Method and secure element for detecting a trusted electronic assembly
The invention relates to a method and a secure element for detecting the trustworthiness of an electronic assembly ( 100 ). The secure element ( 200 ) comprises a control unit ( 210 ), a record storage device ( 230 ), and a secure storage device ( 220 ); the record storage device ( 230 ) comprises a target state value ( 235 ) of the assembly ( 100 ); the secure storage device ( 220 ) comprises a private key ( 226 ) of a proof of origin ( 222 ); the secure element ( 200 ) has a public key ( 224 ) of the proof of origin ( 222 ), said public key being output to a requesting processing unit; and the control unit ( 210 ) is designed to carry out the method in order to detect the trustworthiness. The method has the steps of ascertaining an actual state value ( 233 ) of the actual state of the assembly ( 100 ), reading the target state value ( 235 ) from the record storage device ( 230 ), verifying the authenticity of the secure element ( 200 ), processing the actual state value ( 233 ) and the target state value ( 235 ), and deciding whether the actual state is sufficiently similar to or compatible with or matches the target state such that a trust criterion is satisfied.
1 . A method for proving a trustworthy electronic assembly with a CPU, a bus interface and a secure element, the secure element comprising a proof of origin of the secure element and a record memory with a target state value of the assembly, the secure element further comprising a control unit, wherein the proof of origin comprises a private key of the secure element and a key certificate with a public key, the method comprising:
authenticating the secure element by verifying a proof of origin of the secure element without involvement of any external trusted party,
by:
(a) reading a public key of the secure element,
(b) verifying entirely within the secure element that the private key, which exists in the secure memory of the secure element, corresponds to the public key in the key certificate; and
the method further comprising:
determining an actual state value of an actual state of the assembly;
reading from the record memory at least one target state value, comprising at least the public key of the secure element and the serial number of the assembly and, wherein the target state value represents a target state of the assembly;
comparing in the control unit of the secure element the target state value and the actual state value; and
determining in the control unit of the secure element whether the actual state value is compatible with the target state value or meets a predefined trust criterion.
2 . The method according to claim 1 , wherein the method steps a) and b) are executed one time and wherein the further steps may be executed multiple times.
3 . The method according to claim 1 , further comprising:
based on the determining, authenticating in the control unit of the secure element the use of the assembly or the use of a process that the assembly performs.
4 . The method of claim 3 , further comprising:
in response to the determining, locking or releasing parts of the assembly or components of the assembly, resetting the assembly, or terminating one or more functions of the assembly.
5 . The method of claim 1 , wherein the proof of origin is stored encrypted in the secure element.
6 . The method of claim 5 , wherein the proof of origin is stored encrypted in a secure memory of the secure element, the secure memory being different from the record store.
7 . The method of claim 6 , wherein the reading of the public key of the secure element is performed before verifying that the private key corresponds to the public key in the key certificate.
8 . The method according to claim 1 , wherein verifying that the private key corresponds to the public key in the key certificate further comprises:
generating a new random data value,
sending the data value to the secure element;
encrypting the data value with the private key of the key certificate of the proof of origin in the secure element,
outputting a result value from the secure element,
decrypting the result value with the public key of the key certificate, and
confirming the result value using the generated data value.
9 . The method of claim 1 , wherein the method is performed during the boot process of the assembly.
10 . The method of claim 9 , wherein the boot process of assembly components is altered by performance of the method.
11 . The method according to claim 1 , wherein the method is executable during the boot process, wherein the boot process is altered by performance of the method.
12 . The method of claim 11 , wherein the sequence of the boot process is changed based on performance of the method.
13 . The method of claim 1 , wherein a proof element for proving the trustworthy production of an assembly in the form of a target state value of the assembly is stored at the record memory, wherein the proof element comprises information of the manufacture or processing of the assembly, and wherein a plurality of proof elements including the proof element are linked to each other in the record memory in an unalterable chain.
14 . The method according to claim 1 , wherein based on a completed check of the trustworthiness of the assembly, a new proof element for the record memory is created and stored in the record memory, the new proof element being generated and stored exclusively within the secure element without reliance on an external trusted party.
15 . The method of claim 14 , wherein the new proof element is linked to the plurality of proof elements in the record memory in the form of a cryptographically chained structure, internally within the secure element.
16 . The method of claim 1 , wherein the target state value comprises a plurality of features of the assembly and the features are specific or characteristic parameters for the component or assembly.
17 . A secure element for proving the trustworthiness of an electronic assembly, comprising:
a control unit;
a record memory comprising production records with target state values, each production record being cryptographically linked and unalterable after manufacture;
a secure memory comprising a private key uniquely generated and bound to the secure element during manufacture, and the corresponding public key, and a proof of origin of the secure element, wherein the proof of origin comprises, a public key and a private key of the secure element,
wherein the control unit is configured to authenticate the secure element autonomously, without reliance on an external trusted party, by verifying existence of the private key, which exists in the secure memory of the secure element, with the public key;
wherein the control unit is configured to, in the control unit of the secure element, compare an actual state value of the assembly with one or more of the target state values from the record memory; and
wherein the control unit is configured to determine whether the actual state value is compatible with the one or more target state values or meets a confidence-trust criterion.
18 . The secure element according to claim 17 , wherein the secure memory is encrypted.
19 . The secure element according to claim 18 , wherein the secure memory stores a plurality of proofs or origin, and at least a portion of the proofs of origin stored in the secure memory are encrypted.
20 . The secure element according to claim 17 , wherein a sequence of several target state values of the plurality of target state values are carried out in a specified order.
21 . The secure element according to claim 17 , wherein the plurality of state values of the record memory comprise a plurality of target state values of the assembly in the form of the production records.
22 . The secure element according to claim 17 , wherein the secure element performs a weighted evaluation of the actual state value and the one or more target state values to prove trustworthiness.
23 . The secure element according to claim 17 , wherein the target state values comprise a plurality of features of the assembly or a component of the assembly, wherein the features are specific or characteristic parameters for the component or assembly.
24 . The secure element according to claim 17 , wherein the secure element has an interface to outsource one or more portions of proving trustworthiness to a component of the assembly.
25 . The secure element according to claim 24 , wherein exchanged data are encrypted with the component and the component has a secure engine that performs security functions in a protected area, or the component is secured by security features.
26 . Electronic assembly having a CPU, a bus interface and a memory, characterized in that the assembly comprises a secure element for proving the trustworthiness of the assembly, wherein the secure element has a control unit, a record memory and a secure store, wherein the secure element is formed according to claim 17 .
27 . Hardware component having a protected security processor for proving the trustworthiness of an electronic assembly, wherein the hardware component comprises a record memory and a secure storage, wherein the hardware component is part of the assembly to be authenticated and the hardware component performs the method according to claim 1 .