Hardware Root of Trust for Secure IoT Secret Migration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IoT devices face challenges in implementing strong security due to limited resources, making them vulnerable to malware attacks and data breaches, as existing security solutions require complex code that exceeds the memory capacity of many IoT devices.

Innovation Solution

A framework that establishes a core trusted computing base (TCB) using minimal hardware resources, leveraging a resource-constrained root of trust for measurement, providing sealing and attestation capabilities, and enabling secure communication and remote attestation, while requiring less than twenty kilobytes of code, suitable for devices with limited memory.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If strong security capabilities are implemented in IoT devices, then security protection against malware and data breaches is improved, but device complexity and resource requirements increase beyond what many IoT devices can support

Engineering Contradiction:
Improvesecurity protectionVSAvoidcode size
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the essential security function (root of trust) from complex security implementations and implements it using minimal hardware resources. The core trusted computing base is separated into a small, dedicated hardware component that provides sealing and attestation capabilities without requiring large amounts of code or memory, thus resolving the contradiction between security protection and device complexity

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses a minimal, lightweight root of trust implementation that consumes very few resources (less than twenty kilobytes of code) compared to traditional security solutions. This lightweight approach allows IoT devices with limited memory and processing capabilities to achieve strong security without the overhead of complex security subsystems

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

2Reliability

If existing security solutions are deployed in IoT devices, then security capabilities are improved, but memory capacity requirements exceed what many IoT devices can provide

Engineering Contradiction:
Improvesecurity capabilitiesVSAvoidmemory capacity
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent implements a lightweight security solution that requires less than twenty kilobytes of code, dramatically reducing the memory capacity requirement compared to existing security solutions. This enables deployment on resource-constrained IoT devices while maintaining strong security capabilities through hardware-based root of trust, sealing, and attestation mechanisms

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The patent extracts only the essential security functions (measurement, sealing, attestation) into a minimal hardware root of trust, eliminating the need for large amounts of security code. This extraction approach reduces memory requirements while preserving core security capabilities

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP3362939B1Migrating secrets using hardware roots of trust for devices
Publication Date: 2019.07.10 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3362939B1 patent drawingFigure 1
  • EP3362939B1 patent drawingFigure 2
  • EP3362939B1 patent drawingFigure 3

AI summary

Systems and methods facilitating a framework that provides a core trusted computing base (TCB) of an electronic device with various security capabilities. The framework can include a low-resource device and at least one distributed resource. The low-resource device can be configured to generate sealing keys, migration keys, and attestation keys that are based on a device secret associated with the low-resource device and one or more software modules. The low-resource device can further be configured to use the migration keys and the sealing keys to both verify a software update and migrate secrets from a previous version of the software to a newer version of the software. Additionally, the low-resource device can be configured to generate an attestation statement using the attestation keys and perform attestation using the attestation statement and the at least one distributed resource.