Security Device for OEM Data Storage on Untrusted Hardware

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Original equipment manufacturers (OEMs) face challenges in securely storing valuable data on target data processing devices when using untrusted contract manufacturers, as they cannot ensure the data is not misused or stored on unauthorized devices.

Innovation Solution

A method involving a security data processing device that obtains and verifies a device cryptographic certificate from the target data processing device, generates and stores encrypted data, and decrements a permitted number of devices to prevent unauthorized storage, using public key cryptography to establish shared keys and ensure data integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If data is stored on target data processing devices using contract manufacturers, then manufacturing costs are reduced, but data security and trust are compromised

Engineering Contradiction:
Improvemanufacturing costVSAvoiddata security
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

A security data processing device acts as an intermediary between the OEM and the contract manufacturer. This device performs cryptographic operations including generating device certificates, encrypting data, and managing storage permissions. By introducing this intermediary, the system enables OEMs to work with untrusted contract manufacturers while maintaining data security through cryptographic mediation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional mechanical/trust-based manufacturing processes with cryptographic mechanisms. Instead of relying on trust relationships or physical control, the system uses public key cryptography, digital certificates, and encrypted storage to secure data. This substitution allows data to be securely stored on devices manufactured by untrusted entities.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If data is stored on target data processing devices, then manufacturing efficiency is improved, but unauthorized data modification and storage become possible

Engineering Contradiction:
Improvemanufacturing efficiencyVSAvoiddata modification and unauthorized storage
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The security data processing device performs preliminary actions by generating device cryptographic certificates before data storage. It also pre-establishes encryption keys and storage permissions. These preliminary cryptographic setup actions ensure that when data is stored, it cannot be modified or accessed by unauthorized entities, as the security constraints are already in place.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where the security data processing device monitors and controls storage operations. It tracks which devices are authorized to store data and enforces permission limits. This feedback control prevents unauthorized storage and modification by continuously verifying that only approved devices access the data.

Inventive Principle:
Principle #23Feedback

3Reliability

If cryptographic verification is performed for each device, then data integrity is ensured, but processing time increases

Engineering Contradiction:
Improvedata integrityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Device cryptographic certificates are generated and stored in advance before the actual data storage operation. This preliminary certificate generation allows the verification process during data storage to be faster, as the certificates are already ready for immediate verification without needing to perform complex cryptographic operations at the time of data storage.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11743055B2Storing data on target data processing devices
Publication Date: 2023.08.29 SECURE THINGZ
  • US11743055B2 patent drawing
  • US11743055B2 patent drawing

AI summary

A method of storing data on target data processing devices, the method comprising: for each target data processing device, using a security data processing device on which first data has been stored to: obtain a device cryptographic certificate from the target data processing device, the device cryptographic certificate having been generated by, and being verifiable as having been generated by, a trusted entity; verify the device cryptographic certificate as having been generated by the trusted entity; generate second data using the first data; and store the second data on the target data processing device.