Secure Server Device for Client Data Provisioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Provisioning data, such as device keys or key pairs, to client devices during manufacturing poses security challenges, including encrypting data so that only the target client device can decrypt it, and authenticating the device during the process.
Innovation Solution
A secure server device generates a provisioning asymmetric cryptographic key pair based on a client device class identifier, using this key pair to establish a shared secret for encrypting data, which is then sent to client devices equipped with trusted hardware, allowing secure decryption and authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If data is provisioned to client devices during manufacturing in a non-trusted facility, then device manufacturing flexibility and productivity are improved, but security of data provisioning is worsened
Solution Approach 1:
The system performs preliminary actions by pre-configuring the client device with a unique identifier and public key before data provisioning. The secure server device uses these pre-configured elements to establish encrypted communication channels and authenticate the device, ensuring security is built into the foundation before any sensitive data is transferred.
Solution Approach 2:
The patent introduces a secure server device as an intermediary between the non-trusted manufacturing facility and the client device. This intermediary establishes secure cryptographic channels, manages key pairs, and handles authentication, thereby mediating the security concerns while allowing manufacturing flexibility.
2Reliability
If asymmetric cryptographic key pairs are generated for each device, then security is improved, but device complexity and manufacturing cost increase
Solution Approach 1:
The cryptographic system is segmented into distinct components: a provisioning asymmetric key pair for secure communication and authentication, and separate operational key pairs for actual data protection. This segmentation allows each key pair to have specialized purposes, simplifying management while maintaining strong security.
Solution Approach 2:
The patent extracts the cryptographic key management complexity from the client device and concentrates it in the secure server device. The client device only needs to store its unique identifier, public key, and decrypted provisioning data, while the secure server device handles generation, management, and rotation of all cryptographic materials.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This method establishes a secure data provisioning channel from a non-trusted manufacturing facility to trusted client devices, ensuring only authorized devices can decrypt the data, thus addressing security issues during device manufacturing.
Implementation Method 1
A secure server device generates a provisioning asymmetric cryptographic key pair based on a client device class identifier, using this key pair to establish a shared secret for encrypting data
Implementation Method 2
using this key pair to establish a shared secret for encrypting data
Implementation Method 3
A secure server device generates a provisioning asymmetric cryptographic key pair based on a client device class identifier, using this key pair to establish a shared secret for encrypting data
Data Source
Figure 1A~1B
Figure 1C~1D
Figure 2
AI summary
Devices and methods for secure provisioning of data to a client device are disclosed. A non-trusted manufacturing facility is equipped with a secure server device to establish a secure data provisioning channel from the secure server device to trusted hardware in client devices without the secure server device and the client devices needing to have a shared secret.