Secure Remote Factory Reset With SPSE Challenge Attestation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for remote resetting of devices to factory default settings lack security and efficiency, as they can be vulnerable to attacker interference and require physical intervention, leading to potential prolonged control by malicious entities and high costs for on-site technician visits.
Innovation Solution
A method utilizing a secure processing and storage environment (SPSE) within the device, which communicates over a network to initiate and confirm a factory default reset, including a challenge-response mechanism and attestation reports to prevent attacker interference and ensure secure remote resetting, while also reducing costs by allowing remote operation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If remote resetting is implemented without secure verification, then ease of operation is improved, but reliability deteriorates due to vulnerability to attacker interference
Solution Approach 1:
The system performs preliminary actions by generating a challenge before the reset operation and requiring a verified response. The SPSE generates a challenge value, sends it to the remote unit, and waits for a cryptographically signed response before initiating the reset. This preliminary verification sequence ensures that only authorized reset requests can trigger the factory default reset, preventing attacker interference while maintaining remote operation capability.
2Reliability
If physical technician intervention is required for resetting, then reliability is improved through direct control, but loss of time increases due to travel and on-site procedures
Solution Approach 1:
The system replaces the mechanical system of physical technician intervention with an electronic/cryptographic system. Instead of requiring a technician to physically travel to the device, press buttons, and verify reset completion on-site, the solution uses network communication to transmit reset commands and cryptographic challenge-response mechanisms to verify authorization. The SPSE electronically verifies the signed challenge response and initiates the reset remotely, eliminating travel time while maintaining reliable control through cryptographic verification.
3Reliability
If secure verification mechanisms are added to remote resetting, then reliability is improved, but device complexity increases
Solution Approach 1:
The system extracts the complex security verification functions into a separate, dedicated component called the Secure Processing and Storage Environment (SPSE). Rather than distributing security logic across the entire device firmware, the patent isolates cryptographic key storage, challenge generation, and signature verification into the SPSE module. This extraction allows the main device firmware to remain relatively simple while the SPSE handles the complexity of secure verification, including generating challenges, verifying signed responses, and controlling the reset process based on verification results.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method (100), implemented in a device (10), for remote resetting of the device (10) to factory default settings, the device (10) comprising an electric circuit (12) adapted to carry out the factory default reset and a secure processing and storage environment (16), SPSE, the method (100) comprising: receiving (S110, S112), at the SPSE (16), a request to reset the device (10) to factory default settings and a challenge associated with the request, wherein the request and the challenge are received via a network (30); initiating (S120), by the SPSE (16), a reset to factory default settings of the device (10) by communicating with the electric circuit (12) via a communication channel (14); and sending (S180), by the SPSE (16), a confirmation via the network (30), wherein the confirmation includes a response to the challenge as produced by the SPSE (16) and an attestation report, the attestation report being a declaration by the SPSE (16) that the reset to factory default settings is initiated (S120) or carried out.