Multiple Root of Trust Component for Secure Resource Delegation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cryptographic systems rely on a single root of trust, which limits flexibility and security as resources are privileged to a single entity throughout the lifecycle of an integrated circuit, failing to accommodate multiple entities and secure delegation of resources effectively.

Innovation Solution

Implementing a multiple root of trust component within an integrated circuit, where physical roots of trust are embedded during manufacturing and virtual roots can be established post-manufacturing, allowing for secure delegation of resources to different entities through cryptographic keys and programming of OTP memory, ensuring that resources remain privileged to specific roots of trust.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a single root of trust is used in cryptographic systems, then the system structure is simple and easy to manage, but the flexibility and security are limited as resources are privileged to a single entity throughout the lifecycle of an integrated circuit

Engineering Contradiction:
ImproveflexibilityVSAvoidsystem structure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent divides the single root of trust into multiple roots of trust (first root of trust and second root of trust), each associated with different entities and resource sets. This segmentation allows different entities to have controlled access to specific resources, thereby improving flexibility and adaptability while maintaining manageable system structure through clear separation of privileges.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The integrated circuit is designed to support multiple roots of trust and their associated entities, making the system multi-functional. The circuit can handle different types of cryptographic operations, resource delegations, and entity interactions through a unified architecture that accommodates diverse security requirements without requiring separate hardware for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If resources are privileged to a single entity throughout the lifecycle of an integrated circuit, then the system is simple to manage, but it fails to accommodate multiple entities and secure delegation of resources effectively

Engineering Contradiction:
Improveaccommodation of multiple entitiesVSAvoidmanagement simplicity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

Resources are segmented into different sets, with each set privileged to a specific root of trust and its associated entity. This segmentation enables multiple entities to coexist in the system with defined resource boundaries, allowing effective accommodation of multiple entities while maintaining clear management protocols for each resource set.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces root entities as intermediaries between the integrated circuit and various entities. These root entities manage resource delegation and access control, facilitating secure interaction between multiple entities and the circuit without requiring direct complex management of all entity-circuit interactions, thus preserving ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If a single root of trust is used, then the cryptographic system has a straightforward security model, but it cannot effectively secure delegation of resources to different entities

Engineering Contradiction:
Improvesecurity of resource delegationVSAvoidcryptographic system structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security model is segmented into multiple roots of trust, each providing independent security boundaries for different resource sets. This segmentation enhances the reliability of resource delegation by ensuring that compromise of one root of trust does not affect others, while the modular structure keeps the overall system complexity manageable through clear security zones.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different regions or aspects of the cryptographic system have different security qualities tailored to their specific needs. Each root of trust and its associated resources have customized security parameters and delegation rules, allowing optimal security for each local context while maintaining overall system coherence and avoiding unnecessary complexity.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP3384423B1Device with multiple roots of trust
Publication Date: 2022.08.10 CRYPTOGRAPHY RESEARCH INC
  • EP3384423B1 patent drawingFigure 1
  • EP3384423B1 patent drawingFigure 2
  • EP3384423B1 patent drawingFigure 3

AI summary

A container from a first root of trust associated with a first root entity may be received. The container may correspond to a mapping of a resource of an integrated circuit that is associated with the first root entity. The container may be verified based on a key that corresponds to the first root of trust and that is stored in the integrated circuit at manufacturing of the integrated circuit. An identification may be made that an assignment of the resource from the container corresponds to assigning the resource from the first root of trust to a new root of trust. A new key corresponding to the new root of trust may be generated. Information corresponding to the new key may be stored into a memory of the integrated circuit. Furthermore, the new key may be used to delegate the resource to a subsequent container.