Resilient Device Authentication System
Abstract
A resilient device authentication system comprising: one or more verification authorities (VAs) including a memory loaded with a complete verification set that includes hardware part-specific data, and configured to create a limited verification set (LVS) therefrom; one or more provisioning entities (PEs) each connectable to at least one of the VAs, including a memory loaded with a LVS, and configured to select a subset of data therefrom so as to create an application limited verification set (ALVS); and one or more device management systems connectable to at least one of the PEs, including a memory loaded with an ALVS, and configured to manage device security-related applications through the performance of security-related functions on devices associated with the hardware part-specific data.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A resilient device authentication system, comprising:
a. one or more verification authorities (“VAs”) including a VA memory loaded with a complete verification set (“loaded CVS”) that includes hardware part-specific data, and configured to create a limited verification set (“LVS”) from said loaded CVS; b. one or more provisioning entities (“PEs”) each connectable to at least one of said one or more VAs, including a PE memory loaded with a LVS (“loaded LVS”), and configured to select a subset of data from said loaded LVS so as to create an application limited verification set (“ALVS”); and c. one or more device management systems (“DMSs”) connectable to at least one of said one or more PEs, each DMS including a DMS memory loaded with an ALVS (“loaded ALVS”), and configured to manage one or more device security-related applications through the performance of security-related functions on devices associated with hardware part-specific data in said loaded CVS.
2 . The system of claim 1 , wherein all device security-related applications managed by the system utilize said hardware part-specific data in said loaded CVS.
3 . The system of claim 1 , wherein each of said one or more VAs is configured to perform a one-way algorithmic transformation of hardware specific data in said loaded CVS.
4 . The system of claim 1 , wherein each of said one or more PEs includes a hardware security module configured to limit PE access to LVS data.
5 . The system of claim 4 , wherein each of said one or more DMSs includes a hardware security module configured to limit DMS access to ALVS data.
6 . The system of claim 1 , wherein said one or more device security-related applications include supply chain risk management.
7 . The system of claim 1 , wherein said one or more device security-related applications include device authentication.
8 . The system of claim 1 , wherein said one or more device security-related applications include governing networked communications among devices associated with hardware part-specific data in said loaded CVS.
9 . The system of claim 8 , wherein said networked communications employ a communications protocol in which addresses are based on devices' hardware part-specific data.
10 . The system of claim 9 , wherein said networked communications utilize real or virtual routers.
11 . The system of claim 1 , wherein said one or more VAs consists of a single VA.
12 . The system of claim 1 , wherein said one or more VAs consists of a federated group of VAs.
13 . The system of claim 1 , wherein said one or more VAs consists of a siloed group of VAs.
14 . The system of claim 1 , wherein each of said one or more PEs is configured to receive an LVS from a single VA.
15 . The system of claim 1 , wherein said one or more PEs includes a peer network configured to share information contained in an LVS.
16 . The system of claim 15 , wherein said peer network is configured so that PEs therein are permitted to share information contained in an LVS with a peer seeking to join the network based on a peer-to-peer establishment of trust.
17 . The system of claim 1 , wherein each of said one or more DMSs is configured to store in its DMS memory a record of device interactions.
18 . The system of claim 17 , wherein said record of device interactions is structured in a format useable by each of said one or more device security-related applications.
19 . The system of claim 18 , wherein said one or more device security-related applications include supply chain risk management.
20 . The system of claim 17 , wherein each of said one or more PEs is configured to store in its PE memory an ALVS record containing the content of each ALVS provided by the PE to DMSs and including identification of the recipient DMSs.
21 . The system of claim 20 , wherein each of said one or more VAs is configured to store in its VA memory an LVS record containing the content of each LVS provided by the VA to PEs and identification of the recipient PEs.
22 . The system of claim 21 , wherein each of said one or more VAs is configured to perform a one-way algorithmic transformation of hardware specific data in said loaded CVS, and wherein each LVS record further includes or is associated with an algorithm record stored in said VA memory identifying the algorithm and parameters used in the creation of LVSs it has created.
23 . The system of claim 22 , wherein said one or more VAs are configured to, in response to an authorized entity's request for tracing, provide part of its CVS record, LVS record, and algorithm record to the authorized entity.
24 . The system of claim 23 , wherein said DMS is further configured to, in response to an authorized entity's request for tracing, provide part of its ALVS record to the authorized entity.
25 . The system of claim 1 , wherein said one or more VAs are configured to create a replacement LVS.
26 . The system of claim 25 , wherein said one or more PEs are configured to convey information regarding any device-level security compromise to a VA, and said VA is configured to utilize said information in a blacklist of CVS elements.
27 . The system of claim 1 , wherein said one or more PEs are configured to construct a replacement ALVS.
28 . The system of claim 27 , said one or more VAs are configured to create a replacement LVS.
29 . The system of claim 27 , wherein said one or more PEs are configured to exclude, from said replacement ALVS, data that was included in a loaded ALVS.
30 . The system of claim 29 , wherein said one or more PEs are configured to construct said replacement ALVS without employing a one-way algorithmic transformation.
31 . The system of claim 3 , wherein said one or more VAs are configured to create a replacement LVS by performing a different one-way algorithmic transformation of hardware specific data in said loaded CVS than the one-way algorithmic transformation that was used to create the loaded LVS.
32 . The system of claim 1 , wherein said loaded CVS includes challenge-response pairs.
33 . The system of claim 3 , wherein said loaded CVS includes challenge-response pairs.
34 . The system of claim 33 , wherein said loaded LVS includes elements that each comprise a collection of unobfuscated challenge value/obfuscated response value pairings, and wherein each said element is bound to a unique identity of a hardware part having a physically-unclonable function (“PUF”).
35 . The system of claim 34 , wherein each of said elements is encrypted.
36 . The system of claim 34 , wherein each hardware part further includes a memory loaded with a record of algorithms and parameters used in the creation of data contained in said loaded LVS.
37 . The system of claim 36 , wherein each hardware part further includes a controller configured to process data received from the hardware part's PUF using information contained in said record of algorithms and parameters.
38 . The system of claim 37 , wherein each hardware part further includes a memory loaded with a key that is shared with a VA but is not shared with any DMS.
39 . A method of providing resilient device authentication, comprising:
a. establishing one or more verification authorities (“VAs”) each having a VA memory; b. loading one or more VA memories with a complete verification set (“loaded CVS”) that includes hardware part-specific data; c. creating one or more limited verification sets (“LVSs”) from said loaded CVS; d. establishing one or more provisioning entities (“PEs”) each connectable to at least one of said one or more VAs, and each having a PE memory; e. loading each PE memory with a LVS (“loaded LVS”); f. selecting a subset of data from said loaded LVS so as to create an application limited verification set (“ALVS”); g. establishing one or more device management systems (“DMSs”) connectable to at least one of said one or more PEs, each DMS including a DMS memory; h. loading each DMS memory with an ALVS (“loaded ALVS”); and i. causing one or more DMSs to manage one or more device security-related applications through the performance of security-related functions on devices associated with hardware part-specific data in said loaded CVS.
40 . The method of claim 39 , wherein step c. is performed by one or more VAs utilizing a one-way algorithmic transformation of hardware specific data in said loaded CVS.
41 . The method of claim 39 , further comprising the steps of connecting a PE to a VA, and conveying an LVS from the VA to the PE.
42 . The method of claim 41 , further comprising the step of a VA storing a LVS record containing the content of each LVS provided by it to PEs and an identification of the recipient PEs.
43 . The method of claim 39 , further comprising the steps of connecting a DMS to a PE, and conveying an ALVS from the PE to the DMS.
44 . The method of claim 43 , further comprising the step of a PE storing an ALVS record containing the content of each ALVS provided by it to DMSs and an identification of the recipient DMSs.
45 . The method of claim 39 , wherein step i. further includes said one or more DMSs storing a record of device interactions.Join the waitlist — get patent alerts
Track US2013212642A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.