely by transmitting revocation data to the hardware unit, eliminating the need for physical transportation and on-site reprogramming operations.
Solution Approach 2:
The patent introduces a key management system as an intermediary between the security compromise detection and the hardware unit reprogramming. This system manages the revocation process, generates updated cryptographic keys, and coordinates the secure transmission of revocation data to the affected hardware units.
2Device complexity
If conventional security techniques are used, then implementation simplicity is maintained, but vulnerability to cyberattacks increases
Solution Approach 1:
The patent implements preliminary security measures by pre-establishing a key revocation mechanism and maintaining a database of compromised keys before attacks occur. When a security breach is detected, the system can immediately revoke compromised keys and distribute updated credentials, preventing further unauthorized access rather than reacting after damage occurs.
Solution Approach 2:
The patent establishes a feedback loop where the system continuously monitors for security compromises, detects compromised keys through the key management system, and automatically responds by revoking those keys and distributing updated ones. This closed-loop approach allows the security system to adapt and respond to new threats dynamically.
3Speed
If real-time key revocation is implemented, then system security response time is improved, but processing complexity increases
Solution Approach 1:
The patent implements self-service capabilities where the key management system automatically performs key generation, revocation, and distribution without requiring manual intervention. The hardware units themselves can autonomously receive and apply the revoked key data, reducing the need for complex coordinated processing across multiple systems.
Data Source
AI summary
Various embodiments relate to integrated key revocation with a field loading process and/or related safety and security checks related to an asset system. In an implementation, a data loading request to store a data file via a target storage device of an asset is received. The data file can be signed based on a first key. In response to the data loading request, a key identifier for the first key associated with the data file is compared against (i) a list of key identifiers stored in a key revocation list and (ii) a one-time programmable (OTP) memory of the asset. Additionally, in response to a determination that the data file is successfully authenticated against the key revocation list and the OTP memory, a key revocation process is performed with respect to a second key for the data file associated with the data loading request.


