IoT Device Migration via Dynamic EPID Credential Binding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The migration of logical devices between IoT platforms often requires re-issuance of device credentials, which is a heavyweight process that can impact operational latency and availability due to changes in security properties.
Innovation Solution
The use of dynamically provisioned EPID-based credentials allows logical devices to join and leave platform groups without re-issuing platform credentials, leveraging Intel EPID technology for privacy-preserving identifier management, enabling seamless migration by associating a new platform group key with the device state on the destination platform.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If device credentials are re-issued during migration to maintain security properties, then security reliability is improved, but operational latency and availability deteriorate
Solution Approach 1:
The system performs preliminary binding of platform security properties to device credentials during the commissioning phase before migration occurs. This preliminary action establishes a foundation that allows credentials to be preserved during migration, eliminating the need for time-consuming re-issuance while maintaining security reliability.
Solution Approach 2:
The system copies platform security properties and credential bindings to the destination platform during migration, rather than re-generating credentials. This copying approach maintains security reliability by preserving the original security properties while avoiding the operational latency associated with credential re-issuance.
2Reliability
If device credentials are re-issued during migration, then security properties are maintained, but device complexity and process overhead increase
Solution Approach 1:
The commissioning agent performs preliminary assessment and binding of platform security properties to device credentials before migration. This preliminary action creates a reusable credential structure that simplifies the migration process and reduces complexity, as the same credentials can be transferred without modification.
Solution Approach 2:
The system designs device credentials with universal applicability across multiple platforms by binding them to abstracted platform security properties rather than platform-specific implementations. This universality allows the same credentials to function on both source and destination platforms, eliminating the need for platform-specific credential re-issuance and reducing process overhead.
3Reliability
If platform security properties are tightly bound to device credentials, then security reliability is improved, but adaptability during migration deteriorates
Solution Approach 1:
The system segments the binding relationship into two independent components: platform security properties and device credentials. The commissioning agent binds these components together in a way that allows them to be independently transferred during migration, enabling both security reliability and migration adaptability. This segmentation allows credentials to maintain their security bindings while being adaptable to different platform environments.
Solution Approach 2:
The system implements dynamic credential binding that can adapt to different platform environments during migration. Rather than creating static, platform-specific credentials, the binding mechanism dynamically associates device credentials with the security properties of whichever platform is currently hosting the device, enabling seamless migration while maintaining security reliability.
Data Source
AI summary
In one embodiment, an apparatus comprises a processor to execute instructions and having at least a first logic to execute in a trusted execution environment, a secure storage to store a platform group credential, and a first logical device comprising at least one hardware logic. The platform group credential may be dynamically provisioned into the apparatus and corresponding to an enhanced privacy identifier associated with the apparatus. The first logical device may have a first platform group private key dynamically provisioned into the first logical device and corresponding to an enhanced privacy identifier associated with the first logical device, to bind the first logical device to the apparatus. Other embodiments are described and claimed.


