Secure Remote Factory Reset With SPSE Challenge Attestation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for remote resetting of devices to factory default settings lack security and efficiency, as they can be vulnerable to attacker interference and require physical intervention, leading to potential prolonged control by malicious entities and high costs for on-site technician visits.

Innovation Solution

A method utilizing a secure processing and storage environment (SPSE) within the device, which communicates over a network to initiate and confirm a factory default reset, including a challenge-response mechanism and attestation reports to prevent attacker interference and ensure secure remote resetting, while also reducing costs by allowing remote operation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If remote resetting is implemented without secure verification, then ease of operation is improved, but reliability deteriorates due to vulnerability to attacker interference

Engineering Contradiction:
Improveremote resetting capabilityVSAvoidsecurity against attacker interference
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary actions by generating a challenge before the reset operation and requiring a verified response. The SPSE generates a challenge value, sends it to the remote unit, and waits for a cryptographically signed response before initiating the reset. This preliminary verification sequence ensures that only authorized reset requests can trigger the factory default reset, preventing attacker interference while maintaining remote operation capability.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If physical technician intervention is required for resetting, then reliability is improved through direct control, but loss of time increases due to travel and on-site procedures

Engineering Contradiction:
Improvecontrol over reset processVSAvoidtechnician travel and on-site time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system replaces the mechanical system of physical technician intervention with an electronic/cryptographic system. Instead of requiring a technician to physically travel to the device, press buttons, and verify reset completion on-site, the solution uses network communication to transmit reset commands and cryptographic challenge-response mechanisms to verify authorization. The SPSE electronically verifies the signed challenge response and initiates the reset remotely, eliminating travel time while maintaining reliable control through cryptographic verification.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If secure verification mechanisms are added to remote resetting, then reliability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity verificationVSAvoidsecure processing and storage environment
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system extracts the complex security verification functions into a separate, dedicated component called the Secure Processing and Storage Environment (SPSE). Rather than distributing security logic across the entire device firmware, the patent isolates cryptographic key storage, challenge generation, and signature verification into the SPSE module. This extraction allows the main device firmware to remain relatively simple while the SPSE handles the complexity of secure verification, including generating challenges, verifying signed responses, and controlling the reset process based on verification results.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP3929785B1Remote resetting to factory default settings; a method and a device
Publication Date: 2022.05.04 AXIS
  • EP3929785B1 patent drawingFigure 1
  • EP3929785B1 patent drawingFigure 2
  • EP3929785B1 patent drawingFigure 3

AI summary

A method (100), implemented in a device (10), for remote resetting of the device (10) to factory default settings, the device (10) comprising an electric circuit (12) adapted to carry out the factory default reset and a secure processing and storage environment (16), SPSE, the method (100) comprising: receiving (S110, S112), at the SPSE (16), a request to reset the device (10) to factory default settings and a challenge associated with the request, wherein the request and the challenge are received via a network (30); initiating (S120), by the SPSE (16), a reset to factory default settings of the device (10) by communicating with the electric circuit (12) via a communication channel (14); and sending (S180), by the SPSE (16), a confirmation via the network (30), wherein the confirmation includes a response to the challenge as produced by the SPSE (16) and an attestation report, the attestation report being a declaration by the SPSE (16) that the reset to factory default settings is initiated (S120) or carried out.