Protected Memory Device Identity Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In closed computing systems, service providers face challenges in securely identifying and authenticating devices to prevent unauthorized access to premium content, as existing encryption methods can be compromised, and frequent key updates complicate network security and trust establishment.

Innovation Solution

The method involves storing a device-specific number and content in a protected memory location, generating a hash, and encrypting it with an asymmetric encryption key, which is then stored, allowing for secure authentication and authorization by comparing current and prior hash values to ensure content integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption keys are frequently updated to prevent identity theft attacks, then security against attackers is improved, but network complexity and trust establishment requirements worsen

Engineering Contradiction:
Improvesecurity against attackersVSAvoidnetwork complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by embedding unique device identifiers and service keys directly into the device hardware during manufacturing. This pre-configured security architecture eliminates the need for frequent key updates during operation, as the cryptographic material is established beforehand and cannot be easily extracted or copied by attackers.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a manufacturing location as an intermediary authority that performs cryptographic operations during device production. This intermediary embeds security credentials into devices under controlled conditions, eliminating the need for continuous network-based key distribution and reducing network complexity while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encryption keys are frequently updated, then security is improved, but the ability to establish root of trust worsens

Engineering Contradiction:
ImprovesecurityVSAvoidroot of trust
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent establishes root of trust through preliminary action by having the manufacturing location embed unique device identifiers and service keys into device hardware before deployment. This creates a stable, unchangeable cryptographic foundation that persists throughout the device lifecycle, eliminating the need for ongoing network-based trust establishment.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables devices to serve themselves by incorporating self-contained cryptographic credentials during manufacturing. Each device carries its own unique identifier and service keys embedded in hardware, allowing it to autonomously authenticate and access services without relying on external key distribution or continuous network trust verification.

Inventive Principle:
Principle #25Self-service

3Reliability

If service keys are stored in encrypted memory regions, then protection against key theft is improved, but ease of service access worsens

Engineering Contradiction:
Improveprotection against key theftVSAvoidease of service access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies preliminary action by pre-embedding service keys and device identifiers into hardware during manufacturing. This eliminates the need for runtime decryption operations, as the cryptographic material is already in place and ready for use. Services can be accessed directly using the pre-configured credentials without additional security overhead.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables devices to serve themselves by incorporating self-contained cryptographic credentials during manufacturing. Each device carries its own unique identifier and service keys embedded in hardware, allowing it to autonomously authenticate and access services without relying on external key distribution or continuous network trust verification.

Inventive Principle:
Principle #25Self-service

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This solution enhances security by making it difficult for attackers to tamper with or duplicate device identities, and eliminates the need for frequent key updates, maintaining secure access control within the ecosystem.

Implementation Method 1

encrypting the hash using an asymmetric encryption key

Methodology Applied
Scientific EffectAsymmetric encryption:

Implementation Method 2

generating a hash of the content in the protected memory location and the device specific number

Methodology Applied
Scientific EffectHashing:

Data Source

PatentUS9647847B2Tamper evidence per device protected identity
Publication Date: 2017.05.09 MICROSOFT TECHNOLOGY LICENSING LLC
  • US9647847B2 patent drawing
  • US9647847B2 patent drawing
  • US9647847B2 patent drawing

AI summary

Various techniques are described to protect secrets held by closed computing devices. In an ecosystem where devices operate and are offered a wide range of services from a service provider, the service provider may want to prevent users from sharing services between devices. In order to guarantee that services are not shared between devices, each device can be manufactured with a different set of secrets such as per device identifiers. Unscrupulous individuals may try to gain access to the secrets and transfer secrets from one device to another. In order to prevent this type of attack, each closed computing system can be manufactured to include a protected memory location that is tied to the device.