IP Library Granted Patent US 8,639,939
Granted Patent B2
US 8,639,939 · App. 11/557,041 · Granted Jan 28, 2014

Control method using identity objects

Inventors: Michael Holtzman (Cupertino, CA); Ron Barzilai (Kfar-Vradim, IL); Fabrice Jogand-Coulomb (San Carlos, CA)
Assignee: SanDisk Technologies Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,639,939
App. No.
11/557,041
Granted
Jan 28, 2014
Kind
B2
Abstract

An object known as an identity object comprises a public key and a private key pair and at least one certificate issued by a certificate authority that certifies that the public key of the pair is genuine. In one embodiment, this object may be used as proof of identification by using the private key to sign data provided to it or signals derived from the data. An identity object may be stored in a non-volatile memory as proof of identity, where the memory is controlled by a controller. Preferably, a housing encloses the memory and the controller.

Claims (34)

1. A non-volatile memory card comprising:

housing in a shape of a card and having:

a controller;

a non-volatile memory storing a key pair comprising a private key and a public key, and a certificate for authenticating the key pair; and

an access control structure containing information usable by the controller for authenticating an entity and further information usable by the controller for determining a permission of the entity to access the key pair and certificate once the entity is authenticated by the controller;

wherein the controller is operative to

authenticate an entity to the non-volatile memory card using the access control structure; and

after the entity has been successfully authenticated:

receive data and a command to sign the data from the entity to provide proof of identity of the entity,

determine a permission of the entity to access the key pair and certificate;

employ the private key to sign the data or information derived from the data, wherein the signed data or information derived from the data provides proof of identity of the entity, and

send the certificate and the signed data or information derived from the data to the entity to provide proof of identity of the entity.

2. The non-volatile memory card of claim 1 , wherein the certificate is a certificate chain.

3. The non-volatile memory card of claim 1 , wherein the non-volatile memory comprises a flash memory.

4. The non-volatile memory card of claim 1 , wherein the access control structure allows only authenticated entities to access the data.

5. The non-volatile memory card of claim 1 , wherein the controller authenticates an entity using the access control structure and supplies to an authenticated entity the certificate to certify the public key.

6. The non-volatile memory card of claim 1 , wherein the entity comprises a host device removably connectable to the non-volatile memory card.

7. A method for providing proof of identity of an entity, the method comprising:

performing the following in a non-volatile memory card comprising a housing in a shape of a card and having: (i) a controller, (ii) a non-volatile memory storing a key pair comprising a private key and a public key, and a certificate for authenticating the key pair, and (iii) an access control structure containing information usable by the controller for authenticating an entity and further information usable by the controller for determining a permission of the entity to access the key pair and certificate once the entity is authenticated by the controller:

authenticating an entity to the non-volatile memory card using the access control structure; and

after the entity has been successfully authenticated:

receiving data and a command to sign the data from the entity to provide proof of identity of the entity,

determining a permission of the entity to access the key pair and certificate;

employing the private key to sign the data or information derived from the data, wherein the signed data or information derived from the data provides proof of identity of the entity, and

sending the certificate and the signed data or information derived from the data to the entity to provide proof of identity of the entity.

8. The method of claim 7 , wherein the method further comprises:

after the entity has been successfully authenticated, supplying to the entity the certificate to certify the public key;

receiving data encrypted by the public key; and

decrypting the data using the private key.

9. The method of claim 7 , wherein the certificate is a certificate chain.

10. The method of claim 7 , wherein the non-volatile memory comprises a flash memory.

11. The method of claim 7 , wherein the access control structure allows only authenticated entities to access the data.

12. The method of claim 7 , wherein the controller authenticates an entity using the access control structure and supplies to an authenticated entity the certificate to certify the public key.

13. The method of claim 7 , wherein the entity comprises a host device removably connectable to the non-volatile memory card.

Assignments (6)
PARTIAL RELEASE OF SECURITY INTERESTS Recorded Apr 25, 2025
From: JPMORGAN CHASE BANK, N.A., AS AGENT
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 071382/0001 →
SECURITY AGREEMENT Recorded Apr 25, 2025
From: SANDISK TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 071050/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 31, 2024
From: SANDISK TECHNOLOGIES LLC
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 069796/0423 →
CHANGE OF NAME Recorded May 25, 2016
From: SANDISK TECHNOLOGIES INC
To: SANDISK TECHNOLOGIES LLC
Reel/Frame 038809/0472 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 26, 2011
From: SANDISK CORPORATION
To: SANDISK TECHNOLOGIES INC.
Reel/Frame 026348/0806 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 18, 2007
From: HOLTZMAN, MICHAEL; BARZILAI, RON; JOGAND-COULOMB, FABRICE
To: SANDISK CORPORATION
Reel/Frame 018773/0392 →
Continuity (2)
Provisional Application 60819507 · Jul 7, 2006
Related Publication 20080010455A1 · Jan 10, 2008