IP Library Patent Application 12885580
Patent Application
App. No. 12/885,580

Method of Encrypted Communication with Restricted Rate of Stored Encryption Key Retrievals

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
12/885,580
Abstract

A method of encrypted communication between entities in a manner that frustrates side channel attacks attempting to determine an encryption key. The method involves providing a device with an encryption key stored in memory, providing an external entity with identity data for transmission to the device, applying a one way function to the encryption key and the identity data to generate a variant key, authenticating communications between the device and the external entity with the variant key and limiting the number of times the encryption key is retrieved from the first memory in a given period of time.

Claims (25)

1 . A method of encrypted communication between entities, the method comprising the steps of:

providing a device with an encryption key stored in memory;

providing an external entity with identity data for transmission to the device;

applying a one way function to the encryption key and the identity data to generate a variant key;

authenticating communications between the device and the external entity with the variant key; and,

limiting the number of times the encryption key is retrieved from the first memory in a given period of time.

2 . A method according to claim 1 wherein the encryption key is a base key and the first memory is a non-volatile memory.

3 . A method according to claim 2 wherein the identity data is a unique identifier that identifies the external entity to the exclusion of all other external entities and the step of authenticating communications comprises generating a first variant key based on the one-way function, the base key and information from the external entity, the first variant key being stored for generating a digital signature to authenticate communications between the device and the external entity.

4 . A method according to claim 3 further comprising providing a second memory in the device for a plurality of variant keys generated for digital signatures to authenticate communication with a plurality of external entities respectively.

5 . A method according to claim 4 wherein the second memory is a rewritable memory for storing a predetermined number of the variant keys, the predetermined number of variant keys being less than the threshold number of times that the base key can be retrieved from the non-volatile memory.

6 . A method according to claim 5 wherein the step of generating each of the variant keys using the one-way function includes an adding several separate terms, and the device is configured to use random arrangements of the terms.

7 . A method according to claim 5 wherein the step of generating each of the variant keys using the one-way function includes adding several separate terms, and the device is configured to provide an arrangement of the terms that differs from other like devices.

8 . A method according to claim 5 wherein the one-way function used to generate the variant keys includes adding several separate terms together, the device being configured to add a masking number as an additional term to the one way function, and subsequently subtract the masking number from the sum of the calculation.

9 . A method according to claim 8 wherein the masking number is randomly generated for the generation of each of the variant keys.

10 . A method according to claim 3 wherein the base key can be retrieved only for generating a variant key.

11 . A method according to claim 1 further comprising the step of storing resource data in the device and providing the external entity with certain permissions in relation to operations on the resource data.

12 . A method according to claim 11 wherein the resource data represents a physical property.

13 . A method according to claim 12 wherein the physical property is a remaining amount of a physical resource.

14 . A method according to claim 13 wherein one of the permissions is a read operation in which the resource data is read by the external entity.

15 . A method according to claim 14 wherein the operations include a write operation, in which the resource data is modified by the entity making the request.

16 . A method according to claim 15 wherein the write operation is decrementing the resource data as an indication of consumption of the physical resource.

17 . A method according to claim 1 wherein the one way function is a hash function.

18 . A method according to claim 17 wherein the hash function is SHA1.

19 . A method according to claim 16 further comprising the step of incorporating the device into an ink cartridge.

20 . A method according to claim 19 wherein the external entity is a print engine controller (PEC) in an inkjet printer configured for use with the ink cartridge.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 8, 2013
From: SILVERBROOK RESEARCH PTY. LIMITED
To: ZAMTEC LIMITED
Reel/Frame 030169/0193 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 4, 2013
From: SILVERBROOK RESEARCH PTY. LIMITED
To: ZAMTEC LIMITED
Reel/Frame 029918/0791 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 20, 2010
From: STARR, MATTHEW RAYMOND; PRICE-WHITE, STEPHEN CAMERON
To: SILVERBROOK RESEARCH PTY LTD
Reel/Frame 025009/0981 →