Hardware Root of Trust for Secure IoT Secret Migration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
IoT devices face challenges in implementing strong security due to limited resources, making them vulnerable to malware attacks and data breaches, as existing security solutions require complex code that exceeds the memory capacity of many IoT devices.
Innovation Solution
A framework that establishes a core trusted computing base (TCB) using minimal hardware resources, leveraging a resource-constrained root of trust for measurement, providing sealing and attestation capabilities, and enabling secure communication and remote attestation, while requiring less than twenty kilobytes of code, suitable for devices with limited memory.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If strong security capabilities are implemented in IoT devices, then security protection against malware and data breaches is improved, but device complexity and resource requirements increase beyond what many IoT devices can support
Solution Approach 1:
The patent extracts the essential security function (root of trust) from complex security implementations and implements it using minimal hardware resources. The core trusted computing base is separated into a small, dedicated hardware component that provides sealing and attestation capabilities without requiring large amounts of code or memory, thus resolving the contradiction between security protection and device complexity
Solution Approach 2:
The patent uses a minimal, lightweight root of trust implementation that consumes very few resources (less than twenty kilobytes of code) compared to traditional security solutions. This lightweight approach allows IoT devices with limited memory and processing capabilities to achieve strong security without the overhead of complex security subsystems
2Reliability
If existing security solutions are deployed in IoT devices, then security capabilities are improved, but memory capacity requirements exceed what many IoT devices can provide
Solution Approach 1:
The patent implements a lightweight security solution that requires less than twenty kilobytes of code, dramatically reducing the memory capacity requirement compared to existing security solutions. This enables deployment on resource-constrained IoT devices while maintaining strong security capabilities through hardware-based root of trust, sealing, and attestation mechanisms
Solution Approach 2:
The patent extracts only the essential security functions (measurement, sealing, attestation) into a minimal hardware root of trust, eliminating the need for large amounts of security code. This extraction approach reduces memory requirements while preserving core security capabilities
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Systems and methods facilitating a framework that provides a core trusted computing base (TCB) of an electronic device with various security capabilities. The framework can include a low-resource device and at least one distributed resource. The low-resource device can be configured to generate sealing keys, migration keys, and attestation keys that are based on a device secret associated with the low-resource device and one or more software modules. The low-resource device can further be configured to use the migration keys and the sealing keys to both verify a software update and migrate secrets from a previous version of the software to a newer version of the software. Additionally, the low-resource device can be configured to generate an attestation statement using the attestation keys and perform attestation using the attestation statement and the at least one distributed resource.