IP Library Granted Patent US 8,266,424
Granted Patent B2
US 8,266,424 · App. 11/395,588 · Granted Sep 11, 2012

Method and system for in-field recovery of security when a certificate authority has been compromised

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,266,424
App. No.
11/395,588
Granted
Sep 11, 2012
Kind
B2
Abstract

A certificate credential is generated based on a user device's private key securely stored, or accessible, by a certificate authority. When the certificate authority has been compromised, the credential, which typically includes information encrypted with the device's private key and the corresponding unencrypted information, is sent to the device. The device receives the information in encrypted and unencrypted form and decrypts the encrypted information. If the result of the decryption matches the unencrypted information, the device trusts the signer of the credential.

Claims (36)

1. A method for remotely replacing a certificate associated with a device, comprising:

identifying an update to security information used by the device;

generating a configuration file for a device responsive to the update;

including certificate credential information within the configuration file, wherein the certificate credential information is encrypted or signed using a private key associated with the device; and

sending the configuration file over a communications network to the device in response to a TFTP request received from the device during a registration process for the device to join the communications network;

adding a reissued code verification certificate and manufacturer certificate renewal credential information to the configuration file, the reissued code verification certificate being operable to be used to verify the authenticity of a reissued root certificate based on root certificate renewal credential information and causes the device to download a new software image from a server based upon the authenticity of the reissued root certificate.

2. The method of claim 1 wherein the certificate credential information is associated with a manufacturer certificate authority.

3. The method of claim 1 wherein the certificate credential information is associated with a root certificate authority.

4. The method of claim 1 wherein a manufacturing certificate authority retrieves the private key associated with the device from a secure database for storing a plurality of device private keys.

5. The method of claim 1 wherein the new software image contains a manufacturer certificate.

6. The method of claim 1 wherein the new software image is securely downloaded.

7. The method of claim 1 further comprising:

rebooting the device using the new software image; downloading a reissued device certificate;

verifying the reissued device certificate using a new manufacturer certificate contained in the new software image; and

storing the reissued device certificate into a device memory.

8. The method of claim 6 wherein a secure software download is used to securely download the new software image based on the reissued code verification certificate.

9. The method of claim 7 , further comprising overwriting an existing device certificate from the device memory.

10. A method for remotely replacing a device certificate, comprising:

writing certificate credential information into a configuration file, wherein the certificate credential information is based on a private key of the device; and

sending the configuration file to the device in response to a request;

verifying the configuration file based on the credential information;

overwriting an existing device certificate from a device memory;

wherein the credential information includes manufacturer certificate renewal credential information;

adding a reissued code verification certificate to the configuration file, the reissued code verification certificate being operable to be used to verify the authenticity of a reissued root certificate based on root certificate renewal credential information and causes the device to download a new software image from a server based upon the authenticity of the reissued root certificate.

11. The method of claim 10 wherein the existing device certificate is overwritten with null data.

12. The method of claim 10 further comprising:

downloading a new software image to the device from a server based on a server address contained in the configuration file.

13. The method of claim 12 wherein the new software image contains a manufacturer certificate.

14. The method of claim 12 wherein the new software image is securely downloaded.

15. The method of claim 13 further comprising:

rebooting the device using the new software image;

determining that the existing device certificate has been overwritten;

downloading a new device certificate;

verifying the new device certificate using the new manufacturer certificate contained in the new software image; and

storing the new device certificate into a device memory.

16. The method of claim 14 wherein a secure software download mechanism is used to securely download the new software image.

Assignments (13)
RELEASE OF SECURITY INTEREST AT REEL/FRAME 049905/0504 Recorded Dec 19, 2024
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: ARRIS ENTERPRISES LLC (F/K/A ARRIS ENTERPRISES, INC.); ARRIS TECHNOLOGY, INC.; ARRIS SOLUTIONS, INC.; COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; RUCKUS WIRELESS, LLC (F/K/A RUCKUS WIRELESS, INC.)
Reel/Frame 071477/0255 →
SECURITY INTEREST Recorded Dec 17, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE INC., OF NORTH CAROLINA; OUTDOOR WIRELESS NETWORKS LLC; RUCKUS IP HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC
Reel/Frame 069889/0114 →
SECURITY INTEREST Recorded Nov 19, 2021
From: ARRIS SOLUTIONS, INC.; ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA; RUCKUS WIRELESS, INC.
To: WILMINGTON TRUST
Reel/Frame 060752/0001 →
TERM LOAN SECURITY AGREEMENT Recorded Jul 3, 2019
From: COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; ARRIS ENTERPRISES LLC; ARRIS TECHNOLOGY, INC.; RUCKUS WIRELESS, INC.; ARRIS SOLUTIONS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 049905/0504 →
PATENT SECURITY AGREEMENT Recorded Jul 3, 2019
From: ARRIS ENTERPRISES LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 049820/0495 →
ABL SECURITY AGREEMENT Recorded Jul 3, 2019
From: COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; ARRIS ENTERPRISES LLC; ARRIS TECHNOLOGY, INC.; RUCKUS WIRELESS, INC.; ARRIS SOLUTIONS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 049892/0396 →
CHANGE OF NAME Recorded Jun 25, 2019
From: ARRIS ENTERPRISES, INC.
To: ARRIS ENTERPRISES LLC
Reel/Frame 049586/0470 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Apr 8, 2019
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: ARRIS GROUP, INC.; ARRIS ENTERPRISES, INC.; ARRIS SOLUTIONS, INC.; ARRIS KOREA, INC.; ARRIS HOLDINGS CORP. OF ILLINOIS, INC.; BIG BAND NETWORKS, INC.; TEXSCAN CORPORATION; POWER GUARD, INC.; 4HOME, INC.; ACADIA AIC, INC.; AEROCAST, INC.; BROADBUS TECHNOLOGIES, INC.; GENERAL INSTRUMENT CORPORATION; GENERAL INSTRUMENT AUTHORIZATION SERVICES, INC.; GENERAL INSTRUMENT INTERNATIONAL HOLDINGS, INC.; IMEDIA CORPORATION; JERROLD DC RADIO, INC.; LEAPSTONE SYSTEMS, INC.; MODULUS VIDEO, INC.; MOTOROLA WIRELINE NETWORKS, INC.; NETOPIA, INC.; NEXTLEVEL SYSTEMS (PUERTO RICO), INC.; QUANTUM BRIDGE COMMUNICATIONS, INC.; SETJAM, INC.; SUNUP DESIGN SYSTEMS, INC.; UCENTRIC SYSTEMS, INC.; GIC INTERNATIONAL HOLDCO LLC; GIC INTERNATIONAL CAPITAL LLC; CCE SOFTWARE LLC; THE GI REALTY TRUST 1996
Reel/Frame 048825/0294 →
CHANGE OF NAME Recorded Mar 14, 2017
From: ARRIS ENTERPRISES INC
To: ARRIS ENTERPRISES LLC
Reel/Frame 041995/0031 →
SECURITY AGREEMENT Recorded May 28, 2013
From: ARRIS GROUP, INC.; ARRIS ENTERPRISES, INC.; ARRIS SOLUTIONS, INC.; ARRIS KOREA, INC.; ARRIS HOLDINGS CORP. OF ILLINOIS; BIGBAND NETWORKS, INC.; TEXSCAN CORPORATION; POWER GUARD, INC.; 4HOME, INC.; ACADIA AIC, INC.; AEROCAST, INC.; BROADBUS TECHNOLOGIES, INC.; GENERAL INSTRUMENT CORPORATION; GENERAL INSTRUMENT AUTHORIZATION SERVICES, INC.; GENERAL INSTRUMENT INTERNATIONAL HOLDINGS, INC.; IMEDIA CORPORATION; JERROLD DC RADIO, INC.; LEAPSTONE SYSTEMS, INC.; MODULUS VIDEO, INC.; MOTOROLA WIRELINE NETWORKS, INC.; NETOPIA, INC.; NEXTLEVEL SYSTEMS (PUERTO RICO), INC.; QUANTUM BRIDGE COMMUNICATIONS, INC.; SETJAM, INC.; SUNUP DESIGN SYSTEMS, INC.; UCENTRIC SYSTEMS, INC.; GIC INTERNATIONAL HOLDCO LLC; GIC INTERNATIONAL CAPITAL LLC; CCE SOFTWARE LLC; THE GI REALTY TRUST 1996
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 030498/0023 →
MERGER Recorded Apr 16, 2013
From: ARRIS GROUP, INC.
To: ARRIS ENTERPRISES, INC.
Reel/Frame 030223/0244 →
MERGER Recorded Mar 19, 2012
From: ARRIS INTERNATIONAL, INC.
To: ARRIS GROUP, INC.
Reel/Frame 027883/0254 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 5, 2006
From: NEGAHDAR, ALI
To: ARRIS INTERNATIONAL, INC.
Reel/Frame 017733/0939 →