Electronic Processor Secure Certificate Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Device certificates for electronic processors are challenging to securely provision in untrusted manufacturing environments, as ensuring correct provisioning is difficult, and relying on trusted third-party manufacturers or keeping a trusted server in an untrusted factory poses security risks and costs.

Innovation Solution

The solution involves leveraging secure factory programming techniques by receiving and validating a flashloader, decrypting an encrypted provisioned key bundle using a provisioning key, and executing a provisioning process on the electronic processor, which includes using a common encryption key stored in one-time programmable memory to ensure secure provisioning.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If device certificates are signed by a trusted certificate authority in untrusted manufacturing environments, then device authentication is enabled, but security risks arise from improper provisioning by untrusted manufacturers

Engineering Contradiction:
Improvedevice authenticationVSAvoidsecurity risks from untrusted manufacturing
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by pre-provisioning the electronic processor with security credentials (device certificate, private key, and authorization to operate) before the processor is deployed to the untrusted manufacturing environment. This ensures that the processor inherently possesses authentication capabilities and can securely interact with the trusted server without relying on the untrusted environment for security provisioning.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a trusted server as an intermediary between the untrusted manufacturing environment and the device authentication process. The trusted server securely communicates with the electronic processor using the pre-provisioned credentials, mediating the authentication process and isolating the security-critical operations from the untrusted environment.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If a trusted third-party manufacturer is used to provision device certificates, then security is improved, but manufacturing costs increase

Engineering Contradiction:
Improvesecurity risksVSAvoidmanufacturing cost
Core Design Contradiction:
Object-affected harmful factorsVSEase of manufacture

Solution Approach 1:

The patent applies self-service by enabling the electronic processor to autonomously perform security provisioning using its pre-configured credentials. The processor can independently authenticate with the trusted server and obtain necessary authorizations without requiring manual intervention from trusted third-party manufacturers, thereby reducing manufacturing complexity and cost while maintaining security.

Inventive Principle:
Principle #25Self-service

3Reliability

If a trusted server is kept in an untrusted factory, then device provisioning can be secured, but the security risk of compromising the trusted server increases

Engineering Contradiction:
Improveprovisioning securityVSAvoidrisk of trusted server compromise
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the trusted server from the untrusted factory environment and positions it as a separate, remote entity. The electronic processor maintains secure credentials and can authenticate with the trusted server over secure channels, eliminating the need to physically co-locate the trusted server in the untrusted environment and thereby reducing the attack surface for potential compromises.

Inventive Principle:
Principle #2Taking out (Extraction)

4Object-affected harmful factors

If secure factory programming techniques are used to provision device certificates, then provisioning security is improved, but the complexity of the provisioning process increases

Engineering Contradiction:
Improveimproper provisioningVSAvoidprovisioning process complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent reduces provisioning process complexity by performing the complex security credential generation and embedding operations as preliminary actions during processor manufacturing. The device certificate, private key, and authorization parameters are pre-provisioned into the processor before deployment, simplifying the field provisioning process to essentially verification and activation steps rather than complex cryptographic operations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10979232B2Method for provisioning device certificates for electronic processors in untrusted environments
Publication Date: 2021.04.13 MOTOROLA SOLUTIONS INC
  • US10979232B2 patent drawing
  • US10979232B2 patent drawing
  • US10979232B2 patent drawing

AI summary

Provisioning device certificates for electronic processors. One example method includes receiving a flashloader at the electronic processor. The method also includes validating the flashloader with the electronic processor. After validating the flashloader, the method includes receiving an encrypted provisioned key bundle at the electronic processor. The method also includes decrypting the encrypted provisioned key bundle with the electronic processor using a provisioning key to create a decrypted provisioned key bundle. The method further includes executing a provisioning process on the electronic processor using the decrypted provisioned key bundle.