Secure Server Device for Client Data Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Provisioning data, such as device keys or key pairs, to client devices during manufacturing poses security challenges, including encrypting data so that only the target client device can decrypt it, and authenticating the device during the process.

Innovation Solution

A secure server device generates a provisioning asymmetric cryptographic key pair based on a client device class identifier, using this key pair to establish a shared secret for encrypting data, which is then sent to client devices equipped with trusted hardware, allowing secure decryption and authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If data is provisioned to client devices during manufacturing in a non-trusted facility, then device manufacturing flexibility and productivity are improved, but security of data provisioning is worsened

Engineering Contradiction:
Improvedevice manufacturing efficiencyVSAvoiddata provisioning security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary actions by pre-configuring the client device with a unique identifier and public key before data provisioning. The secure server device uses these pre-configured elements to establish encrypted communication channels and authenticate the device, ensuring security is built into the foundation before any sensitive data is transferred.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a secure server device as an intermediary between the non-trusted manufacturing facility and the client device. This intermediary establishes secure cryptographic channels, manages key pairs, and handles authentication, thereby mediating the security concerns while allowing manufacturing flexibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If asymmetric cryptographic key pairs are generated for each device, then security is improved, but device complexity and manufacturing cost increase

Engineering Contradiction:
Improvedata encryption securityVSAvoidcryptographic key management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The cryptographic system is segmented into distinct components: a provisioning asymmetric key pair for secure communication and authentication, and separate operational key pairs for actual data protection. This segmentation allows each key pair to have specialized purposes, simplifying management while maintaining strong security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts the cryptographic key management complexity from the client device and concentrates it in the secure server device. The client device only needs to store its unique identifier, public key, and decrypted provisioning data, while the secure server device handles generation, management, and rotation of all cryptographic materials.

Inventive Principle:
Principle #2Taking out (Extraction)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This method establishes a secure data provisioning channel from a non-trusted manufacturing facility to trusted client devices, ensuring only authorized devices can decrypt the data, thus addressing security issues during device manufacturing.

Implementation Method 1

A secure server device generates a provisioning asymmetric cryptographic key pair based on a client device class identifier, using this key pair to establish a shared secret for encrypting data

Methodology Applied
Scientific EffectAsymmetric cryptographic key pair generation:

Implementation Method 2

using this key pair to establish a shared secret for encrypting data

Methodology Applied
Scientific EffectCryptographic key exchange:

Implementation Method 3

A secure server device generates a provisioning asymmetric cryptographic key pair based on a client device class identifier, using this key pair to establish a shared secret for encrypting data

Methodology Applied
Scientific EffectSymmetric cryptographic encryption:

Data Source

PatentEP3695561B1Secure provisioning of data to client device
Publication Date: 2022.04.27 HUAWEI TECH CO LTD
  • EP3695561B1 patent drawingFigure 1A~1B
  • EP3695561B1 patent drawingFigure 1C~1D
  • EP3695561B1 patent drawingFigure 2

AI summary

Devices and methods for secure provisioning of data to a client device are disclosed. A non-trusted manufacturing facility is equipped with a secure server device to establish a secure data provisioning channel from the secure server device to trusted hardware in client devices without the secure server device and the client devices needing to have a shared secret.