Remote Attestation for Modular Devices with Multiple Cryptoprocessors

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods fail to provide persistent security validation for modular networking devices with multiple cryptoprocessors, as existing solutions do not effectively verify all cryptoprocessors across the device's lifetime, especially when modules are replaced.

Innovation Solution

A method and system for creating a signed attestation bundle using an attestation key that is not tied to specific hardware, allowing for the verification of all constituent devices within a supervising device, which generates a signed dossier in a secure enclave for remote attestation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If modular devices use multiple cryptoprocessors in replaceable modules, then device functionality and flexibility are improved, but security validation becomes more complex and cannot persist across module replacements

Engineering Contradiction:
Improvemodular functionalityVSAvoidsecurity validation persistence
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system segments security validation into two parts: module-specific cryptoprocessor validation and supervisor device-level attestation. The supervisor device collects and aggregates attestation information from multiple modules, creating a consolidated security profile that persists independently of individual module presence.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The supervisor device's attestation mechanism serves multiple functions: it validates individual module cryptoprocessors, aggregates their security states, and maintains persistent device-level attestation that works regardless of which specific modules are installed. This universal mechanism handles both module-specific and device-wide security requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If validation is tied to specific hardware cryptoprocessors, then security verification is simplified, but validation cannot persist when modules are replaced

Engineering Contradiction:
Improvevalidation simplicityVSAvoidvalidation persistence
Core Design Contradiction:
Ease of operationVSDuration of action of stationary object

Solution Approach 1:

The supervisor device acts as an intermediary between module cryptoprocessors and external validators. It collects attestation information from various modules, aggregates their security states, and presents a unified device-level attestation. This mediator approach maintains simple hardware-level validation while creating persistent device-wide security validation that survives module replacements.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If all cryptoprocessors are validated individually, then security coverage is improved, but validation complexity and overhead increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidvalidation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system merges individual module attestation results into a single device-level attestation bundle. The supervisor device collects security measurements from multiple cryptoprocessors across different modules, combines them into aggregated attestation information, and presents it as a unified validation package. This maintains comprehensive security coverage while simplifying the validation process through consolidation.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP3948612B1Remote attestation of modular devices with multiple cryptoprocessors
Publication Date: 2024.02.14 CISCO TECHNOLOGY INC
  • EP3948612B1 patent drawingFigure 1
  • EP3948612B1 patent drawingFigure 2
  • EP3948612B1 patent drawingFigure 3

AI summary

The present technology discloses systems, methods, and computer-readable media for requesting at least one signed security measurement from at least one module with a corresponding cryptoprocessor, the at least one module existing within a device; receiving the at least one signed security measurement from the at least one module with the corresponding cryptoprocessor; validating the at least one signed security measurement; generating a signed dossier including all validated signed security measurements in a secure enclave, the signed dossier being used by an external network device for remote attestation of the device.