Cryptographic secret generation and provisioning
A system includes a memory device and a processor, operatively coupled with the memory device, to perform operations including receiving, from a device via a brokering agent, a request to provide an encrypted version of a set of secrets data corresponding to a target state of the device, determining whether to authorize the request in view of the brokering agent, and in response to authorizing the request, providing the encrypted version of the set of secrets data and permission to transition to the target state.
1 . A system comprising:
a memory device; and
a processing device, operatively coupled with the memory device, to perform operations comprising:
authorizing a request to provide a set of secrets data corresponding to a target device supply chain state associated with a supply chain of a device; and
in response to authorizing the request, providing the set of secrets data and permission for the device to transition to the target device supply chain state.
2 . The system of claim 1 , wherein the operations further comprise maintaining, on a distributed ledger, a record indicative of the set of secrets data being provided to the device.
3 . The system of claim 1 , wherein the operations further comprise, in response to not authorizing the request:
maintaining, on a distributed ledger, a record indicative of denying access to the set of secrets data.
4 . The system of claim 1 , wherein:
determining whether to authorize the request comprises:
determining whether a brokering agent is authorized to handle the request;
in response to determining that the brokering agent is authorized to handle the request, receiving, from the device via the brokering agent, a supersession package while in the device is in a supersession state; and
determining whether the device has permission to transition to the target device supply chain state based on the supersession package; and
providing the set of secrets data and permission to transition to the target device supply chain state comprises:
in response to determining that the device has permission to transition to the target device supply chain state based on the supersession package, sending, to the device via the brokering agent, a commit package to commit the set of secrets data.
5 . The system of claim 1 , wherein the request is received during a state transition process to transition the device from a current device supply chain state to the target device supply chain state.
6 . The system of claim 1 , wherein the target device supply chain state is one of a manufacturer provisioning state corresponding to a manufacturing stage of the supply chain associated with a manufacturer of the device, a vendor provisioning state corresponding to a vendor stage of the supply chain associated with a vendor in possession of the device, an end-use provisioning state corresponding to an end-use stage of the supply chain, and an operational state corresponding to an operational stage of the supply chain.
7 . The system of claim 1 , wherein the set of secrets data is generated by a hardware security module.
8 . A method comprising:
authorizing, by a processing device, a request to initiate a state progression from a current device supply chain state associated with a supply chain of a device to a target device supply chain state associated with the supply chain of the device, wherein the current device supply chain state corresponds to a current set of secrets data inserted on the device; and
in response to authorizing the request, transitioning, by the processing device, the device from the current device supply chain state to the target device supply chain state.
9 . The method of claim 8 , further comprising maintaining, by the processing device on a distributed ledger, a record indicative of the device transitioning to the target device supply chain state.
10 . The method of claim 8 , further comprising, in response to not authorizing the request, preventing, by the processing device, the device from transitioning to the target device supply chain state.
11 . The method of claim 8 , wherein request is a request to provide a set of secrets data corresponding to the target device supply chain state.
12 . The method of claim 11 , wherein:
determining whether to authorize the request comprises:
determining whether a brokering agent is authorized to handle the request;
in response to determining that the brokering agent is authorized to handle the request, receiving, from the device via the brokering agent, a supersession package while in the device is in a supersession state; and
determining whether the device has permission to transition to the target device supply chain state based on the supersession package; and
transitioning the device from the current device supply chain state to the target device supply chain state comprises:
in response to determining that the device has permission to transition to the target device supply chain state based on the supersession package, sending, to the device via the brokering agent, a commit package to commit the set of secrets data.
13 . The method of claim 11 , wherein the set of secrets data is generated by a hardware security module.
14 . The method of claim 8 , wherein the target device supply chain state is one of a manufacturer provisioning state corresponding to a manufacturing stage of the supply chain associated with a manufacturer of the device, a vendor provisioning state corresponding to a vendor stage of the supply chain associated with a vendor in possession of the device, an end-use provisioning state corresponding to an end-use stage of the supply chain, and an operational state corresponding to an operational stage of the supply chain.
15 . A non-transitory computer-readable storage medium comprising instructions that, when executed by a processing device, cause the processing device to perform operations comprising:
authorizing a request to provide a set of secrets data corresponding to a target device supply chain state associated with a supply chain of a device; and
in response to authorizing the request, providing the set of secrets data and permission to transition to the target device supply chain state.
16 . The non-transitory computer-readable storage medium of claim 15 , wherein the operations further comprise maintaining, on a distributed ledger, a record indicative of the set of secrets data being provided to the device.
17 . The non-transitory computer-readable storage medium of claim 15 , wherein the operations further comprise, in response to not authorizing the request:
maintaining, on a distributed ledger, a record indicative of denying access to the set of secrets data.
18 . The non-transitory computer-readable storage medium of claim 15 , wherein:
determining whether to authorize the request comprises:
determining whether a brokering agent is authorized to handle the request;
in response to determining that the brokering agent is authorized to handle the request, receiving, from the device via the brokering agent, a supersession package while in the device is in a supersession state; and
determining whether the device has permission to transition to the target device supply chain state based on the supersession package; and
providing the set of secrets data and permission to transition to the target device supply chain state comprises:
in response to determining that the device has permission to transition to the target device supply chain state based on the supersession package, sending, to the device via the brokering agent, a commit package to commit the set of secrets data.
19 . The non-transitory computer-readable storage medium of claim 15 , wherein the target device supply chain state is one of a manufacturer provisioning state corresponding to a manufacturing stage of the supply chain associated with a manufacturer of the device, a vendor provisioning state corresponding to a vendor stage of the supply chain associated with a vendor in possession of the device, an end-use provisioning state corresponding to an end-use stage of the supply chain, and an operational state corresponding to an operational stage of the supply chain.
20 . The non-transitory computer-readable storage medium of claim 15 , wherein the set of secrets data is generated by a hardware security module.