Trusted Platform Module Segmentation for IoT Cryptographic Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current IoT devices face challenges in efficiently performing cryptographic operations, particularly in complying with FIPS 140-2 and 140-3 standards, as processor-intensive tasks like SSL and TLS are performed on microprocessors, leading to cumbersome and costly validation processes.

Innovation Solution

Implementing Trusted Platform Modules (TPMs) within IoT devices to perform all cryptographic functions, including SSL and TLS, while segregating these operations from the rest of the device's processor and memory, ensuring compliance with FIPS standards and reducing validation costs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic operations are performed on the microprocessor of the IoT device, then the device can execute cryptographic functions, but the validation process becomes time-consuming and expensive

Engineering Contradiction:
Improvecompliance with FIPS standardsVSAvoidvalidation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the IoT device into two distinct parts: a trusted execution environment (TEE) for cryptographic operations and a non-secure environment for other operations. This segmentation allows the cryptographic functions to be validated separately according to FIPS standards, reducing overall validation time and cost while maintaining compliance.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts cryptographic operations from the general-purpose microprocessor and places them in a dedicated trusted execution environment. This extraction enables independent validation of the cryptographic module, eliminating the need to validate the entire device and significantly reducing validation time and expenses.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If cryptographic operations are performed on the microprocessor of the IoT device, then the device can execute cryptographic functions, but maintenance becomes extremely cumbersome

Engineering Contradiction:
Improvecompliance with FIPS standardsVSAvoidmaintenance difficulty
Core Design Contradiction:
ReliabilityVSEase of repair

Solution Approach 1:

By segmenting the device into TEE and non-TEE portions, the patent enables independent maintenance and updates of the cryptographic module without affecting other device components. This modular approach simplifies maintenance procedures and reduces complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The extraction of cryptographic functions into a separate TEE allows the cryptographic module to be maintained, updated, or replaced independently from the rest of the device, making maintenance much easier and less cumbersome.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If cryptographic operations are performed on the microprocessor of the IoT device, then the device can execute cryptographic functions, but the system complexity increases

Engineering Contradiction:
Improvecompliance with FIPS standardsVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the system into clearly defined TEE and non-TEE portions with well-established communication interfaces. This segmentation reduces system complexity by creating distinct functional boundaries and simplifying the integration between cryptographic and non-cryptographic components.

Inventive Principle:
Principle #1Segmentation

4Ease of manufacture

If cryptographic operations are segregated from the rest of the device, then compliance validation becomes easier, but the device structure becomes more complex

Engineering Contradiction:
Improvevalidation easeVSAvoiddevice structure
Core Design Contradiction:
Ease of manufactureVSDevice complexity

Solution Approach 1:

The patent implements segmentation that creates clear boundaries between TEE and non-TEE portions, which simplifies the validation process by allowing separate assessment of cryptographic compliance. The well-defined interfaces between segments prevent excessive structural complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The TEE is designed as a universal cryptographic module that can be integrated into different IoT device types and configurations. This multi-functionality approach allows the same TEE architecture to serve various cryptographic needs without proportionally increasing device structural complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11374909B2Use of trusted platform modules for cryptographic operations in an internet of things device
Publication Date: 2022.06.28 POSITIONING UNIVERSAL INC
  • US11374909B2 patent drawing
  • US11374909B2 patent drawing
  • US11374909B2 patent drawing

AI summary

Providing security functions in an IoT device can comprise executing, by a TPM of the IoT device, a set of cryptographic functions. The set of cryptographic functions can comprise providing a secure unidirectional uplink from the IoT device to one or more communications networks. The set of cryptographic functions can also be executed by a second TPM to provide a secure unidirectional downlink from the one or more communications networks to the IoT device. The processor of the IoT device need not perform cryptographic functions and the processor of the IoT device and a memory of the IoT device can be outside of a secure boundary maintained by the first TPM and the second TPM. Cryptographic information to provide the secure unidirectional uplink and the secure unidirectional downlink can be exchanged between the first TPM and the second TPM.