Security Processor Key Management for Supply Chain Ownership Transfer
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing Information Handling Systems (IHSs) face challenges in managing secure boot processes across different entities in a supply chain, particularly in scenarios involving changes of ownership or control, where secure boot keys need to be rendered usable or unusable to ensure secure access to specific controllers, without compromising the integrity of the system.
Innovation Solution
A security processor with embedded public keys that can initiate different secure boot processes, where changes in ownership or control trigger the rendering of keys as usable or unusable, using one-way counters to manage access to various controllers, such as USB, network, and storage controllers, allowing for exclusive control by different entities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple secure boot keys are stored in the security processor to support different entities, then the adaptability of the system is improved, but the device complexity increases
Solution Approach 1:
The patent divides the key management system into separate secure boot keys (first secure boot key and second secure boot key) associated with different entities. Each key is stored in a distinct location within the security processor and can be independently activated or deactivated based on ownership changes, thereby managing complexity through systematic segmentation.
Solution Approach 2:
The patent implements dynamic key activation and deactivation mechanisms where the first secure boot key can be rendered unusable upon change of ownership, and the second secure boot key can be activated. This dynamic switching capability allows the system to adapt to different ownership states without requiring physical hardware changes.
2Reliability
If secure boot keys are rendered unusable upon ownership change, then the security is improved, but the ease of operation deteriorates
Solution Approach 1:
The patent implements preliminary action by pre-configuring multiple secure boot keys and establishing the framework for automatic key switching before ownership changes occur. The system is prepared in advance to handle ownership transitions, reducing the operational burden during actual key management events.
Solution Approach 2:
The security processor automatically manages the activation and deactivation of secure boot keys based on ownership change detection. The system performs self-service by autonomously rendering the first secure boot key unusable and activating the second secure boot key without requiring manual intervention, thereby maintaining security while improving ease of operation.
3Reliability
If hardware replacement is required for each entity change, then the reliability is improved, but the productivity deteriorates
Solution Approach 1:
The patent creates a virtual copy of the secure boot key functionality by implementing a second secure boot key that mirrors the capabilities of the first key but is associated with a different entity. This virtual copying allows ownership transfer without physical hardware replacement, maintaining system integrity while improving supply chain efficiency.
Solution Approach 2:
The patent changes the operational parameters of the security processor by switching between different secure boot keys based on ownership state. Instead of replacing hardware, the system changes which key is active, thereby maintaining reliability while avoiding the productivity losses associated with hardware replacement cycles.
Data Source
AI summary
Embodiments of systems and methods for managing control of a security processor in a supply chain are described. In some embodiments, a security processor may include: a core; and a memory coupled to the core, the memory having program instructions stored thereon that, upon execution by the core, cause the security processor to: store a first public key usable to initiate a first secure boot process and unusable to initiate a second secure boot process; store a second public key usable to initiate the second secure boot process and unusable to initiate the first secure boot process; and in response to a first change of control or ownership of the security processor, render the first public key unusable to initiate the first secure boot process.


