Owner Revocation Emulation Containers for Secure Key Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing electronic device security systems limit subsequent owners by requiring shared key revocation and image rollback protection information, restricting their ability to manage keys and images independently.
Innovation Solution
A system and method for creating and managing owner revocation emulation containers, which generate unique private keys and signatures for each owner, allowing independent management of assets and revocation of assets associated with previous owners.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If key revocation and image rollback protection information is stored in OTP memory, then security and revocation capability are improved, but subsequent owners are limited by previous owners' configurations
Solution Approach 1:
The patent segments the revocation information storage by creating separate owner revocation emulation containers for each owner. Each container is independently stored in non-volatile memory, allowing subsequent owners to have their own revocation information without being constrained by previous owners' configurations. This segmentation resolves the contradiction by enabling both secure revocation capability and owner independence.
Solution Approach 2:
The patent transitions from storing revocation information in a single shared OTP memory location to storing multiple independent containers in non-volatile memory with different ownership identifiers. This dimensional change from a single shared space to multiple independent spaces allows each owner to have full control over their own revocation information while maintaining the security benefits of revocation capability.
2Ease of manufacture
If a single configuration is provisioned in OTP memory during manufacturing, then device provisioning is simplified, but multiple owners cannot independently manage their own keys and images
Solution Approach 1:
The patent introduces dynamic owner revocation emulation containers that can be created, updated, and managed during the device lifecycle. While the initial OTP memory configuration remains static and simple for manufacturing, the system dynamically generates additional owner-specific containers in non-volatile memory as needed. This dynamic approach maintains ease of manufacture while enabling multi-owner support.
Solution Approach 2:
The patent performs preliminary provisioning of the first owner's configuration in OTP memory during manufacturing, then enables subsequent owners to create their own containers. This preliminary action simplifies manufacturing by establishing a baseline configuration, while the flexible container creation mechanism subsequently enables multi-owner support without complicating the initial provisioning process.
3Reliability
If 32 bits in OTP memory are allocated for key revocation, then revocation protection is enabled, but the second owner can only support one key after the first owner revokes 31 keys
Solution Approach 1:
The patent segments the key revocation storage by creating separate owner revocation emulation containers for each owner. Each container has its own allocation of revocation bits in non-volatile memory, independent of other owners. This segmentation resolves the resource contention problem where the second owner would be limited by the first owner's key revocations, allowing each owner to have full utilization of the revocation protection capability.
Data Source
AI summary
A device having a processor and a boot code, the processor may create a plurality of revocation emulation containers corresponding to a plurality of owners of the electronic device over time, wherein respective revocation emulation containers may comprise asset revocation information associated with respective owners of the electronic device. The processor may program the asset revocation information of the plurality of revocation emulation containers in a one-time-programmable manner. The processor may use the asset revocation information of the plurality of revocation emulation containers to determine whether to revoke use of respective assets of a plurality of assets associated with the plurality of owners of the electronic device over time. The processor may revoke the subsequent use of respective assets of the plurality of assets associated with the plurality of owners of the electronic device over time based on a determination the respective asset should be revoked.


