Secure Software Hardware Association via Cryptographic Binding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Original equipment manufacturers (OEMs) face revenue loss and brand equity degradation due to device cloning and unauthorized production, where stolen hardware designs and software are used to create low-cost clones, and hackers modify systems to disrupt business models, leading to unauthorized use and overbuilding.

Innovation Solution

Cryptographically binding OEM hardware with OEM program code using symmetric and asymmetric cryptography to ensure that hardware runs only approved program code, preventing replication or alteration, through secure software and hardware association (SSHA) techniques, which include authenticating program code and generating ChipID tokens for verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If TCG TPM is used to store keys and digital certificates, then security of digital signature and key exchange is improved, but control over executed software is lost

Engineering Contradiction:
Improvesecurity of digital signature and key exchangeVSAvoidcontrol over executed software
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent divides the security function into two independent parts: the TPM handles cryptographic key storage and digital signature verification (immutable security functions), while a new controller component handles runtime software control and hardware/software binding (flexible control functions). This segmentation allows each component to specialize without compromising the other.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new controller as an intermediary between the TPM and the executed software. This controller receives cryptographic proofs from the TPM and uses them to enable/disable software execution, thereby mediating between security requirements and control flexibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of manufacture

If hardware designs are stolen and cloned, then manufacturing cost is reduced, but OEM revenue and brand equity are lost

Engineering Contradiction:
Improvemanufacturing costVSAvoidOEM revenue protection
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent performs preliminary binding of cryptographic keys to specific hardware identifiers during the manufacturing process. The TPM is programmed with hardware-specific keys before the product reaches the customer, making it impossible for clones to replicate the exact hardware/software binding even if they copy the design.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates a composite security mechanism that combines hardware identifiers, cryptographic keys stored in TPM, and software binding layers. This multi-layer composite approach makes cloning extremely difficult as it would require replicating not just the hardware design but also the unique cryptographic binding to specific hardware.

Inventive Principle:
Principle #40Composite materials

3Ease of operation

If software is copied to unauthorized hardware, then system functionality is maintained, but OEM authorization is violated

Engineering Contradiction:
Improvesystem functionalityVSAvoidOEM authorization
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements a feedback mechanism where the TPM continuously verifies hardware identifiers against stored binding information during software execution. If unauthorized hardware is detected, the system receives feedback to terminate execution, thereby maintaining authorization integrity while allowing legitimate software to run normally.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent replaces traditional mechanical/license-based software protection with cryptographic verification using TPM. Instead of relying on copy protection mechanisms that can be bypassed, the system uses mathematical cryptography to prove hardware/software binding, making unauthorized execution mathematically impossible.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS8677144B2Secure software and hardware association technique
Publication Date: 2014.03.18 MARVELL ASIA PTE LTD
  • US8677144B2 patent drawing
  • US8677144B2 patent drawing
  • US8677144B2 patent drawing

AI summary

In an embodiment, authenticated hardware and authenticated software are cryptographically binded using symmetric and asymmetric cryptography. Cryptographically binding the hardware and software ensures that original equipment manufacturer (OEM) hardware will only run OEM software. Cryptographically binding the hardware and software protects the OEM binary code so it will only run on the OEM hardware and cannot be replicated or altered to operate on unauthorized hardware. This cryptographic binding technique is referred to herein as secure software and hardware association (SSHA).