Peripheral Onboarding via Cryptographic Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure input/output technologies face challenges in establishing trustworthiness of peripherals during onboarding in IoT systems, particularly in preventing malicious attacks and ensuring authorized device connections, due to high costs and labor requirements, and lack of industrial open standards.

Innovation Solution

The implementation of a mechanism using enhanced privacy identification (EPID) identifiers, TCG DICE identifiers, and IEEE 802.11AR identifiers, leveraging secure device onboarding primitives, system firmware, and trusted platform module (TPM) measurements to onboard peripherals securely, ensuring only authorized devices are connected and data is trusted, through a process of identifier exchange, platform state validation, and challenge-response validation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional secure I/O mechanisms are used to establish trustworthiness of peripherals, then security is improved, but cost and labor requirements increase significantly

Engineering Contradiction:
Improvetrustworthiness of peripheralsVSAvoidcost and labor requirements
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent replaces complex mechanical secure I/O mechanisms with a software-based cryptographic verification system. Instead of using dedicated hardware security modules and proprietary protocols, the system uses standard bus interfaces combined with cryptographic primitives (hash functions, challenge-response authentication) to achieve the same security goals at lower cost and without specialized components

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent creates a universal onboarding mechanism that works across different peripheral devices and computing platforms using standard interfaces. The challenge-response authentication protocol and hash-based verification can be applied to any peripheral that can communicate over standard buses (USB, PCI, etc.), eliminating the need for device-specific security implementations

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If proprietary secure onboarding components are implemented, then security is improved, but device complexity and compatibility requirements increase

Engineering Contradiction:
ImprovesecurityVSAvoidproprietary components
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent eliminates proprietary hardware security components by substituting them with software-based cryptographic verification. The system uses standard bus interfaces and software agents to perform authentication, replacing the need for specialized security hardware and reducing device complexity

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent changes the approach from hardware-based security parameters to software-based cryptographic parameters. Instead of relying on physical security features, the system uses hash function outputs, cryptographic keys, and authentication tokens that can be implemented in software without additional hardware

Inventive Principle:
Principle #35Parameter changes

3Reliability

If manual verification of peripheral devices is performed, then security is improved, but productivity and onboarding speed decrease

Engineering Contradiction:
Improveauthorized device connectionsVSAvoidonboarding speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements self-service onboarding where the peripheral device and computing device automatically perform mutual authentication without user intervention. The secure device onboarding agents on both devices handle the challenge-response verification automatically, enabling zero-touch onboarding while maintaining security

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs security verification in advance during the onboarding process itself, rather than requiring manual verification later. The challenge-response authentication and hash verification are completed automatically when the device is first connected, ensuring security is established before any data transfer occurs

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10678938B2Trustworthy peripheral transfer of ownership
Publication Date: 2020.06.09 INTEL CORP
  • US10678938B2 patent drawing
  • US10678938B2 patent drawing
  • US10678938B2 patent drawing

AI summary

Systems and techniques for trustworthy peripheral transfer of ownership are described herein. A unique peripheral identifier may be received from an ownership manifest of the peripheral device. The unique peripheral identifier may be transferred to a bus controller for a bus between the computing device and the peripheral device. A measurement may be received from the peripheral device by the basic input and output system of the computing device. A measurement of a computing platform of the computing device may be generated. The measurement may indicate peripheral devices interconnected to the computing device. Data transfer between the peripheral device and the computing device may be allowed via the bus based on validation of the measurement of the computing platform against a platform configuration register of the computing device.