US2017277895A1PendingUtilityA1
Staged Control Release In Boot Process
Assignee: INTERDIGITAL PATENT HOLDINGS INCPriority: Apr 12, 2010Filed: Jun 12, 2017Published: Sep 28, 2017
Est. expiryApr 12, 2030(~3.7 yrs left)· nominal 20-yr term from priority
H04L 9/0861G06F 21/57H04W 84/045H04W 12/10G06F 21/86H04L 63/08G06F 21/12H04W 12/108
54
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
Integrity validation of a network device may be performed. A network device comprising a secure hardware module, may receive a root key. The secure hardware module may also receive a first code measurement. The secure hardware module may provide a first key based on the root key and the first code measurement. The secure hardware module may receive a second code measurement and provide a second key based on the first key and the second code measurement. The release of keys based on code measurements may provide authentication in stages.
Claims
exact text as granted — not AI-modifiedWhat is claimed:
1 . A method to perform integrity validation of a network device, the method comprising:
receiving a measurement of first code stored in a memory of the network device; generating a first key based on a root key stored in a secure memory of the network device and the first code measurement, and wherein the first key relates to a first stage of trust associated with a first function of the network device, and wherein the first key is capable of being used by a first stakeholder to access the first function; receiving a measurement of second code stored in the memory of the network device; and generating a second key based on the first key and the second code measurement, wherein the second key relates to a second stage of trust associated with a second function of the network device, and wherein the second key is capable of being used by a second stakeholder to access the second function.
2 . The method of claim 1 , further comprising preventing access to the first function when the first code measurement is invalid.
3 . The method of claim 2 , further comprising preventing access to the second function when the second code measurement is invalid.
4 . The method of claim 1 , further comprising:
receiving a nonce; and sending a signed message in response to the nonce, wherein the signed message indicates an untrustworthy state, a partial trustworthy state, or a trustworthy state.
5 . The method of claim 4 , further comprising providing a last valid credential when the partial trustworthy state is indicated, wherein the last valid credential includes a last valid key associated with a last valid code measurement.
6 . The method of claim 4 , wherein the signed message further indicates a freshness of a boot state, and wherein the nonce is derived locally via at least one of a sequence counter or a date and time stamp function.
7 . The method of claim 1 , wherein the root key is stored in the secure memory at a time of manufacture or a time of provisioning.
8 . The method of claim 1 , wherein the secure memory is part of a secure hardware module and wherein the root key is not visible to software outside of the secure hardware module.Join the waitlist — get patent alerts
Track US2017277895A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.