Storage Device Attestation Using CDI-Based Certificates
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing storage devices lack effective mechanisms to verify the reliability of host devices and applications, which can lead to security vulnerabilities and data integrity issues.
Innovation Solution
The implementation of a storage device and electronic system that generates and verifies compound device identifiers (CDIs) using public and private keys to authenticate host devices and applications, ensuring the reliability of the host device and applications through attestation processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a storage device implements verification mechanisms for host device reliability and application authenticity, then security and reliability are improved, but device complexity increases
Solution Approach 1:
The patent introduces a certificate-based intermediary verification system where the storage device obtains host device certificates and application certificates from a trusted authority. These certificates act as intermediaries that contain verified reliability information, allowing the storage device to verify host reliability and application authenticity without implementing complex verification mechanisms itself.
Solution Approach 2:
The patent implements preliminary verification actions by requiring the storage device to verify host device certificates and application certificates before allowing data access. The verification of host reliability and application authenticity is performed in advance, ensuring that only trusted hosts and applications can access stored data.
2Reliability
If the storage device verifies application attestation data and host certificates, then data integrity is improved, but processing time increases
Solution Approach 1:
The patent performs verification actions in advance by checking host device certificates and application certificates before data access requests are processed. This preliminary verification ensures data integrity while allowing efficient subsequent data access operations.
Solution Approach 2:
The patent implements a feedback mechanism where the storage device verifies application attestation data and host certificates, then uses the verification results to control data access. The verification feedback loop ensures that only verified hosts and applications can access data, maintaining integrity while optimizing processing efficiency.
Data Source
AI summary
An electronic system comprising a storage device configured to generate a device public key and a device private key based on a device CDI generated from a device DICE, generate a host certificate including a first device signature generated by signing a host public key with the device private key in response to receiving a request of generating the host certificate including the host public key, and send a request of generating a device certificate including the host certificate and the device public key; and a host device configured to generate the host public key and a host private key based on a host CDI generated by a host DICE, generate the device certificate including a first host signature generated by signing the device public key with the host private key in response to the request of generating the device certificate, and send the device certificate to the storage device.


