IoT Boot Integrity via Crypto Accelerator Extraction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
IoT devices face challenges in ensuring platform integrity due to resource, size, and cost constraints, making traditional TPM-based solutions unsuitable for miniaturized devices, and existing lightweight approaches like DICE are susceptible to leakage and reuse.
Innovation Solution
A lightweight solution leveraging crypto-acceleration modules on microprocessors and microcontroller-based IoT devices, providing a Root of Trust module with integrated internal control logic for secure storage and reporting of platform integrity measurements, using cryptographic primitives like hash and cipher modules to support Extend and Quote operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional TPM-based solutions are used for platform integrity measurement, then security and reliability are improved, but device size, cost, and resource consumption increase making them unsuitable for IoT devices
Solution Approach 1:
The patent extracts the essential functionality of TPM (integrity measurement and attestation) and implements it using only the device's existing crypto-acceleration modules and boot ROM, removing the need for separate TPM hardware. This extraction approach maintains security while eliminating the size and cost overhead of traditional TPM solutions.
Solution Approach 2:
The patent makes the existing crypto-acceleration modules serve dual purposes: their original cryptographic functions plus new integrity measurement and attestation functions. By making these modules multi-functional, the system achieves TPM-like security capabilities without adding dedicated hardware components.
2Device complexity
If lightweight approaches like DICE are used to reduce device complexity, then resource constraints are addressed, but security is weakened due to susceptibility to leakage and reuse
Solution Approach 1:
The patent performs integrity measurements during the boot process before the device becomes fully operational, capturing the system state in its most trusted configuration. This preliminary measurement approach ensures that any subsequent compromises or attacks occur after the integrity baseline is already established, preventing leakage and reuse attacks.
Solution Approach 2:
The patent introduces a measurement value (integrity hash) as an intermediary that represents the device's trusted state. This intermediary is stored in a protected location and used for attestation without exposing the actual boot components, thereby preventing direct leakage while maintaining security verification.
3Reliability
If dedicated TPM hardware is included in IoT device design, then platform integrity measurement capability is improved, but manufacturing cost and device size increase
Solution Approach 1:
The patent enables the device's existing crypto-acceleration modules to perform integrity measurement and attestation functions independently, without requiring external TPM hardware. This self-service approach allows IoT devices to achieve security capabilities using their own built-in resources, eliminating the need for additional components and reducing manufacturing complexity.
4Adaptability or versatility
If existing crypto accelerators are repurposed for integrity measurement, then device resource utilization is improved, but cryptographic operation overhead may increase
Solution Approach 1:
The patent performs integrity measurements during the boot process when the system is already executing code and the crypto-acceleration modules are naturally active. By leveraging this existing operational context, the patent avoids additional energy overhead that would result from activating these modules separately for measurement purposes.
Data Source
AI summary
Embodiments of the present invention are directed to an improved system and method of producing, recording and reporting boot integrity measurements of an Internet of Things (“IoT”) computing device to resource (such as an on-chip software module, an external software module, a printer, a network router, or a server), so the resource can confirm that the IoT computing device can be trusted before access to the resource is granted. Embodiments provide a new and less expensive architecture for reliably collecting and relaying device state information to support trust-sensitive applications. Embodiments leverage crypto-acceleration modules found on many existing microprocessors and microcontroller-based IoT devices, while introducing little additional overhead or additional circuitry. Embodiments provide a Root of Trust module comprising integrated internal control logic that functions as a secure on-chip wrapper for cryptographic primitive modules, which provide secure storage and reporting of the host's platform integrity measurements.


