Remote Secure Device Conversion via Cryptographic Certificate

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Developers face barriers in accessing development hardware for secure devices like gaming consoles, requiring lengthy approval processes and specialized hardware acquisition, limiting the availability of development tools and increasing costs.

Innovation Solution

A system and method for remotely activating secure devices for development capabilities, allowing any retail-purchased device to be converted into a development-capable hardware by generating and transmitting a cryptographically signed certificate that interacts with the security processor to unlock developer mode, enabling sandboxing and protecting against malicious code.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If developers use specialized development hardware devices (dev kits) to develop applications for secure devices, then developers can run unapproved software for development and testing, but developers face barriers in accessing development hardware requiring lengthy approval processes and specialized hardware acquisition

Engineering Contradiction:
Improveaccessibility of development hardwareVSAvoidtime for approval process and hardware acquisition
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent creates a cryptographic copy of the development kit's security credentials (certificate and key) and transmits them to the retail device. This allows the retail device to replicate the security profile of a development kit without requiring physical possession of specialized hardware, thereby eliminating acquisition barriers and approval processes while maintaining security integrity through cryptographic verification.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system introduces a certificate authority and cryptographic certificate as an intermediary between the development kit and the retail device. This intermediary mechanism enables secure communication and trust establishment without requiring direct physical connection or specialized hardware, allowing remote activation of development capabilities through network-based certificate transmission.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If specialized development hardware is required for application development, then security is maintained through hardware-level protection, but costs increase and availability of development tools is limited

Engineering Contradiction:
Improvesecurity protectionVSAvoidhardware acquisition complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces the mechanical/physical security system (specialized development hardware devices) with a cryptographic software-based system (certificates and keys). This substitution eliminates the need for complex hardware acquisition and distribution infrastructure while maintaining security through cryptographic verification, thereby reducing device complexity and increasing accessibility without compromising security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If retail-purchased devices are converted into development-capable hardware, then accessibility and efficiency for developers increases and costs are reduced, but protection against piracy and malicious code must be maintained

Engineering Contradiction:
Improvedeveloper device compatibilityVSAvoidpiracy and malicious code
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies different security profiles to different operational modes of the device. The certificate contains mode-specific permissions that enable development capabilities when in developer mode while maintaining restrictions when in retail mode. This local quality approach allows the same device to exhibit different security characteristics depending on the active mode, enabling versatility for developers while maintaining protection against piracy and malicious code through mode-specific access controls.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system implements feedback mechanisms where the security processor continuously verifies certificate validity and device state. The certificate authority can revoke certificates if security violations are detected, and the system monitors for unauthorized modifications. This feedback loop ensures that even when development capabilities are unlocked, the system remains protected by actively detecting and responding to potential security threats.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10158495B2Remote hardware device conversion
Publication Date: 2018.12.18 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10158495B2 patent drawing
  • US10158495B2 patent drawing
  • US10158495B2 patent drawing

AI summary

Examples of the disclosure remotely activate a secure device for application development. A request is received at a device entitlement component for a developer kit from a secure device in a user mode via a network. A determination is made as to whether the secure device is in at least one allowed development group. In response to determining that the secure device is in the at least one allowed development group, a certificate is generated defining a permissions level associated with the developer identifier for the secure device. The certificate is transmitted to the secure device, including a key that interacts with a security processor of the secure device to convert hardware capabilities of the secure device to provide a developer mode at the secure device.