Secure Remote Factory Reset With SPSE Attestation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for remotely resetting devices to factory default settings lack security, as attackers can prevent or forge reset confirmations, leading to potential prolonged control by malicious entities and increased costs due to unnecessary on-site technician visits.
Innovation Solution
A method utilizing a secure processing and storage environment (SPSE) within the device, which communicates via a network to initiate and confirm a factory default reset, includes receiving a request and challenge, initiating the reset, and sending a confirmation with an attestation report to ensure the reset's authenticity and prevent attacker interference.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a remote reset to factory default settings is implemented without enhanced security measures, then the ease of operation is improved, but the reliability is worsened due to potential attacker interference and confirmation forgery
Solution Approach 1:
The device is segmented into a secure processing and storage environment (SPSE) and other circuitry. The SPSE is isolated and protected from attackers, allowing it to independently verify reset confirmations and generate cryptographic proofs that cannot be forged by malicious entities controlling other parts of the device.
Solution Approach 2:
The SPSE acts as an intermediary between the reset function and the network communication. It receives reset requests, verifies them through cryptographic challenge-response mechanisms, and only sends confirmations after successfully initiating a reset. This intermediary role prevents attackers from directly manipulating reset confirmations.
2Reliability
If a secure processing and storage environment is implemented to prevent confirmation forgery, then the reliability is improved, but the device complexity increases
Solution Approach 1:
The critical security functions are extracted into a separate SPSE that can be implemented using dedicated secure hardware elements. This extraction allows the main device to remain relatively simple while the security-critical operations are handled by specialized, tamper-resistant components designed for their specific purpose.
Solution Approach 2:
The SPSE autonomously manages cryptographic key storage, challenge-response verification, and reset confirmation generation without requiring complex external security infrastructure. The secure element performs these security functions independently, reducing the overall system complexity while maintaining high reliability.
3Reliability
If the SPSE independently verifies reset confirmations using cryptographic challenges, then the reliability is improved, but the use of energy increases due to additional processing
Solution Approach 1:
The SPSE performs cryptographic challenge-response verification only when reset operations are initiated, rather than continuously monitoring all device operations. This partial action approach provides necessary security verification while minimizing energy consumption during normal device operation.
Data Source
AI summary
A method, implemented in a device, for remote resetting of the device to factory default settings, the device comprising an electric circuit adapted to carry out the factory default reset and a secure processing and storage environment, SPSE, the method comprising: receiving, at the SPSE, a request to reset the device to factory default settings and a challenge associated with the request, wherein the request and the challenge are received via a network; initiating, by the SPSE, a reset to factory default settings of the device by communicating with the electric circuit via a communication channel; and sending, by the SPSE, a confirmation via the network, wherein the confirmation includes a response to the challenge as produced by the SPSE and an attestation report, the attestation report being a declaration by the SPSE that the reset to factory default settings is initiated or carried out.


