Providing cryptographically secure post-secrets-provisioning services
A system includes a memory device and a processor, operatively coupled to the memory device, to perform operations including receiving a request to provide a post-secrets-provisioning service with respect to a device, in response to receiving the request, determining whether to authorize the request, in response to authorizing the request, obtaining a set of secrets data corresponding to the device, and providing the post-secrets-provisioning service by performing a cryptographic function utilizing the set of secrets data.
1. A system comprising:
a memory; and
a processor, operatively coupled to the memory, to perform operations comprising:
receiving a request to provide a post-secrets-provisioning service with respect to a device having a supply chain state corresponding to a supply chain associated with the device, wherein the supply chain state is one of: a manufacturing provisioning state corresponding to a manufacturing stage of the supply chain, a vendor provisioning state corresponding to a vendor stage of the supply chain, a network provisioning state corresponding to a network stage of the supply chain, or an operational state corresponding to an operational stage of the supply chain;
in response to receiving the request, determining whether to authorize the request based on a proof of ownership of the device;
in response to authorizing the request, obtaining a set of secrets data corresponding to the supply chain state of the device; and
emulating, by utilizing the set of secrets data, the device having the supply chain state to provide the post-secrets-provisioning service.
2. The system of claim 1 , further comprising a distributed ledger maintaining the proof of ownership of the device.
3. The system of claim 2 , wherein obtaining the set of secrets data comprises generating the set of secrets data using at least one of the distributed ledger or a secrets generator.
4. The system of claim 1 , wherein providing the post-secrets-provisioning service comprises at least one of: providing a data or trust verification service, providing a data production service, providing a file authorization service, or providing a service to locate a secrets and service provider system to handle the request.
5. The system of claim 4 , wherein the set of secrets data comprises a previous set of secrets data, and wherein providing the data production service comprises recovering data encrypted with the previous set of secrets data.
6. The system of claim 4 , wherein providing the file authorization service comprises:
generating, using the set of secrets data, an authorization packet comprising an encrypted version of a file; and
sending, to the device, the authorization packet to enable the device to determine whether the encrypted version of the file is valid for decryption by the device.
7. The system of claim 6 , wherein the file comprises at least one of: a document, an application, or a consumable data packet.
8. A method comprising:
receiving, by a processor, a request to provide a post-secrets-provisioning service with respect to a device having a supply chain state corresponding to a supply chain associated with the device, wherein the supply chain state is one of: a manufacturing provisioning state corresponding to a manufacturing stage of the supply chain, a vendor provisioning state corresponding to a vendor stage of the supply chain, a network provisioning state corresponding to a network stage of the supply chain, or an operational state corresponding to an operational stage of the supply chain;
in response to receiving the request, determining, by the processor, whether to authorize the request based on a proof of ownership of the device;
in response to authorizing the request, obtaining, by the processor, a set of secrets data corresponding to the supply chain state of the device; and
emulating, by the processor utilizing the set of secrets data, the device having the supply chain state to provide the post-secrets-provisioning service.
9. The method of claim 8 , wherein the proof of ownership of the device is maintained on a distributed ledger.
10. The method of claim 9 , wherein obtaining the set of secrets data comprises generating the set of secrets data using at least one of the distributed ledger or a secrets generator.
11. The method of claim 8 , wherein providing the post-secrets-provisioning service comprises at least one of: providing a data or trust verification service, providing a data production service, providing a file authorization service, or providing a service to locate a secrets and service provider system to handle the request.
12. The method of claim 11 , wherein the set of secrets data comprises a previous set of secrets data, and wherein providing the data production service comprises recovering data encrypted with the previous set of secrets data.
13. The method of claim 11 , wherein providing the file authorization service comprises:
generating, using the set of secrets data, an authorization packet comprising an encrypted version of a file; and
sending, to the device, the authorization packet to enable the device to determine whether the encrypted version of the file is valid for decryption by the device.
14. The method of claim 13 , wherein the file comprises at least one of: a document, an application, or a consumable data packet.
15. A non-transitory computer-readable storage medium comprising instructions that, when executed by a processing device, cause the processing device to perform operations comprising:
receiving a request to provide a post-secrets-provisioning service with respect to a device having a supply chain state corresponding to a supply chain associated with the device, wherein the supply chain state is one of: a manufacturing provisioning state corresponding to a manufacturing stage of the supply chain, a vendor provisioning state corresponding to a vendor stage of the supply chain, a network provisioning state corresponding to a network stage of the supply chain, or an operational state corresponding to an operational stage of the supply chain, and wherein the post-secrets-provisioning service comprises at least one of: a data or trust verification service, a data production service, a file authorization service, or a service to locate a secrets and service provider system to handle the request;
in response to receiving the request, determining whether to authorize the request based on a proof of ownership of the device maintained on a distributed ledger;
in response to authorizing the request, obtaining a set of secrets data using the distributed ledger, wherein the set of secrets data corresponds to the supply chain state of the device; and
emulating, by utilizing the set of secrets data, the device having the supply chain state to provide the post-secrets-provisioning service.
16. The non-transitory computer-readable storage medium of claim 15 , wherein the set of secrets data comprises a previous set of secrets data, wherein the post-secrets-provisioning service is a data production service, and wherein providing the data production service comprises recovering data encrypted with the previous set of secrets data.
17. The non-transitory computer-readable storage medium of claim 15 , wherein the post-secrets-provisioning service is a file authorization service, and wherein providing the file authorization service comprises:
generating, using the set of secrets data, an authorization packet comprising an encrypted version of a file; and
sending, to the device, the authorization packet to enable the device to determine whether the encrypted version of the file is valid for decryption by the device.
18. The non-transitory computer-readable storage medium of claim 17 , wherein the file comprises at least one of: a document, an application, or a consumable data packet.
19. The non-transitory computer-readable storage medium of claim 15 , wherein obtaining the set of secrets data comprises generating the set of secrets data.