Electronic Processor Secure Certificate Provisioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Device certificates for electronic processors are challenging to securely provision in untrusted manufacturing environments, as ensuring correct provisioning is difficult, and relying on trusted third-party manufacturers or keeping a trusted server in an untrusted factory poses security risks and costs.
Innovation Solution
The solution involves leveraging secure factory programming techniques by receiving and validating a flashloader, decrypting an encrypted provisioned key bundle using a provisioning key, and executing a provisioning process on the electronic processor, which includes using a common encryption key stored in one-time programmable memory to ensure secure provisioning.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If device certificates are signed by a trusted certificate authority in untrusted manufacturing environments, then device authentication is enabled, but security risks arise from improper provisioning by untrusted manufacturers
Solution Approach 1:
The patent applies preliminary action by pre-provisioning the electronic processor with security credentials (device certificate, private key, and authorization to operate) before the processor is deployed to the untrusted manufacturing environment. This ensures that the processor inherently possesses authentication capabilities and can securely interact with the trusted server without relying on the untrusted environment for security provisioning.
Solution Approach 2:
The patent introduces a trusted server as an intermediary between the untrusted manufacturing environment and the device authentication process. The trusted server securely communicates with the electronic processor using the pre-provisioned credentials, mediating the authentication process and isolating the security-critical operations from the untrusted environment.
2Object-affected harmful factors
If a trusted third-party manufacturer is used to provision device certificates, then security is improved, but manufacturing costs increase
Solution Approach 1:
The patent applies self-service by enabling the electronic processor to autonomously perform security provisioning using its pre-configured credentials. The processor can independently authenticate with the trusted server and obtain necessary authorizations without requiring manual intervention from trusted third-party manufacturers, thereby reducing manufacturing complexity and cost while maintaining security.
3Reliability
If a trusted server is kept in an untrusted factory, then device provisioning can be secured, but the security risk of compromising the trusted server increases
Solution Approach 1:
The patent extracts the trusted server from the untrusted factory environment and positions it as a separate, remote entity. The electronic processor maintains secure credentials and can authenticate with the trusted server over secure channels, eliminating the need to physically co-locate the trusted server in the untrusted environment and thereby reducing the attack surface for potential compromises.
4Object-affected harmful factors
If secure factory programming techniques are used to provision device certificates, then provisioning security is improved, but the complexity of the provisioning process increases
Solution Approach 1:
The patent reduces provisioning process complexity by performing the complex security credential generation and embedding operations as preliminary actions during processor manufacturing. The device certificate, private key, and authorization parameters are pre-provisioned into the processor before deployment, simplifying the field provisioning process to essentially verification and activation steps rather than complex cryptographic operations.
Data Source
AI summary
Provisioning device certificates for electronic processors. One example method includes receiving a flashloader at the electronic processor. The method also includes validating the flashloader with the electronic processor. After validating the flashloader, the method includes receiving an encrypted provisioned key bundle at the electronic processor. The method also includes decrypting the encrypted provisioned key bundle with the electronic processor using a provisioning key to create a decrypted provisioned key bundle. The method further includes executing a provisioning process on the electronic processor using the decrypted provisioned key bundle.


