Method of updating device certificate and device for driving the method
A device may include processing circuitry configured to, generate a device identifier associated with the device, and generate a unique endorsement identity (ID) associated with the device identifier, a first layer sub-circuit configured to, receive the device identifier, and generate a first certificate and a second certificate based on the device identifier and the unique endorsement ID, the first certificate and the second certificate including information to authenticate the device, and the processing circuitry is further configured to, receive the first certificate and the second certificate, and verify whether the device has been modified based on the first certificate and the second certificate, wherein, in response to the first layer sub-circuit being modified, the first layer sub-circuit is further configured to, generate an endorsement key based on a new unique endorsement ID, and generate a certificate signing request for the new unique endorsement ID based on the endorsement key.
1 . A device comprising:
processing circuitry configured to,
generate a device identifier associated with the device, and
generate a unique endorsement identity associated with the device identifier;
a first layer sub-circuit configured to,
receive the device identifier, and
generate a first certificate and a second certificate based on the device identifier and the unique endorsement identity, the first certificate and the second certificate including information to authenticate the device; and
the processing circuitry is further configured to,
receive the first certificate and the second certificate, and
verify whether the device has been modified based on the first certificate and the second certificate,
wherein, in response to the first layer sub-circuit being modified, the first layer sub-circuit is further configured to,
generate an endorsement key based on a new unique endorsement identity, and
generate a certificate signing request for the new unique endorsement identity based on the endorsement key.
2 . The device of claim 1 , wherein the processing circuitry is further configured to generate the device identifier by inputting unique device secret data into a first function.
3 . The device of claim 2 , wherein the processing circuitry is further configured to generate the unique endorsement identity by inputting the unique device secret data into a second function.
4 . The device of claim 1 , wherein the first layer sub-circuit is further configured to generate an endorsement private key and an endorsement public key.
5 . The device of claim 4 , wherein the first layer sub-circuit is further configured to generate an endorsement certificate signing request based on the endorsement private key and the endorsement public key.
6 . The device of claim 1 , wherein the processing circuitry is further configured to verify whether the first layer sub-circuit has been modified based on the second certificate and the certificate signing request.
7 . The device of claim 6 , wherein the first layer sub-circuit is further configured to:
determine whether the first layer sub-circuit has been modified; and
update a certificate chain based on the certificate signing request and results of the determination.
8 . A method of updating a device certificate, the method comprising:
generating a device identifier associated with a desired device;
generating a unique endorsement identity associated with the device identifier;
transmitting the device identifier to a first layer sub-circuit, the transmitting causing the first layer sub-circuit to,
generate a first certificate and a second certificate based on the device identifier and the unique endorsement identity, the first certificate and the second certificate including information to authenticate the desired device;
receiving the first certificate and the second certificate; and
verifying whether the desired device has been modified based on the first certificate and the second certificate,
wherein, in response to the first layer sub-circuit being modified, the first layer sub-circuit is further caused to generate the first certificate and the second certificate by generating an endorsement key based on a new unique endorsement identity, and generating a certificate signing request for the new unique endorsement identity based on the endorsement key.
9 . The method of claim 8 , wherein the generating the device identifier further comprises generating the device identifier by inputting unique device secret data into a first function.
10 . The method of claim 9 , wherein the generating the unique endorsement identity further comprises generating the unique endorsement identity by inputting the unique device secret data into a second function.
11 . The method of claim 8 , wherein the generating the endorsement key further comprises generating an endorsement private key and an endorsement public key.
12 . The method of claim 11 , wherein the generating the first certificate and the second certificate: further comprises generating an endorsement certificate signing request based on the endorsement private key and the endorsement public key.
13 . The method of claim 8 , wherein the verifying whether the desired device has been modified further comprises determining whether the first layer sub-circuit has been modified based on the first certificate, the second certificate, and the certificate signing request.
14 . The method of claim 13 , wherein the verifying whether the desired device has been modified further comprises updating a certificate chain of the desired device based on the certificate signing request and results of determining whether the first layer sub-circuit has been modified.
15 . A method comprising:
verifying an intermediate certificate based on a root certificate combined with the intermediate certificate to form a root certificate chain;
determining whether a bootloader of a device has been modified by verifying a device certificate based on the intermediate certificate combined with the device certificate to form a device certificate chain; and
updating the device certificate chain based on a device certificate signing request, the device certificate signing request generated based on a unique endorsement identity associated with a device identifier associated with the device, and results of the determining whether the bootloader of the device has been modified,
wherein the updating the device certificate chain includes,
combining a new device certificate and the intermediate certificate,
verifying a modification of the bootloader included in the device based on the root certificate, the intermediate certificate, and the device certificate signing request, and
updating the device certificate chain based on the device certificate signing request in response to results of determining whether the bootloader has been modified.
16 . The method of claim 15 , further comprising:
generating the device identifier associated with the device; and
generating the unique endorsement identity associated with the device identifier by inputting unique device secret data into a first function and a second function, respectively.
17 . The method of claim 15 , wherein the updating of the device certificate chain comprises:
generating an endorsement private key and an endorsement public key; and
generating an endorsement key based on the endorsement private key and the endorsement public key.
18 . The method of claim 17 , wherein the updating of the device certificate chain further comprises:
generating an endorsement certificate signing request based on the endorsement private key and the endorsement public key.