IoT Device Migration via Dynamic EPID Credential Binding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The migration of logical devices between IoT platforms often requires re-issuance of device credentials, which is a heavyweight process that can impact operational latency and availability due to changes in security properties.

Innovation Solution

The use of dynamically provisioned EPID-based credentials allows logical devices to join and leave platform groups without re-issuing platform credentials, leveraging Intel EPID technology for privacy-preserving identifier management, enabling seamless migration by associating a new platform group key with the device state on the destination platform.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If device credentials are re-issued during migration to maintain security properties, then security reliability is improved, but operational latency and availability deteriorate

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidoperational latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary binding of platform security properties to device credentials during the commissioning phase before migration occurs. This preliminary action establishes a foundation that allows credentials to be preserved during migration, eliminating the need for time-consuming re-issuance while maintaining security reliability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system copies platform security properties and credential bindings to the destination platform during migration, rather than re-generating credentials. This copying approach maintains security reliability by preserving the original security properties while avoiding the operational latency associated with credential re-issuance.

Inventive Principle:
Principle #26Copying

2Reliability

If device credentials are re-issued during migration, then security properties are maintained, but device complexity and process overhead increase

Engineering Contradiction:
Improvesecurity propertiesVSAvoidprocess overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The commissioning agent performs preliminary assessment and binding of platform security properties to device credentials before migration. This preliminary action creates a reusable credential structure that simplifies the migration process and reduces complexity, as the same credentials can be transferred without modification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system designs device credentials with universal applicability across multiple platforms by binding them to abstracted platform security properties rather than platform-specific implementations. This universality allows the same credentials to function on both source and destination platforms, eliminating the need for platform-specific credential re-issuance and reducing process overhead.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If platform security properties are tightly bound to device credentials, then security reliability is improved, but adaptability during migration deteriorates

Engineering Contradiction:
Improvesecurity propertiesVSAvoidmigration adaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system segments the binding relationship into two independent components: platform security properties and device credentials. The commissioning agent binds these components together in a way that allows them to be independently transferred during migration, enabling both security reliability and migration adaptability. This segmentation allows credentials to maintain their security bindings while being adaptable to different platform environments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements dynamic credential binding that can adapt to different platform environments during migration. Rather than creating static, platform-specific credentials, the binding mechanism dynamically associates device credentials with the security properties of whichever platform is currently hosting the device, enabling seamless migration while maintaining security reliability.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11381396B2System, apparatus and method for migrating a device having a platform group
Publication Date: 2022.07.05 MCAFEE LLC
  • US11381396B2 patent drawing
  • US11381396B2 patent drawing
  • US11381396B2 patent drawing

AI summary

In one embodiment, an apparatus comprises a processor to execute instructions and having at least a first logic to execute in a trusted execution environment, a secure storage to store a platform group credential, and a first logical device comprising at least one hardware logic. The platform group credential may be dynamically provisioned into the apparatus and corresponding to an enhanced privacy identifier associated with the apparatus. The first logical device may have a first platform group private key dynamically provisioned into the first logical device and corresponding to an enhanced privacy identifier associated with the first logical device, to bind the first logical device to the apparatus. Other embodiments are described and claimed.