Provisioning Control Apparatus Secure Vault Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security enclaves in electronic components with limited hardware resources, such as chips or microprocessors, are insufficient to store the necessary cryptographic keys and configuration data securely, limiting their security capabilities.
Innovation Solution
A provisioning control apparatus that encrypts security-sensitive provisioning data using a secure vault encryption key and securely provides it to the electronic component's hardware security enclave and non-volatile memory, creating a secure vault for storing sensitive data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security enclaves are used to store cryptographic keys, then security is improved, but the number of keys that can be stored is limited due to hardware resource constraints
Solution Approach 1:
The patent divides the storage system into two segments: a hardware security enclave for storing critical encryption keys and a non-volatile memory for storing additional cryptographic keys. This segmentation allows the system to overcome the limited capacity of the security enclave while maintaining security through encrypted storage in the non-volatile memory.
Solution Approach 2:
The patent introduces an intermediary mechanism - a secure vault with encryption - that bridges the hardware security enclave and the non-volatile memory. The security enclave stores encryption keys that protect data in the non-volatile memory, acting as an intermediary that enables extended key storage while maintaining security guarantees.
2Reliability
If hardware security enclaves are used, then security capabilities are improved, but hardware resource consumption increases
Solution Approach 1:
The patent uses the hardware security enclave as an intermediary that performs only the essential key protection functions, while the actual storage of cryptographic keys is handled by the non-volatile memory. This intermediary approach allows security capabilities to be improved without proportionally increasing hardware resource consumption.
Solution Approach 2:
The patent creates a virtual extension of the security enclave's capabilities through encrypted storage in non-volatile memory. Instead of physically expanding the security enclave hardware, the system creates a secure virtual storage space that behaves like an extension of the enclave, reducing the need for additional hardware resources.
3Reliability
If configuration data is stored in the security enclave, then security is improved, but the limited memory size of the enclave prevents sufficient storage
Solution Approach 1:
The patent segments the storage of configuration data between the security enclave (for critical security parameters) and the non-volatile memory (for additional configuration data). This segmentation allows sufficient storage capacity while maintaining security through encrypted access control.
Solution Approach 2:
The patent introduces encryption as an intermediary mechanism that allows configuration data to be stored securely in the non-volatile memory. The security enclave provides the encryption keys that protect the configuration data, creating an intermediary security layer that enables extended storage without compromising security.
Data Source
Figure 1
Figure 2a
Figure 2b
AI summary
The invention relates to a provisioning control apparatus (140) configured to be coupled to a provisioning equipment server (160), the provisioning equipment server (160) being electrically connectable with one or more electronic components (170) for provisioning the one or more electronic components (170) with security sensitive provisioning data (150), each electronic component (170) comprising a security enclave and a non-volatile memory. The provisioning control apparatus (140) comprises a processor (141) configured to encrypt the security sensitive provisioning data (150) using a secure vault encryption key for obtaining encrypted security sensitive provisioning data (150). Moreover, the provisioning control apparatus (140) comprises a communication interface (143) configured to securely provide the secure vault encryption key to the provisioning equipment server (160) for storing the secure vault encryption key in the security enclave of the electronic component (170). The communication interface (143) is further configured to provide the encrypted security sensitive provisioning data (150) to the provisioning equipment server (160) for storing the encrypted security sensitive provisioning data in the non-volatile memory of the electronic component (170) and thereby creating a secure vault in the non-volatile memory of the electronic component (170) for securely storing the encrypted security sensitive provisioning data (150).