Secure Computing Hardware Secret Generator Module

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing device authentication methods are flawed, allowing hostile parties to frustrate accurate identification due to reliance on certificate authorities and private keys that can be stolen or shared, making it difficult to definitively identify devices.

Innovation Solution

A secure computing hardware apparatus is developed, featuring a secret generator module that produces a module-specific secret, which is used to generate a delegable and anonymizable signature, ensuring the authenticity and integrity of devices through secure proof protocols resistant to tampering and analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If certificate authorities and private keys are used for device authentication, then device identification can be established, but the system becomes vulnerable to key theft and sharing by hostile parties

Engineering Contradiction:
Improvedevice identification reliabilityVSAvoidvulnerability to key theft and sharing
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication secret from software-based key storage and embeds it directly in hardware circuitry. The secret is generated and stored within the secure computing hardware apparatus, physically separating it from external access points that could be compromised by hackers or malware.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a hardware-based secret generator as an intermediary between the device and authentication protocols. This hardware component acts as a trusted mediator that produces authentication secrets without exposing them to software layers that could be compromised, thereby breaking the direct connection between authentication credentials and vulnerable software systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If traditional authentication methods are used, then device identity can be verified, but accurate identification is frustrated by hostile parties sharing private keys

Engineering Contradiction:
Improvedevice identification accuracyVSAvoididentification trustworthiness
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent segments the authentication system into distinct hardware and software components. The secret generation and storage functions are isolated in dedicated hardware circuitry, while software components only interact through controlled interfaces. This segmentation ensures that even if software is compromised, the core authentication secret remains protected in hardware.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent replaces software-based key management mechanisms with hardware-based secret generation and protection. Instead of relying on software to protect private keys, the system uses physical hardware properties and circuit-level security to generate and safeguard authentication secrets, making them resistant to software-based attacks.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11831777B2Secure computing hardware apparatus
Publication Date: 2023.11.28 ARES TECHNOLOGIES INC
  • US11831777B2 patent drawing
  • US11831777B2 patent drawing
  • US11831777B2 patent drawing

AI summary

A secure computing hardware apparatus includes at least a secret generator module, the at least a secret generator module configured to generate a module-specific secret, and a device identifier circuit communicatively connected to the at least a secret generator, the device identifier circuit configured to produce at least an output comprising a secure proof of the module-specific secret. Secret generator module may implement one or more physically unclonable functions to generate the module-specific secret.