Tamper-Resistant Software Repository for Secure Device Lifecycle Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

One-time programmable (OTP) ROMs in computing systems are costly, prone to hardware failures, and lack flexibility, as they cannot be reset or reconfigured, leading to issues with manufacturing errors and security vulnerabilities.

Innovation Solution

A one-time-settable tamper-resistant software repository is implemented using cryptographically signed and encrypted software, accessible only at the highest privilege level, allowing recordable event fields to be set once and resettable in manufacturing mode, with updates mirrored in both RAM and non-volatile memory.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If OTP ROM is used to securely store information, then security is improved, but manufacturing costs increase and hardware failure rates occur

Engineering Contradiction:
ImprovesecurityVSAvoidmanufacturing costs
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent replaces physical OTP hardware (ROM/fuses) with a software-based secure repository implemented in non-volatile memory. The security function is maintained through cryptographic mechanisms (encryption keys, digital signatures) rather than physical one-time programming, eliminating the need for specialized hardware while preserving security requirements.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent changes the state of the storage medium from permanently programmed (OTP) to rewritable (non-volatile memory), allowing the security repository to be reset and reprogrammed. This parameter change enables both security maintenance and manufacturing flexibility, as devices can be refurbished by resetting the repository rather than requiring replacement.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If OTP ROM is used to store security information, then tamper resistance is improved, but flexibility is reduced due to inability to reset or reconfigure

Engineering Contradiction:
Improvetamper resistanceVSAvoidflexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces dynamic characteristics to the security repository by implementing reset capabilities through authorized interfaces. The repository can transition between locked and reset states based on authentication, allowing adaptive response to different operational scenarios while maintaining tamper resistance during normal operation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent enables recovery of the security repository through authorized reset operations. When security policies need to be updated or devices refurbished, the repository can be reset and reprogrammed with new security parameters, allowing recovery without physical damage or replacement.

Inventive Principle:
Principle #34Discarding and recovering

3Reliability

If PROM is used for security storage, then security is improved, but device complexity increases due to specialized hardware requirements

Engineering Contradiction:
ImprovesecurityVSAvoidhardware complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the non-volatile memory serve multiple functions: general data storage and security repository. The same memory component handles both operational data and security-critical information, eliminating the need for separate OTP hardware while maintaining security through software-based protection mechanisms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent replaces specialized OTP hardware with standard non-volatile memory components combined with cryptographic software. This substitution eliminates specialized hardware requirements while maintaining security through digital signatures, encryption keys, and authenticated access control mechanisms.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Reliability

If OTP fuses are used to prevent unauthorized access, then security is improved, but manufacturing costs and hardware failure rates increase

Engineering Contradiction:
ImprovesecurityVSAvoidmanufacturing costs
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent replaces physical OTP fuses with software-based security mechanisms in non-volatile memory. The security function is achieved through cryptographic authentication and encrypted storage rather than physical fuse blowing, eliminating manufacturing costs associated with OTP processes while maintaining security requirements.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent treats the security repository as a software object that can be reset and reprogrammed rather than a permanent hardware component. This approach is more cost-effective than OTP manufacturing, as software resetting is cheaper than physical fuse replacement or device recall.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS8656190B2One time settable tamper resistant software repository
Publication Date: 2014.02.18 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8656190B2 patent drawing
  • US8656190B2 patent drawing
  • US8656190B2 patent drawing

AI summary

A one-time-settable tamper resistant software repository may be used in any computing system to store system information such as security violations and policies for responding to them. A one-time-settable tamper resistant software repository may be cryptographically signed, encrypted with a per device key and accessible by only the most privileged software executed by a computing device, e.g., hypervisor or operating system kernel. A one-time-settable tamper resistant software repository may be mirrored in RAM for performance. Recordable event fields in a software repository may be one-time-settable without the ability to reset them in a field operation mode whereas they may be resettable in a different mode such as a manufacturing mode. Memory allocated to a one-time-settable tamper resistant software repository may be reset, reclaimed, reassigned, scaled and otherwise flexibly adapted to changing conditions and priorities in the lifespan of a computing device, which may be particularly useful for service-backed consumer devices.