IP Library Granted Patent US 9,094,699
Granted Patent B2
US 9,094,699 · App. 10/871,120 · Granted Jul 28, 2015

System and method for security key transmission with strong pairing to destination client

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,094,699
App. No.
10/871,120
Granted
Jul 28, 2015
Kind
B2
Abstract

Systems and methods for security key transmission with strong pairing to a destination client are disclosed. A security key may be generated by an on-chip key generator, an off-chip device, and/or software. A rule may then be paired with the security key and an address associated with the security key. The rule may define permissible usage by a destination module, which is defined by the associated address. The rule may comprise a command word, which may be implemented using a data structure associated with a permissible algorithm type, a security key size, and/or a security key source.

Claims (55)

1. A method for security key transmission, the method comprising:

generating, by at least one processor in an integrated circuit, a security key sequence comprising a security key, a security command comprising an algorithm associated with the security key, and an address associated with a destination module;

sending, by the processor, the security key sequence to the destination module; and

receiving, by the processor, an error message from the destination module in response to the algorithm being different than an algorithm configuration of the destination module.

2. The method of claim 1 , wherein the security command defines permissible usage by the destination module.

3. The method of claim 1 , further comprising:

sending, by the processor, a command word to the destination module.

4. The method of claim 3 , wherein the command word comprises instructions for the destination module to invalidate the security key.

5. The method of claim 1 , wherein the security command further comprises a security key size and a security key source.

6. The method of claim 1 , wherein the security command indicates whether the destination module is authorized to use the security key.

7. The method of claim 1 , further comprising:

generating the security key by a key generator disposed in the integrated circuit, an external key generator, or software.

8. The method of claim 1 , further comprising:

serially transmitting, by the processor, the security key sequence to the destination module.

9. The method of claim 1 , further comprising:

comparing, by the destination module, the algorithm with the algorithm configuration of the destination module.

10. The method of claim 9 , further comprising:

sending, by the destination module, the error message to the processor in response to the algorithm being different than the algorithm configuration of the destination module.

11. The method of claim 9 , further comprising:

invalidating, by the destination module, the security key in response to the algorithm being different than the algorithm configuration of the destination module.

12. A non-transitory machine-readable storage having stored thereon, a computer program having at least one code section for security key transmission, the at least one code section being executable by a machine for causing the machine to perform steps comprising:

generating a security sequence comprising a security key, a security command comprising an algorithm associated with the security key, and an address associated with a destination module;

sending the security sequence to the destination module; and

receiving an error message from the destination module in response to the algorithm being different than an algorithm configuration of the destination module.

13. The non-transitory machine-readable storage of claim 12 , wherein the security command defines permissible usage by the destination module.

14. The non-transitory machine-readable storage of claim 12 , the steps further comprising:

sending a command word to the destination module.

15. The non-transitory machine-readable storage of claim 12 , wherein the command word comprises instructions for the destination module to invalidate the security key.

16. The non-transitory machine-readable storage of claim 12 , wherein the security command further comprises a security key size and a security key source.

17. The non-transitory machine-readable storage of claim 12 , wherein the security command indicates whether the destination module is authorized to use the security key.

18. The non-transitory machine-readable storage of claim 12 , the steps further comprising

generating the security key by a key generator disposed in the integrated circuit, an external key generator, or software.

19. The non-transitory machine-readable storage of claim 12 , the steps further comprising:

serially transmitting the security key sequence to the destination module.

20. The non-transitory machine-readable storage of claim 12 , the steps further comprising:

comparing the algorithm with the algorithm configuration of the destination module.

21. The non-transitory machine-readable storage of claim 20 , the steps further comprising:

generating the error message to the processor in response to the algorithm being different than the algorithm configuration of the destination module.

22. The non-transitory machine-readable storage of claim 20 , the steps further comprising:

invalidating the security key in response to the algorithm being different than the algorithm configuration of the destination module.

23. A system for security key transmission, the system comprising:

at least one processor in an integrated circuit that is configured to generate a security key sequence comprising a security key, a security command comprising an algorithm associated with the security key, and an address associated with a destination module, wherein the processor is further configured to:

send the security key sequence to the destination module, and

receive an error message from the destination module in response to the algorithm being different than an algorithm configuration of the destination module.

24. The system of claim 23 , wherein the security command defines permissible usage by the destination module.

25. The system of claim 23 , wherein the processor is further configured to send a command word to the destination module.

26. The system of claim 25 , wherein the command word comprises instructions for the destination module to invalidate the security key.

27. The system of claim 23 , wherein the security command further comprises a security key size and a security key source.

28. The system of claim 23 , wherein the security command indicates whether the destination module is authorized to use the security key.

29. The system of claim 23 , further comprising a generator for generating the security key.

30. The system of claim 29 , wherein the generator comprises a key generator disposed in the integrated circuit, an external key generator, or software.

31. The system of claim 23 , wherein the processor is further configured to serially transmit the security key sequence to the destination module.

32. The system of claim 23 , further comprising a destination module processor configured to compare the algorithm with the algorithm configuration of the destination module.

33. The system of claim 32 , wherein the destination module processor is further configured to send the error message to the processor in response to the algorithm being different than the algorithm configuration of the destination module.

34. The system of claim 32 , wherein the destination module processor is further configured to invalidate the security key in response to the algorithm being different than the algorithm configuration of the destination module.

Assignments (8)
CORRECTIVE ASSIGNMENT TO CORRECT THE PATENT NUMBER 9,385,856 TO 9,385,756 PREVIOUSLY RECORDED AT REEL: 47349 FRAME: 001. ASSIGNOR(S) HEREBY CONFIRMS THE MERGER. Recorded Mar 22, 2019
From: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
To: AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE. LIMITED
Reel/Frame 051144/0648 →
CORRECTIVE ASSIGNMENT TO CORRECT THE EFFECTIVE DATE PREVIOUSLY RECORDED ON REEL 047229 FRAME 0408. ASSIGNOR(S) HEREBY CONFIRMS THE THE EFFECTIVE DATE IS 09/05/2018. Recorded Oct 29, 2018
From: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
To: AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE. LIMITED
Reel/Frame 047349/0001 →
MERGER Recorded Oct 4, 2018
From: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
To: AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE. LIMITED
Reel/Frame 047229/0408 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Feb 3, 2017
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: BROADCOM CORPORATION
Reel/Frame 041712/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 1, 2017
From: BROADCOM CORPORATION
To: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
Reel/Frame 041706/0001 →
PATENT SECURITY AGREEMENT Recorded Feb 11, 2016
From: BROADCOM CORPORATION
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 037806/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 12, 2015
From: CHEN, IUE-SHUENN; PATARIU, KEVIN
To: BROADCOM CORPORATION
Reel/Frame 035827/0634 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2004
From: CHEN, IUE-SHUENN; PATARIU, KEVIN
To: BROADCOM CORPORATION
Reel/Frame 015088/0460 →