Security Processor Key Derivation for Supply Chain Transitions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Information Handling Systems (IHSs) face challenges in managing secure boot processes across multiple entities in the supply chain, particularly in ensuring secure key management and control transitions during product returns, warranty claims, and re-provisioning, which can compromise security and efficiency.

Innovation Solution

A security processor-based system that derives dependent symmetric encryption keys using a counter to track secure boot events, allowing for secure key management and transitions between entities, ensuring only authorized entities have access and control over encryption keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If symmetric encryption keys are stored in the security processor for secure boot, then security is improved, but key management complexity increases when entities need to be evicted or re-provisioned

Engineering Contradiction:
ImprovesecurityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the symmetric encryption key into two separate keys: a first symmetric key stored in the security processor and a second symmetric key stored in external memory. This segmentation allows the security processor to maintain security while enabling flexible key management and eviction of entities without compromising the stored key material.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a key derivation function as an intermediary that generates the second symmetric key from the first symmetric key and entity-specific input data. This mediator enables secure key management by allowing derivation of entity-specific keys without storing sensitive material in the security processor.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If a counter is used to track secure boot events and entity evictions, then key management efficiency is improved, but system complexity increases

Engineering Contradiction:
Improvekey management efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The security processor autonomously manages key derivation and entity eviction by utilizing the counter to track secure boot events. The system self-services by automatically deriving new keys based on counter increments without requiring external intervention, improving efficiency while maintaining manageable complexity.

Inventive Principle:
Principle #25Self-service

3Reliability

If the first symmetric key is fused into the security processor, then security is improved, but adaptability decreases when entities need to be evicted or re-provisioned

Engineering Contradiction:
ImprovesecurityVSAvoidadaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the key storage by keeping the first symmetric key fused in the security processor while storing the second symmetric key in external memory. This allows the fused key to maintain security while the external key enables adaptability for entity eviction and re-provisioning.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent uses parameter changes by deriving different second symmetric keys based on changes in the counter and entity input data. This allows the system to adapt to different entities and states while maintaining the same fused first symmetric key, balancing security with adaptability.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20230015334A1Deriving dependent symmetric encryption keys based upon a type of secure boot using a security processor
Publication Date: 2023.01.19 DELL PROD LP
  • US20230015334A1 patent drawing
  • US20230015334A1 patent drawing
  • US20230015334A1 patent drawing

AI summary

Embodiments of systems and methods for deriving dependent symmetric encryption keys based upon a type of secure boot using a security processor are described. In some embodiments, a security processor may include: a core; and a memory coupled to the core, the memory having program instructions stored thereon that, upon execution by the core, cause the security processor to: retrieve a first symmetric key based, at least in part, upon a type of secure boot performed to bootstrap an Information Handling System (IHS); and derive a second symmetric key based, at least in part, upon the first symmetric key.