NFC Smart Card Root of Trust for Mobile Secure Boot
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for establishing a hardware-based root of trust in mobile platforms, such as burning a root key into silicon or using SD cards, require significant manufacturing access and resources, and are not suitable for widespread deployment, especially in government environments where existing smart cards like the CAC can be repurposed.
Innovation Solution
Utilizing Near Field Communication (NFC) to authenticate and boot a mobile platform with a smart card, such as a CAC, which serves as a hardware-based root of trust, eliminating the need for additional identity management and hardware readers, and allowing for secure communication and secure boot processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional methods (burning root key into silicon or using SD cards) are used to establish hardware-based root of trust, then security and reliability are improved, but device complexity and manufacturing requirements worsen
Solution Approach 1:
The patent introduces an NFC reader as an intermediary device that enables the mobile platform to communicate with and authenticate against a remote root of trust stored on an ICC. This mediator approach allows the mobile platform to obtain authentication credentials without requiring complex local hardware modifications or manufacturing processes, thus maintaining security while reducing device complexity and manufacturing barriers
Solution Approach 2:
The patent makes the ICC universal by allowing it to serve multiple functions: storing the root of trust, providing authentication credentials, and enabling secure boot. The NFC reader also serves multiple purposes including reading the digital certificate, verifying digital signatures, and facilitating secure communication. This multi-functionality reduces the need for separate dedicated components, thereby reducing overall device complexity
2Reliability
If conventional hardware-based root of trust methods are used, then authentication security is improved, but ease of deployment worsens
Solution Approach 1:
The mobile platform performs self-authentication by automatically receiving the digital certificate from the ICC via NFC, verifying the digital signature using stored credentials, and booting itself upon successful verification. This self-service approach eliminates the need for complex manual deployment processes, making secure boot accessible to any mobile platform with NFC capability without requiring specialized manufacturing access
Solution Approach 2:
The patent segments the root of trust function from the mobile platform itself, placing it on a separate ICC that can be read via NFC. This segmentation allows the authentication functionality to be distributed rather than embedded, enabling easier deployment and scalability since the ICC can be independently issued and transferred to different devices without modifying the platform hardware
3Adaptability or versatility
If existing smart cards like CAC are repurposed as hardware root of trust, then adaptability and cost-effectiveness are improved, but device complexity worsens
Solution Approach 1:
The patent makes the ICC universal by allowing it to serve multiple functions: storing the root of trust, providing authentication credentials, and enabling secure boot. The NFC reader also serves multiple purposes including reading the digital certificate, verifying digital signatures, and facilitating secure communication. This multi-functionality reduces the need for separate dedicated components, thereby reducing overall device complexity
Solution Approach 2:
The patent merges the functions of the root of trust storage, authentication credential provision, and secure communication into a single integrated approach using the ICC and NFC reader. By combining these functions rather than implementing them as separate systems, the solution reduces overall device complexity while maintaining adaptability to existing smart card infrastructure
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
Enables secure and measured boot of mobile platforms, reduces the need for custom hardware and multiple certificates, and provides a cost-effective solution for secure identity management and authentication, suitable for large-scale deployments like those in the U.S. Government.
Implementation Method 1
receiving, by a mobile platform, a digital certificate from an integrated circuit card ('ICC') via close-proximity radio communication
Data Source
AI summary
The exemplary embodiments described herein relate to systems and methods for identifying and authenticating a mobile platform. One embodiment relates to a method comprising receiving, by a mobile platform, a digital certificate from an integrated circuit card (“ICC”) via close-proximity radio communication, verifying the digital certificate with a digital signature stored on the mobile platform, and booting the mobile platform upon verification of the digital certificate of the ICC. A further embodiment relates to a mobile platform, comprising a non-transitory computer readable storage medium storing a digital signature, and a processor receiving a digital certificate from an integrated circuit card (“ICC”) via close-proximity radio communication between the ICC and the mobile platform, verifying the digital certificate with the digital signature, booting the mobile platform upon verification of the digital certificate of the ICC.

