SIM Card Root of Trust for FDO Device Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing IoT device onboarding processes are slow, expensive, and insecure, particularly due to vulnerabilities in root of trust keys and the impact of using Trusted Platform Modules (TPMs) on device hardware.
Innovation Solution
A method and system that utilize a hardware-based secure element with an IoT SAFE applet to generate and store cryptographic keys, produce device certificates, and establish a device ownership chain, thereby enhancing the security of FDO-compliant communication devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If TPMs are used as root of trust to enhance security, then device security is improved, but hardware complexity and cost increase
Solution Approach 1:
The patent applies universality by using the SIM card as a multi-functional element that serves both as a communication authentication module and as a root of trust for device security. The SIM card's existing hardware security features are leveraged to perform cryptographic operations, eliminating the need for separate TPM hardware while maintaining security requirements.
Solution Approach 2:
The patent uses copying by transferring the root of trust functionality from dedicated TPM hardware to the SIM card's secure element. The SIM card replicates the cryptographic key storage and processing capabilities traditionally provided by TPM, allowing the same security functions to be performed by an existing, widely-deployed component.
2Reliability
If manual onboarding by technicians is used to ensure secure device setup, then security is improved, but onboarding time and cost increase
Solution Approach 1:
The patent applies self-service by enabling devices to automatically perform their own onboarding and authentication operations. The SIM card-based security architecture allows devices to independently generate cryptographic credentials, authenticate to networks, and establish secure communications without requiring manual intervention from technicians, thereby reducing onboarding time while maintaining security.
Solution Approach 2:
The patent uses preliminary action by pre-configuring the SIM card with security credentials and cryptographic capabilities before device deployment. The root of trust is established in advance within the SIM card, allowing devices to immediately perform secure operations upon activation without requiring manual security setup during onboarding.
3Reliability
If proprietary pre-configuration solutions are used to secure devices at manufacturing, then device security is improved, but supply chain flexibility and interoperability decrease
Solution Approach 1:
The patent applies universality by adopting the SIM card as a standardized, industry-wide root of trust mechanism that works across multiple vendors and device types. This universal approach replaces proprietary solutions with a common platform that maintains security requirements while enabling interoperability and flexibility in the supply chain, allowing different manufacturers to integrate security consistently.
Solution Approach 2:
The patent uses parameter changes by transitioning from proprietary security implementations to a standardized SIM card-based architecture. This change in the security substrate parameter enables devices to maintain secure credentials while being compatible with multiple carriers and platforms, thereby improving supply chain adaptability without compromising security.
Data Source
Figure 1
Figure 2
AI summary
The invention provides a method for increasing the security of a FDO-compliant communication device, wherein the method comprises the following steps: • providing a hardware-based secure element comprising an IoT SAFE applet; wherein the loT SAFE applet comprises at least one empty persistent container configured to store cryptographic data generated by the IoT SAFE applet; • providing the FDO-compliant communication device; • connecting the hardware-based secure element to the FDO-compliant communication device; • generating, by the loT SAFE applet, a public and a private device key, the public and private keys being stored in the empty container of IoT SAFE applet; • producing a device certificate by using the public and private device keys of the IoT SAFE applet; and • computing a Device Initialization, DI, protocol to establish a device ownership chain.