Security Module Endorsement via Generalized Key Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security module endorsement methods face challenges in validating the authenticity of computing devices due to the inability to efficiently manage and verify the unique characteristics of diverse device models, batches, and manufacturing classes, especially when these modules are widely distributed across different devices.

Innovation Solution

A method involving a generalized endorsement key independent of device characteristics, which is used to extend integrity measurements with device-specific information, digitally signed, and combined to generate a specialized endorsement credential for authenticating the security module, allowing for validation by a certificate authority server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a generalized endorsement key independent of device characteristics is used, then the security module can be widely distributed across different devices, but the ability to validate authenticity of specific device models and batches is compromised

Engineering Contradiction:
Improvedistribution across different devicesVSAvoidvalidation of device characteristics
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The endorsement credential is segmented into multiple components: a generalized endorsement key for broad device compatibility and extended integrity measurements containing device-specific characteristics. This segmentation allows the system to simultaneously achieve wide distribution capability while maintaining precise validation of specific device models and batches through the separate integrity measurement component.

Inventive Principle:
Principle #1Segmentation

2Reliability

If integrity measurements are extended with device-specific information, then authenticity validation is improved, but the complexity of generating and verifying endorsement credentials increases

Engineering Contradiction:
Improveauthenticity validationVSAvoidendorsement credential generation
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Integrity measurements are extended with device-specific information during the initial endorsement credential generation process, before the security module is deployed. This preliminary action ensures that device characteristics are captured and incorporated into the credential structure upfront, eliminating the need for complex real-time extensions during verification and simplifying the overall process.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If specialized endorsement credentials are generated for each device, then security and trustworthiness are enhanced, but the computational overhead and processing time increase

Engineering Contradiction:
Improvesecurity and trustworthinessVSAvoidcredential generation and validation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Instead of generating completely unique specialized endorsement credentials for each device, the system uses a standardized credential structure that copies and incorporates relevant device characteristics into integrity measurements. This approach maintains the uniqueness and security requirements for each device while using a template-based generation process that significantly reduces computational overhead and processing time compared to creating entirely custom credentials.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9692599B1Security module endorsement
Publication Date: 2017.06.27 GOOGLE LLC
  • US9692599B1 patent drawing
  • US9692599B1 patent drawing
  • US9692599B1 patent drawing

AI summary

Techniques for security module endorsement are provided. An example method includes receiving a generalized endorsement key at a security module, wherein the security module is associated with a computing device and wherein the generalized endorsement key is independent of characteristics of the computing device, automatically extending integrity measurements stored in one or more registers of the security module with information characterizing the computing device, wherein the integrity measurements are based on one or more software processes at the computing device, digitally signing the extended integrity measurements with a digital signature, and generating a specialized endorsement credential as a combination of the digitally signed extended integrity measurements, the digital signature and the generalized endorsement key, wherein the specialized endorsement credential is used to validate authenticity of the security module.