IP Library Granted Patent US 8,499,169
Granted Patent B2
US 8,499,169 · App. 12/174,709 · Granted Jul 30, 2013

Client authentication device and methods thereof

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,499,169
App. No.
12/174,709
Granted
Jul 30, 2013
Kind
B2
Abstract

A method of authenticating a data processing device includes receiving a request to authenticate the data processing device. In response, an authentication key is accessed an authenticated at an authentication module. The authentication key is stored at a storage module that is located within the same integrated circuit package as the authentication module, so that the authentication key can be communicated to the module without exposing the key to unauthorized probing. The integrated circuit package also includes a tamper detection module to determine whether a memory of the data processing device has been accessed. In response to determining the memory has been accessed, the tamper detection module instructs the authentication module to not authenticate the data processing device.

Claims (41)

1. A method, comprising:

receiving a request to authenticate a client device via a network;

in response to receiving the request:

retrieving an authentication key from a storage module at the client device, the storage module located at a first integrated circuit package;

determining at a tamper detection module whether a memory of the client device has been accessed;

in response to determining the memory of the client device has not been accessed,

using the authentication key at an authentication module to determine an authentication result for the client device, the authentication module located at the first integrated circuit package;

communicating the authentication result via the network; and

in response to determining a portion of the memory of the client device has been accessed, fixing a data bus of the memory at a predetermined voltage.

2. The method of claim 1 , wherein receiving the request to authenticate the client device comprises receiving the request at a processor of the client device, the processor located at a second integrated circuit package different from the first.

3. The method of claim 1 , wherein the first integrated circuit package includes a plurality of external connectors, and wherein the storage module is inaccessible via the plurality of external connectors after storage of the authentication key.

4. The method of claim 1 , further comprising:

wherein authenticating the authentication key comprises setting the authentication result to indicate a denial of authentication in response to determining the memory has been accessed.

5. A method, comprising:

receiving a request to authenticate a client device via a network;

in response to receiving the request:

retrieving an authentication key from a storage module at the client device via an interconnect that is protected from external probing;

using the authentication key to determine an authentication result; and

communicating the authentication result via the network;

receiving configuration information from a memory;

configuring a processor of the client device based on the configuration information;

fixing a write-enable input of the memory at a defined value so that data cannot be stored at the memory; and

monitoring a voltage of the write-enable input of the memory to detect tampering of the memory.

6. The method of claim 5 , wherein receiving the authentication key to authenticate the client device comprises receiving the request at the processor of the client device, the processor coupled to the storage module via the interconnect.

7. A device, comprising:

a network interface module configured to receive an authentication request from a network;

a processor;

a memory coupled to the processor via a bus, the memory comprising a write enable input configured to place the memory in a writeable state based on a signal at the write enable input; and

a first integrated circuit package, comprising:

a storage module configured to store an authentication key;

an authentication module configured to access the authentication key and to determine an authentication result based on the authentication key in response to the authentication request; and

a tamper detection module coupled to the authentication module, the tamper detection module configured to:

detect tampering of the memory,

provide control information to the authentication module indicating whether the memory has been tampered, and

fixing the bus at a predetermined voltage in response to determining the memory has been tampered.

8. The device of claim 7 , wherein the processor comprises a second integrated circuit package different from the first.

9. The device of claim 7 , wherein the first integrated circuit package includes a plurality of external connectors, and wherein the storage module is inaccessible via the plurality of external connectors.

10. The device of claim 7 , wherein the authentication module is configured to set the authentication result to indicate a denial of authentication in response to determining the control information indicates the memory has been tampered.

11. The device of claim 7 , wherein the tamper detection module is configured to detect tampering of the memory by monitoring a voltage of the write enable input of the memory.

12. The device of claim 7 , wherein the tamper detection module is configured to detect tampering of the memory by comparing data communicated via the bus with expected values.

13. The device of claim 12 , wherein the tamper detection module is configured to compare data communicated via the bus by comparing a hash value based on the data to an expected hash value.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 19, 2012
From: QUALCOMM ATHEROS, INC.
To: QUALCOMM INCORPORATED
Reel/Frame 029503/0936 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2011
From: BIGFOOT NETWORKS, INC.
To: QUALCOMM ATHEROS, INC.
Reel/Frame 026990/0280 →