Secure Enclave Firmware Integrity in Insecure Manufacturing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Insecure manufacturing environments for embedded devices pose challenges in protecting the integrity and confidentiality of firmware, as contract manufacturers may lack physical security measures to safeguard proprietary firmware during the assembly and testing process.

Innovation Solution

A system and method that involves a Secure Enclave within the embedded device, which verifies unauthenticated content and establishes a secure connection for loading firmware, ensuring that the firmware is encrypted and inaccessible outside the device, thereby maintaining integrity and confidentiality without relying on physical security measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical security measures are implemented at the contract manufacturer's premises, then the confidentiality and integrity of firmware are improved, but the manufacturing cost and complexity increase significantly

Engineering Contradiction:
Improvefirmware integrity and confidentialityVSAvoidsecurity infrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces physical security measures (mechanical systems like secure facilities, guards, and access controls) with cryptographic security mechanisms. The Secure Enclave performs cryptographic verification of firmware authenticity and establishes encrypted communication channels, substituting the need for physical security infrastructure while maintaining firmware protection in contract manufacturer environments.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If the contract manufacturer produces products for multiple OEM customers, then the productivity and versatility of the manufacturing facility improve, but the ability to physically secure the premises and protect firmware confidentiality deteriorates

Engineering Contradiction:
Improvemanufacturing throughputVSAvoidfirmware confidentiality
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces cryptographic intermediaries (digital certificates, encrypted communication protocols, and the Secure Enclave) between the firmware and the manufacturing environment. These cryptographic layers act as mediators that protect firmware confidentiality regardless of how many different OEM customers the contract manufacturer serves, allowing high productivity while maintaining security through software-based isolation rather than physical segregation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If firmware is transferred in plaintext for programming purposes, then the ease of operation and programming speed improve, but the risk of unauthorized access and firmware compromise increases

Engineering Contradiction:
Improvefirmware programming easeVSAvoidfirmware exposure to unauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent changes the state parameter of firmware from plaintext to encrypted form during transfer and storage. The Secure Enclave manages cryptographic keys and performs decryption only within its protected boundary, allowing the firmware to be transferred and programmed while maintaining encryption during transit. This parameter change (from plaintext to encrypted) protects against unauthorized access while still enabling programming operations through controlled decryption within the Secure Enclave.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10860744B2System and method for ensuring integrity and confidentiality of data programmed in an insecure manufacturing environment
Publication Date: 2020.12.08 SILICON LABORATORIES INC
  • US10860744B2 patent drawing
  • US10860744B2 patent drawing
  • US10860744B2 patent drawing

AI summary

A system and method of downloading firmware into an embedded device while maintaining the integrity and confidentiality of the firmware is disclosed. In one embodiment, the process comprises four phases. In the first phase, unauthenticated content is written into the memory of the embedded device. In the second phase, this content is verified. In the third step, a secure connection is established between the host and the embedded device. In the fourth step, the firmware is loaded into the embedded device using this secure connection. The firmware is encrypted as it is transferred from the host to the embedded device and is never accessible outside of the embedded device.