Security Chip One-Time Programmable Slots Multi-Entity Trusts
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing information handling systems face challenges in supporting multiple independent silicon-rooted trusts, limiting the ability of end users to have total control over firmware, identity, and keys without compromising supply-chain assurances, often requiring different SoCs or motherboards for various products.
Innovation Solution
A security chip with a programmable read-only memory featuring one-time programmable slots and a counter that allows for the creation and invalidation of multiple independent trusts, enabling a single security chip to be used across multiple business lines with different firmware, identity, and keys, while maintaining ownership and renter entity privileges.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple independent silicon-rooted trusts are supported, then the ability of end users to have total control over firmware, identity, and keys is improved, but the system complexity increases requiring different SoCs or motherboards for various products
Solution Approach 1:
The security chip is designed with multiple one-time programmable slots that can store different groups of keys for different entities, allowing a single chip design to serve multiple business lines and applications. The chip can function as different silicon-rooted trusts by programming different slots with different key groups, eliminating the need for different SoC designs for different products.
2Device complexity
If a single security chip is used across multiple business lines, then device complexity is reduced, but the ability to maintain both ownership and renter entity privileges simultaneously is challenged
Solution Approach 1:
The security chip's key storage is segmented into multiple one-time programmable slots, with each slot capable of storing a separate group of keys for a different entity. This segmentation allows the chip to maintain distinct key groups for owner entities and renter entities simultaneously, with each slot operating as an independent trust domain while being managed through a unified counter mechanism.
Solution Approach 2:
A one-time programmable counter is introduced as an intermediary mechanism to manage the validity state of different key groups. The counter tracks which slots are active and can be programmed only once, providing a controlled mechanism to switch between different entity privileges (owner or renter) without compromising the security of stored key groups.
3Reliability
If one-time programmable slots are used to store key groups, then security is improved, but the flexibility to modify keys after programming is lost
Solution Approach 1:
The system performs preliminary programming of key groups into one-time programmable slots during manufacturing or initial setup. The one-time programmable nature ensures that once keys are written, they cannot be modified or tampered with, providing strong security guarantees. The counter mechanism is also preliminarily set to track which slots have been programmed, preventing any future modification attempts.
Data Source
AI summary
A compute device of an information handling system includes a security chip. The security chip includes a programmable read only memory, which in turn includes multiple one-time programmable slots and a one-time programmable slot counter. A first slot of the one-time programmable slots stores a first group of keys associated with a first entity of the security chip. A second slot of the one-time programmable slots stores a second group of keys associated with a second entity of the security chip. The one-time programmable slot counter includes multiple entries. Each of the entries is associated with a different one of the one-time programmable slots. Each of the entries is preset to a first value. The one-time programmable slot counter is only able to count in one direction. A first entry of the entries is updated to invalidate the second group of keys associated with the second entity.


