Device key security

US10680814B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10680814-B2
Application numberUS-201615168384-A
CountryUS
Kind codeB2
Filing dateMay 31, 2016
Priority dateMay 28, 2015
Publication dateJun 9, 2020
Grant dateJun 9, 2020

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A device, method or server having memory configured to store cryptographic material required to execute one or more device functions. A communications interface for communicating over a network. Logic configured to receive from the server over the communications interface the cryptographic material required to execute the one or more device functions. The device is configured to delete the cryptographic material from the memory.

First claim

Opening claim text (preview).

The invention claimed is: 1. A device comprising: active memory that requires power to store data and that is configured to store cryptographic material required to execute one or more device functions; a communications interface for communicating over a network; and logic configured to: receive, from a server over the communications interface, the cryptographic material required to execute the one or more device functions; store the cryptographic material in the active memory, wherein the device is configured to cause the cryptographic material to become unavailable for use in the active memory in response to a detection of one or more triggers, and wherein causing the cryptographic material to become unavailable for use in the active memory includes deleting the cryptographic material; and upon detection of a firmware or other software version update of the device and to protect against version rollback, change the cryptographic material during the firmware or other software version update, whereby the cryptographic material is protected from being used maliciously as a result of how the cryptographic material is stored and as a result of how the cryptographic material is managed upon detection of certain triggering events. 2. The device of claim 1 , wherein the cryptographic material is a device key. 3. The device of claim 1 , wherein the logic is further configured to run a generic bootstrapping architecture (GBA) protocol, and wherein the cryptographic material is received from the server and is protected using said GBA protocol. 4. The device according to claim 1 , wherein the one or more device functions include any one or more of: encryption of content or communications, decryption of content or communications, validation, authentication, validation of a new subscriber identity module (SIM) and firmware update. 5. The device according to claim 1 , wherein the communications interface is a cellular interface. 6. The device according to claim 1 , wherein the logic is further configured to receive from the server over the communications interface the cryptographic material during a boot process of the device. 7. The device according to claim 1 , further comprising memory storing one or more other device functions not requiring the cryptographic material to execute. 8. The device of claim 7 , wherein the one or more other device functions not requiring the cryptographic material to execute include any one or more of: a boot-loader, communication over the communications interface, and establishment of a secure communication over the communications interface. 9. The device according to claim 1 , wherein the device further comprises at least one of: customer premises equipment (CPE); a machine to machine (M2M) device; a DSL or cable modem; or a Wi-Fi router. 10. The device of claim 1 , wherein the logic is further configured to detect a tampering event in which the device is being tampered. 11. The device of claim 1 , wherein the cryptographic material is a device key, and wherein the device key is a symmetric key usable for encryption, decryption, and integrity checking. 12. The device of claim 1 , wherein the cryptographic material is a device key, and wherein the device key is an asymmetric key, and wherein a separate key is used for integrity checking and authentication. 13. The device of claim 1 , wherein the cryptographic material is a device key, and wherein the device key is a single device-specific-encryption key (DSEK). 14. The device of claim 13 , wherein, upon powering off or returning to a sleeping state, the device erases the DSEK. 15. A method comprising the steps of: receiving from a server over a communications network cryptographic material; storing the cryptographic material in an active memory within a device, the active memory requiring power to store data; in response to a detection of one or more triggers, causing the cryptographic material to become unavailable for use in the active memory, the cryptographic memory being required to execute one or more device functions stored within the device, wherein causing the cryptographic material to become unavailable for use in the active memory includes deleting the cryptographic material; and upon detection of a firmware or other software version update of the device and to protect against version rollback, changing the cryptographic material during the firmware or other software version update, whereby the cryptographic material is protected from being used maliciously as a result of how the cryptographic material is stored and as a result of how the cryptographic material is managed upon detection of certain triggering events. 16. The method of claim 15 , wherein the server provides the cryptographic material to the device by retrieving the cryptographic material from a cryptographic material store and sending the cryptographic material to the device over the communications network. 17. The method of claim 15 , wherein the method further comprises using the cryptographic material to execute one of the one or more device functions. 18. The method according to claim 15 , wherein the method further comprises: decrypting a device key using the cryptographic material; and executing one of the one or more device functions using the device key. 19. The method according to claim 15 , wherein the device further comprises at least one of: customer premises equipment (CPE); a machine to machine (M2M) device; a DSL or cable modem; or a Wi-Fi router. 20. The method according to claim 15 , wherein the cryptographic material is received during a boot process of the device.

Assignees

Inventors

Classifications

  • Key management, e.g. using generic bootstrapping architecture [GBA] · CPC title

  • H04L9/0894Primary

    Escrow, recovery or storing of secret information, e.g. secret key escrow or cryptographic key storage · CPC title

  • G06F21/575Primary

    Secure boot · CPC title

  • H04L9/0891Primary

    Revocation or update of secret information, e.g. encryption key update or rekeying · CPC title

  • using a trusted network node as an anchor · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10680814B2 cover?
A device, method or server having memory configured to store cryptographic material required to execute one or more device functions. A communications interface for communicating over a network. Logic configured to receive from the server over the communications interface the cryptographic material required to execute the one or more device functions. The device is configured to delete the cryp…
Who is the assignee on this patent?
Vodafone Ip Licensing Ltd
What technology area does this patent fall under?
Primary CPC classification H04L9/0894. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jun 09 2020 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).