US2023006821A1PendingUtilityA1

Cryptographic feature licensing

Assignee: ROCKWELL AUTOMATION TECH INCPriority: Sep 24, 2019Filed: Sep 15, 2022Published: Jan 5, 2023
Est. expirySep 24, 2039(~13.1 yrs left)· nominal 20-yr term from priority
H04L 9/0825G05B 19/4185H04L 9/3263G06F 21/629H04L 9/006G06F 21/10H04L 9/3247
56
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Techniques to facilitate feature licensing of an industrial controller employed in an industrial automation environment are disclosed. In one implementation, a first private key unique to an industrial controller and a security certificate is stored in a hardware root of trust within the controller. The security certificate is signed by a certificate authority for authenticating the controller. After being authenticated, the industrial controller receives a device information package provided by the certificate authority. The device information package is encrypted with a first public key paired with the first private key and signed using a second private key assigned to the certificate authority. The controller validates the device information package using a second public key paired with the second private key and decrypts the package using the first private key. One or more functions of the industrial controller are enabled based on a license included in the device information package.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method for licensing features of industrial devices employed in an industrial automation environment, the method comprising:
 storing, in a hardware root of trust within an industrial controller, a first private key unique to the industrial controller and a security certificate, wherein the security certificate is signed by a certificate authority for authenticating the industrial controller;   receiving, at the industrial controller, a device information package provided by the certificate authority, wherein the device information package is encrypted with a first public key paired with the first private key and signed using a second private key assigned to the certificate authority;   validating, at the industrial controller, the device information package using a second public key paired with the second private key;   decrypting, at the industrial controller, the validated device information package using the first private key; and   enabling one or more functions of the industrial controller based on a license included in the device information package.   
     
     
         2 . The method of  claim 1  further comprising:
 receiving, at the industrial controller, a revocation of the license provided by the certificate authority, and 
 disabling, at the industrial controller, the one or more functions of the industrial device controller based on the revocation of the license. 
 
     
     
         3 . The method of  claim 2  further comprising:
 generating, at the industrial controller, a record that indicates the license was revoked, and 
 signing, at the industrial controller, the record using the first private key unique to the industrial controller. 
 
     
     
         4 . The method of  claim 1  wherein the second public key is securely stored in the hardware root of trust within the industrial controller. 
     
     
         5 . The method of  claim 1  wherein the first private key and the security certificate are securely stored in the hardware root of trust within the industrial controller during manufacturing of the industrial controller. 
     
     
         6 . An industrial controller employed in an industrial automation environment, the industrial controller comprising:
 a hardware root of trust that stores a first private key unique to the industrial controller and a security certificate, wherein the security certificate is signed by a certificate authority for authenticating the industrial controller; and   a processor configured to:
 receive a device information package provided by the certificate authority, wherein the device information package is encrypted with a first public key paired with the first private key and signed using a second private key assigned to the certificate authority; 
 validate the device information package using a second public key paired with the second private key; 
 decrypt the validated device information package using the first private key; and 
 enable one or more functions of the industrial controller based on a license included in the device information package. 
   
     
     
         7 . The industrial controller of  claim 6 , wherein the processor is further configured to:
 receive a revocation of the license provided by the certificate authority, and   disable the one or more functions of the industrial device controller based on the revocation of the license.   
     
     
         8 . The industrial controller of  claim 7 , wherein the processor is further configured to:
 generate a record that indicates the license was revoked; and   sign the record using the first private key unique to the industrial controller.   
     
     
         9 . The industrial controller of  claim 6 , wherein the second public key is securely stored in the hardware root of trust within the industrial controller. 
     
     
         10 . The industrial controller of  claim 6 , wherein the first private key and the security certificate are securely stored in the hardware root of trust within the industrial controller during manufacturing of the industrial controller.

Join the waitlist — get patent alerts

Track US2023006821A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.