IP Library Granted Patent US 7,802,092
Granted Patent B1
US 7,802,092 · App. 11/242,213 · Granted Sep 21, 2010

Method and system for automatic secure delivery of appliance updates

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,802,092
App. No.
11/242,213
Granted
Sep 21, 2010
Kind
B1
Abstract

A system and method to securely deliver software updates to an appliance are provided. The system comprises a key generator, a reporting module, and a certificate signing request (CSR) module. The key generator may be configured to generate, at the processing system, verification data for the processing system. The reporting module may be configured to communicate the verification data from the processing system to a verification database. The certificate signing request (CSR) module may be configured to obtain a signed certificate from a certificate authority (CA) based on the verification data stored in the verification database.

Claims (51)

1. An appliance, comprising:

a memory;

a network interface device;

a processor connected to the memory and the network interface device;

a key generator configured to generate, via the processor of the appliance, a manufacturing public key for the appliance;

a reporting module coupled to the key generator and configured to communicate via the network interface device verification data, including the manufacturing public key and a serial number of the appliance, from the appliance to a verification database; and

a certificate signing request (CSR) module configured to obtain via the network interface device a signed certificate from a certificate authority (CA) based on the verification data stored in the verification database, wherein the CA has access to the verification database.

2. The appliance of claim 1 , wherein the key generator is configured to generate the verification data by:

generating a plurality of prime numbers;

deriving, from the plurality of prime numbers, a manufacturing key pair, the manufacturing key pair including a manufacturing private key and the manufacturing public key; and

associating the serial number of the appliance with the manufacturing public key.

3. The appliance of claim 2 , further comprising a non-volatile memory configured to store the plurality of prime numbers.

4. The appliance of claim 3 , wherein the non-volatile memory is an electrically erasable programmable read-only memory (EEPROM).

5. The appliance of claim 3 , wherein the key generator is further configured to recreate the manufacturing private key utilizing the plurality of prime numbers stored in the non-volatile memory.

6. The appliance of claim 5 , wherein the CSR includes the serial number of the appliance and the CSR is signed with the manufacturing private key.

7. The appliance of claim 3 , wherein the key generator is further configured to generate a communications key pair, the communications key pair comprising a communications public key.

8. The appliance of claim 7 , wherein the CSR includes the communications public key as a subject key.

9. The appliance of claim 1 , wherein the appliance is a proxy server.

10. A method to permit secure communications with an appliance, the method comprising:

generating, at the appliance, verification data, including a manufacturing public key and a serial number of the appliance, for the appliance;

communicating the verification data to a verification database;

generating, at the appliance, a certificate signing request (CSR) including the serial number of the appliance, wherein the CSR is signed with a manufacturing private key;

sending the CSR to a certificate authority (CA); and

obtaining, at the appliance, a signed certificate from the CA based on the verification data obtained from the verification database, wherein the CA has access to the verification database.

11. The method of claim 10 , wherein generating the verification data further comprises:

generating a plurality of prime numbers;

deriving, from the plurality of prime numbers, a manufacturing key pair, the manufacturing key pair including the manufacturing private key and the manufacturing public key;

associating the serial number of the appliance with the manufacturing public key; and

identifying the associated serial number and the manufacturing public key as the verification data.

12. The method of claim 11 , further comprising storing, in a non-volatile memory of the appliance, the plurality of prime numbers.

13. The method of claim 12 , wherein obtaining the signed certificate further comprises:

receiving the signed certificate;

accepting the signed certificate; and

storing the signed certificate at the appliance.

14. The method of claim 10 , further comprising generating a communications key pair, the communications key pair comprising a communications public key.

15. The method of claim 14 , wherein the CSR includes the communications public key as a subject key.

16. The method of claim 15 , further comprising:

establishing a secure connection with a download server utilizing the signed certificate; and

receiving a software update from the download server according to the serial number of the appliance.

17. The method of claim 15 , further comprising establishing a secure connection with another appliance utilizing the signed certificate.

18. The method of claim 15 , further comprising establishing a secure connection with a management node associated with the appliance, utilizing the signed certificate.

19. A method to permit secure communications with an appliance, the method comprising:

receiving, from the appliance, a certificate signing request (CSR) signed with a manufacturing private key from a manufacturing key pair, wherein the CSR includes a serial number of the appliance and a communications public key from a communications key pair;

extracting the serial number from the CSR;

interrogating a verification database with the serial number to access a manufacturing public key associated with the serial number;

verifying the signature on the CSR with the manufacturing public key; and

responsive to verifying the signature on the CSR with the manufacturing public key, returning a signed certificate to the appliance.

20. A non-transitory tangible machine-readable medium having stored thereon data representing sets of instructions which, when executed by a machine, cause the machine to:

generate, at a processing system of an appliance, verification data, including a manufacturing public key and a serial number of the appliance, for the processing system;

communicate the verification data from the processing system of the appliance to a verification database; and

obtain a signed certificate from a certificate authority (CA), based on the verification data stored in the verification database, wherein the CA has access to the verification database.

Assignments (8)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2019
From: SYMANTEC CORPORATION
To: CA, INC.
Reel/Frame 051144/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2016
From: BLUE COAT SYSTEMS, INC.
To: SYMANTEC CORPORATION
Reel/Frame 039851/0044 →
RELEASE OF SECURITY INTEREST Recorded Aug 1, 2016
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 039516/0929 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 30740/0181 Recorded May 29, 2015
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 035797/0280 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 27727/0144 Recorded May 29, 2015
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 035798/0006 →
SECURITY INTEREST Recorded May 22, 2015
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS THE COLLATERAL AGENT
Reel/Frame 035751/0348 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 3, 2013
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 030740/0181 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL RECORDED AT R/F 027727/0178 Recorded Oct 16, 2012
From: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 029140/0170 →