Unique System Key Generation for Computing Platform Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cryptographic key management systems are vulnerable to security breaches when a single key wrapping key is used across multiple computing platforms, as compromising one device can expose all others, and manufacturing devices can be targeted to obtain these keys.

Innovation Solution

Generating and assigning a unique system key for each computing platform during manufacturing, using a processor and encryption algorithm to securely create, store, and manage user keys, with features like local storage, random number generation, and attack detection to prevent key exposure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a single key wrapping key is installed in every computing platform during manufacturing, then key management is simplified and ease of operation is improved, but security is compromised because if one device is compromised, an attacker can use the discovered key wrapping key on other devices

Engineering Contradiction:
Improvekey managementVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent divides the single key wrapping key into multiple unique key wrapping keys, with each computing platform receiving a distinct key. This segmentation ensures that compromise of one device does not expose keys for other devices, resolving the security vulnerability while maintaining simplified key management through automated generation and distribution.

Inventive Principle:
Principle #1Segmentation

2Reliability

If a unique key wrapping key is generated for each computing platform, then security is improved because compromise of one device does not expose other devices, but the manufacturing process becomes more complex and device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidkey management system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling computing platforms to automatically generate their own unique key wrapping keys during manufacturing or initialization. This automated key generation eliminates the need for manual key distribution and reduces manufacturing complexity, while still providing the security benefit of unique keys per device.

Inventive Principle:
Principle #25Self-service

3Reliability

If a unique key wrapping key is generated for each computing platform, then security is improved, but if the manufacturing device is attacked, an ambitious attacker could determine the key wrapping keys for manufactured computing platforms

Engineering Contradiction:
ImprovesecurityVSAvoidmanufacturing device attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by generating and securing key wrapping keys either during the manufacturing process with secure isolation or by enabling post-manufacturing key generation at the device level. This ensures keys are established before potential attacks can occur, and the unique per-device generation prevents manufacturing device compromises from exposing other devices' keys.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9444622B2Computing platform with system key
Publication Date: 2016.09.13 HEWLETT PACKARD ENTERPRISE DEV LP
  • US9444622B2 patent drawing
  • US9444622B2 patent drawing
  • US9444622B2 patent drawing

AI summary

A method for installing a system key onto a computing platform is disclosed. A system key generator is installed on the computing platform. The system key generator is activated and generates a system key within the computing platform. The system key is also stored within the computing platform.