Secure Configuration Updates Using Signed Certificates
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing configuration update methods for electronic products in zero-trust environments are vulnerable to malicious attacks, as they rely on insecure password-based access control and encryption, which can lead to unauthorized tampering and breaches, compromising the integrity and safety of systems like industrial robots.
Innovation Solution
Implementing a secure configuration update system that uses signed security certificates and authentication flows, combining keys stored in flash memory and OTP memory, allowing verification of configuration data integrity and authenticity, and enabling updates by trusted third parties without direct intervention from silicon providers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If password-based access control and encryption are used for configuration updates, then ease of operation is improved, but security and reliability deteriorate due to vulnerability to malicious attacks and unauthorized tampering
Solution Approach 1:
The patent introduces a trusted third party (silicon provider) as an intermediary that signs configuration updates with cryptographic certificates. This mediator verifies the authenticity and integrity of configuration data before it is applied, eliminating the need for password-based access control while maintaining security through certificate-based authentication and verification mechanisms
2Reliability
If direct intervention from silicon providers is required for configuration updates, then security is improved through centralized control, but device complexity and operational overhead increase
Solution Approach 1:
The patent enables authorized third parties to perform configuration updates independently by presenting valid signatures and certificates. The system automatically verifies the authenticity of updates through cryptographic verification without requiring direct intervention from silicon providers, thereby reducing operational overhead while maintaining security through certificate-based authentication
3Ease of manufacture
If configuration data is stored in flash memory, then ease of manufacture and data persistence are improved, but security deteriorates due to potential unauthorized access and tampering
Solution Approach 1:
The patent implements preliminary cryptographic verification of configuration data before it is stored in flash memory. The system verifies digital signatures and authentication certificates in advance to ensure data integrity and authenticity, preventing unauthorized tampering with stored configuration data while maintaining ease of manufacture through standardized security protocols
Data Source
AI summary
Disclosed examples generate an original equipment manufacturer (OEM) private key and an OEM public key; generate an OEM certificate based on the OEM public key; cause sending of the OEM certificate from an OEM product to a silicon provider, the silicon provider to sign the OEM certificate based on a silicon provider private key; and cause storage of the signed OEM certificate in the OEM product.


