Voucher-Based Edge Computing Ownership via Hardware Root of Trust
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing voucher systems for IoT and edge computing devices fail to securely manage ownership transfers and updates, as they do not retain entity information and do not enable secure onboarding operations or verification of partial ownership after ownership changes.
Innovation Solution
The implementation of embedded and digital vouchers using a hardware root of trust, such as the Trusted Computing Group's Device Identity Composition Engine (DICE), which allows for secure onboarding and verification of partial ownership, enabling authorized updates and retooling by retaining entity information even after ownership transfer.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional voucher systems are used for IoT and edge computing devices, then device connectivity and basic operations are enabled, but secure ownership transfer and verification of partial ownership cannot be performed after ownership changes
Solution Approach 1:
The voucher system is segmented into multiple types including embedded vouchers stored in hardware root of trust and digital vouchers stored in accessible memory. This segmentation allows different voucher types to serve different security functions, with embedded vouchers preserving entity information securely for ownership verification while digital vouchers enable flexible operations.
Solution Approach 2:
An intermediary voucher validation mechanism is introduced that checks both the digital voucher and embedded voucher against a whitelist of authorized entities. This intermediary validation process enables secure ownership transfer by verifying that transfer operations are authorized while preserving the original entity information in the embedded voucher.
2Ease of operation
If embedded vouchers are stored in accessible memory for easy verification, then onboarding operations are simplified, but security is compromised as the vouchers can be modified or accessed by unauthorized entities
Solution Approach 1:
The system segments voucher storage into two distinct locations: embedded vouchers stored in hardware root of trust (secure, immutable) and digital vouchers stored in accessible memory (easy to read). This segmentation allows the system to achieve both ease of operation by reading from accessible memory and security by validating against the secure embedded voucher.
Solution Approach 2:
The system replaces the traditional single-voucher mechanical system with a dual-voucher system where the embedded voucher in hardware root of trust serves as an unchangeable reference. This substitution eliminates the need to balance security and accessibility by providing a secure anchor that enables easy verification through digital vouchers without compromising security.
3Reliability
If ownership information is cleared after transfer to protect privacy, then security is improved, but the ability to verify partial ownership and perform authorized updates is lost
Solution Approach 1:
The embedded voucher is prepared in advance during device manufacturing with the original entity information and authorized operations whitelist already embedded in the hardware root of trust. This preliminary action ensures that even after ownership transfer and clearing of accessible ownership information, the device retains the ability to verify partial ownership and perform authorized updates through the preserved embedded voucher.
Data Source
AI summary
Systems and methods for implementing a voucher to identify ownership rights of a computing component, within robust supply chain and owner domains, are disclosed. In an example, a computing device configuration includes a hardware component, trusted hardware circuitry to provide an embedded voucher for the hardware component, and storage memory to provide a voucher for validation of the hardware component. The embedded voucher includes an identifier for the hardware component and the identifier is generated on behalf of an original entity authorized to issue the identifier. The voucher includes a second identifier provided on behalf of a subsequent entity and the second identifier is generated based on the identifier for the hardware component included in the embedded voucher. The voucher may be used to the identify ownership rights in the hardware component for the original entity and the subsequent entity, to enable subsequent actions (such as onboarding, updates, etc.)


