Security Processor Key Derivation for Supply Chain Transitions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing Information Handling Systems (IHSs) face challenges in managing secure boot processes across multiple entities in the supply chain, particularly in ensuring secure key management and control transitions during product returns, warranty claims, and re-provisioning, which can compromise security and efficiency.
Innovation Solution
A security processor-based system that derives dependent symmetric encryption keys using a counter to track secure boot events, allowing for secure key management and transitions between entities, ensuring only authorized entities have access and control over encryption keys.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If symmetric encryption keys are stored in the security processor for secure boot, then security is improved, but key management complexity increases when entities need to be evicted or re-provisioned
Solution Approach 1:
The patent divides the symmetric encryption key into two separate keys: a first symmetric key stored in the security processor and a second symmetric key stored in external memory. This segmentation allows the security processor to maintain security while enabling flexible key management and eviction of entities without compromising the stored key material.
Solution Approach 2:
The patent introduces a key derivation function as an intermediary that generates the second symmetric key from the first symmetric key and entity-specific input data. This mediator enables secure key management by allowing derivation of entity-specific keys without storing sensitive material in the security processor.
2Productivity
If a counter is used to track secure boot events and entity evictions, then key management efficiency is improved, but system complexity increases
Solution Approach 1:
The security processor autonomously manages key derivation and entity eviction by utilizing the counter to track secure boot events. The system self-services by automatically deriving new keys based on counter increments without requiring external intervention, improving efficiency while maintaining manageable complexity.
3Reliability
If the first symmetric key is fused into the security processor, then security is improved, but adaptability decreases when entities need to be evicted or re-provisioned
Solution Approach 1:
The patent segments the key storage by keeping the first symmetric key fused in the security processor while storing the second symmetric key in external memory. This allows the fused key to maintain security while the external key enables adaptability for entity eviction and re-provisioning.
Solution Approach 2:
The patent uses parameter changes by deriving different second symmetric keys based on changes in the counter and entity input data. This allows the system to adapt to different entities and states while maintaining the same fused first symmetric key, balancing security with adaptability.
Data Source
AI summary
Embodiments of systems and methods for deriving dependent symmetric encryption keys based upon a type of secure boot using a security processor are described. In some embodiments, a security processor may include: a core; and a memory coupled to the core, the memory having program instructions stored thereon that, upon execution by the core, cause the security processor to: retrieve a first symmetric key based, at least in part, upon a type of secure boot performed to bootstrap an Information Handling System (IHS); and derive a second symmetric key based, at least in part, upon the first symmetric key.


