System and method for controlling features on a device

US10003580B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10003580-B2
Application numberUS-201213615311-A
CountryUS
Kind codeB2
Filing dateSep 13, 2012
Priority dateDec 13, 2007
Publication dateJun 19, 2018
Grant dateJun 19, 2018

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Trust between entities participating in an upgrade or enablement/disablement process is established and, to facilitate this remotely and securely, a highly tamper resistant point of trust in the system that is being produced is used. This point of trust enables a more efficient distribution system to be used. Through either a provisioning process or at later stages, i.e. subsequent to installation, manufacture, assembly, sale, etc.; the point of trust embodied as a feature controller on the device or system being modified is given a feature set (or updated feature set) that, when validated, is used to enable or disable entire features or to activate portions of the feature.

First claim

Opening claim text (preview).

The invention claimed is: 1. A method operable with a feature controller of a device for provisioning features in the device, the feature controller performing: participating in a public key based key agreement with a remote server, by performing cryptographic operations using a connection between the feature controller and the remote server, to establish a shared secret with the remote server, wherein the shared secret is a shared key established in the key agreement; storing the shared secret in a secure memory within the feature controller; receiving, at the device, a message comprising an encrypted control instruction for controlling the device and a signature, the signature having been generated using the control instruction and information provided by the device, the information provided by the device comprising an identifier associated with the device derived from at least a portion of a public key of a static key pair; decrypting the encrypted control instruction using the shared secret to obtain a decrypted control instruction; storing the decrypted control instruction in the feature controller; verifying the signature; and in response to said verifying the signature, executing the control instruction. 2. The method of claim 1 , wherein the information provided by the device comprises an ephemeral public key provided to the remote server during the key agreement. 3. The method of claim 1 , wherein the key agreement comprises an elliptic curve based key agreement. 4. The method of claim 1 , wherein the key agreement comprises an elliptic curve Menezes-Qu-Vanstone (ECMQV) key agreement. 5. The method of claim 1 , wherein the identifier associated with the device is generated using a static key pair. 6. The method of claim 1 , wherein the control instruction comprises feature control programming. 7. The method of claim 1 , wherein the control instruction comprises at least one command. 8. The method of claim 1 , wherein the identifier is unique to the device. 9. The method of claim 1 , wherein the identifier is unique to a group comprising a plurality of devices. 10. The method of claim 1 , wherein the message is a concatenation of the encrypted control instruction and the signature. 11. A non-transitory computer readable medium comprising computer executable instructions for performing operations at a device for provisioning features in the device, the operations comprising: participating in a public key based key agreement with a remote server, by performing cryptographic operations using a connection between a feature controller of a device and the remote server, to establish a shared secret with the remote server, wherein the shared secret is a shared key established in the key agreement; storing the shared secret in a secure memory within the feature controller; receiving, at the device, a message comprising an encrypted control instruction for controlling the device and a signature, the signature having been generated using the control instruction and information provided by the device, the information provided by the device comprising an identifier associated with the device derived from at least a portion of a public key of a static key pair; decrypting the encrypted control instruction using the shared secret to obtain a decrypted control instruction; storing the decrypted control instruction in the feature controller; verifying the signature; and in response to said verifying the signature, executing the control instruction. 12. A device comprising: a processor; a feature controller for provisioning features of the device; a connection between the feature controller and a remote server; and at least one memory, the memory comprising computer executable instructions that when executed by the processor operate the device to: participate in a public key based key agreement with the remote server, by performing cryptographic operations using the connection between the feature controller and the remote server, to establish a shared secret with the remote server, wherein the shared secret is a shared key established in the key agreement; store the shared secret in a secure memory within the feature controller; receive, at the device, a message comprising an encrypted control instruction for controlling the device and a signature, the signature having been generated using the control instruction and information provided by the device, the information provided by the device comprising an identifier associated with the device derived from at least a portion of a public key of a static key pair; decrypt the encrypted control instruction using the shared secret to obtain a decrypted control instruction; store the decrypted control instruction in the feature controller; verify the signature; and in response to verifying the signature, execute the control instruction.

Assignees

Inventors

Classifications

  • Metering · CPC title

  • for key exchange, e.g. in peer-to-peer networks (cryptographic mechanisms or cryptographic arrangements for key agreement H04L9/0838) · CPC title

  • wherein the data content is protected, e.g. by encrypting or encapsulating the payload · CPC title

  • Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities · CPC title

  • involving control of end-device applications over a network · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10003580B2 cover?
Trust between entities participating in an upgrade or enablement/disablement process is established and, to facilitate this remotely and securely, a highly tamper resistant point of trust in the system that is being produced is used. This point of trust enables a more efficient distribution system to be used. Through either a provisioning process or at later stages, i.e. subsequent to installat…
Who is the assignee on this patent?
Daskalopoulos Michael, Vadekar Ashok, Wong David, and 4 more
What technology area does this patent fall under?
Primary CPC classification H04L63/0428. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jun 19 2018 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).