Security Device for OEM Data Storage on Untrusted Hardware
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Original equipment manufacturers (OEMs) face challenges in securely storing valuable data on target data processing devices when using untrusted contract manufacturers, as they cannot ensure the data is not misused or stored on unauthorized devices.
Innovation Solution
A method involving a security data processing device that obtains and verifies a device cryptographic certificate from the target data processing device, generates and stores encrypted data, and decrements a permitted number of devices to prevent unauthorized storage, using public key cryptography to establish shared keys and ensure data integrity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If data is stored on target data processing devices using contract manufacturers, then manufacturing costs are reduced, but data security and trust are compromised
Solution Approach 1:
A security data processing device acts as an intermediary between the OEM and the contract manufacturer. This device performs cryptographic operations including generating device certificates, encrypting data, and managing storage permissions. By introducing this intermediary, the system enables OEMs to work with untrusted contract manufacturers while maintaining data security through cryptographic mediation.
Solution Approach 2:
The patent replaces traditional mechanical/trust-based manufacturing processes with cryptographic mechanisms. Instead of relying on trust relationships or physical control, the system uses public key cryptography, digital certificates, and encrypted storage to secure data. This substitution allows data to be securely stored on devices manufactured by untrusted entities.
2Productivity
If data is stored on target data processing devices, then manufacturing efficiency is improved, but unauthorized data modification and storage become possible
Solution Approach 1:
The security data processing device performs preliminary actions by generating device cryptographic certificates before data storage. It also pre-establishes encryption keys and storage permissions. These preliminary cryptographic setup actions ensure that when data is stored, it cannot be modified or accessed by unauthorized entities, as the security constraints are already in place.
Solution Approach 2:
The system implements feedback mechanisms where the security data processing device monitors and controls storage operations. It tracks which devices are authorized to store data and enforces permission limits. This feedback control prevents unauthorized storage and modification by continuously verifying that only approved devices access the data.
3Reliability
If cryptographic verification is performed for each device, then data integrity is ensured, but processing time increases
Solution Approach 1:
Device cryptographic certificates are generated and stored in advance before the actual data storage operation. This preliminary certificate generation allows the verification process during data storage to be faster, as the certificates are already ready for immediate verification without needing to perform complex cryptographic operations at the time of data storage.
Data Source
AI summary
A method of storing data on target data processing devices, the method comprising: for each target data processing device, using a security data processing device on which first data has been stored to: obtain a device cryptographic certificate from the target data processing device, the device cryptographic certificate having been generated by, and being verifiable as having been generated by, a trusted entity; verify the device cryptographic certificate as having been generated by the trusted entity; generate second data using the first data; and store the second data on the target data processing device.

