Microcode Challenge Response for Secure Device Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In complex electronic device manufacturing, the distributed production of components across multiple facilities raises security concerns, as counterfeit devices can be created by reverse-engineering components, leading to intellectual property loss and revenue decline, especially when the final assembly facility is not entirely secure.

Innovation Solution

The implementation of a microcode-based challenge/response process using an augmented processor with a microcode interpreter, where encrypted microcode is decrypted and executed within the processor hardware, ensuring only appropriately signed software is executed and preventing tampering, and a secure boot mechanism is enforced to validate the authenticity of the processor and software.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If components are manufactured by multiple external manufacturers, then manufacturing cost and flexibility are improved, but security risk increases due to potential counterfeiting

Engineering Contradiction:
Improvemanufacturing flexibilityVSAvoiddevice authenticity
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent applies preliminary action by embedding a security element during the component manufacturing process itself, before the component is assembled into the final device. This security element contains unique identification data that enables later verification of the component's authenticity and manufacturing origin, preventing counterfeiting while allowing distributed manufacturing

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary verification system that acts as a mediator between the distributed manufacturing ecosystem and the final device authentication. The security element serves as an intermediary carrier of trust information, allowing external manufacturers to produce components without compromising overall system security through the use of verifiable authentication mechanisms

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security verification is performed on all components, then device authenticity is improved, but processing time and complexity increase

Engineering Contradiction:
Improvedevice authenticityVSAvoidverification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

By performing security verification in advance during component manufacturing and embedding authentication data in the security element, the patent eliminates the need for time-consuming verification processes during final device assembly or operation. The authentication information is prepared beforehand and can be quickly validated later

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts the security verification function from the final device assembly process and places it in the component manufacturing process. This separation allows security checks to be performed independently during production without adding time pressure to the main assembly timeline

Inventive Principle:
Principle #2Taking out (Extraction)

3Productivity

If distributed manufacturing is implemented, then production capacity is improved, but control over manufacturing security deteriorates

Engineering Contradiction:
Improveproduction capacityVSAvoidmanufacturing security control
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent creates a universal security element that can be applied across multiple component types and manufacturers. This standardized security mechanism maintains consistent security control levels throughout the distributed manufacturing network, allowing the system to scale production capacity while maintaining uniform security standards through a multi-functional authentication approach

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2591437B1Microcode-based challenge/response process
Publication Date: 2018.11.14 BLACKBERRY LTD
  • EP2591437B1 patent drawingFigure 1
  • EP2591437B1 patent drawingFigure 2
  • EP2591437B1 patent drawingFigure 3

AI summary

Augmented processor hardware contains a microcode interpreter. When encrypted microcode is included in a challenge from a service requiring authentication, the microcode may be passed to the microcode interpreter. Based on decryption and execution of the microcode taking place at the processor hardware, tampering by potentially abusive device software may be avoided.