Secure provisioning of keys
US-2020344075-A1 · Oct 29, 2020 · US
US11809170B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-11809170-B2 |
| Application number | US-202117393420-A |
| Country | US |
| Kind code | B2 |
| Filing date | Aug 4, 2021 |
| Priority date | Aug 7, 2020 |
| Publication date | Nov 7, 2023 |
| Grant date | Nov 7, 2023 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
An industrial automation system device includes: a secure communication processing unit for communicating securely with a further trusted industrial automation system device; and a pre-shared secret module including a pre-shared secret, the pre-shared secret including shared asymmetric key pair generation data. The secure communication processing unit: derives a shared asymmetric key pair including a shared secret key and a shared public key from the shared asymmetric key pair generation data, derives a shared certificate including the shared public key, signs the shared certificate with the derived shared secret key, and generates a device asymmetric key pair including a device secret key and a device public key.
Opening claim text (preview).
What is claimed is: 1. An industrial automation system device, comprising: a secure communication hardware processor configured to communicate securely with a further trusted industrial automation system device; and a pre-shared secret module comprising a pre-shared secret, the pre-shared secret comprising shared asymmetric key pair generation data, wherein the secure communication hardware processor is configured to: derive a shared asymmetric key pair comprising a shared secret key and a shared public key from the shared asymmetric key pair generation data; derive a shared certificate comprising the shared public key; sign the shared certificate with the shared secret key; generate a device asymmetric key pair comprising a device secret key and a device public key; and derive a device certificate comprising the device public key and signed with the shared secret key. 2. The industrial automation system device of The industrial automation system device of further comprising: an OPC Unified Architecture device, wherein the device certificate comprises a device specific Application Instance Certificate, and wherein the shared certificate comprises a shared Application Instance Certificate. 3. The industrial automation system device of claim 1 , wherein the pre-shared secret further comprises shared certificate related information, and wherein the communication hardware processor is configured to derive the shared certificate from the shared certificate related information of the pre-shared secret. 4. The industrial automation system device of claim 1 , wherein the device certificate comprises pre-configured default data. 5. The industrial automation system device of claim 1 , wherein a key generation algorithm for generating the shared asymmetric key pair comprises an algorithm identical to an algorithm used by the further device. 6. The industrial automation system device of claim 1 , wherein the pre-shared secret provides a sufficient entropy to derive the shared asymmetric key pair in a cryptographically secure way. 7. The industrial automation system device of claim 1 , wherein the secure communication hardware processor is further configured to use a regular entropy source for generating the device asymmetric key pair. 8. The industrial automation system device of claim 1 , further comprising: a certificate store comprising the device certificate; and a trust list comprising the shared certificate. 9. The industrial automation system device of claim 3 , wherein the shared certificate related information of the pre-shared secret comprises one or more of the following: subject name, validity period, certificate signature algorithm, version, serial number, signature hash algorithm, issuer, public key, public key parameters, basic constraints, alternative name, subject key identifier, authority key identifier, key usage, and/or thumbprint. 10. The industrial automation system device of claim 3 , wherein the shared certificate related information for the shared certificate and the device certificate of the pre-shared secret are each interpreted as an X.509 certificate. 11. The industrial automation system device of claim 1 , wherein the pre-shared secret is provided to the device by pre-configuration or through an external access interface. 12. An industrial automation system, comprising: at least one industrial automation system device that comprises: a secure communication hardware processor configured to communicate securely with a further trusted industrial automation system device; and a pre-shared secret module comprising a pre-shared secret, the pre-shared secret comprising shared asymmetric key pair generation data, wherein the secure communication hardware processor is configured to: derive a shared asymmetric key pair comprising a shared secret key and a shared public key from the shared asymmetric key pair generation data; derive a shared certificate comprising the shared public key; sign the shared certificate with the shared secret key; generate a device asymmetric key pair comprising a device secret key and a device public key; and derive a device certificate comprising the device public key and signed with the shared secret key. 13. The industrial automation system of claim 12 , wherein at least the further trusted device comprises an identical pre-shared secret for deriving identical shared asymmetric key pairs and an identical shared certificate. 14. A method for secure communication in an industrial automation system, comprising: providing a pre-shared secret comprising asymmetric key pair generation data; deriving a shared asymmetric key pair comprising a shared secret key and a shared public key from the asymmetric key pair generation data; deriving a shared certificate comprising the shared public key; signing the shared certificate with the shared secret key; generating a device asymmetric key pair comprising a device secret key and a device public key; and deriving a device certificate comprising the device public key and signed with the shared secret key. 15. The method of claim 14 , further comprising: trusting a further device based on the shared certificate and communicating securely with the further device based on the shared certificate and the device asymmetric key pair.
characterised by the network communication · CPC title
using asymmetric-key encryption or public key infrastructure [PKI], e.g. key signature or public key certificates · CPC title
using a plurality of keys or algorithms · CPC title
involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements (network architectures or network communication protocols for supporting authentication of entities using certificates in a packet data network H04L63/0823) · CPC title
wherein the sending and receiving network entities apply asymmetric encryption, i.e. different keys for encryption and decryption (cryptographic mechanisms or cryptographic arrangements for public-key encryption H04L9/30) · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.