IP Library Granted Patent US 8,438,394
Granted Patent B2
US 8,438,394 · App. 13/179,387 · Granted May 7, 2013

Device-bound certificate authentication

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,438,394
App. No.
13/179,387
Granted
May 7, 2013
Kind
B2
Abstract

A device-bound certificate authority binds a certificate to one or more devices by including digital fingerprints of the devices in the certificate. A device only uses a device-bound certificate if the digital fingerprint of the device is included in the certificate and is verified. Thus, a certificate is only usable by one or more devices to which the certificate is explicitly bound. Such device-bound certificates can be used for various purposes served by certificates generally such as device driver authentication and authorization of access to secure content, for example.

Claims (20)

1. A method for binding a digital certificate that can be stored on a computer-readable medium to multiple devices, the method comprising:

receiving at a server computer a request from a remote device through a computer network wherein the request identifies the certificate and identifies each of devices by a device identifier created by the server computer, each device identifier being uniquely associated with a digital fingerprint of one of the devices;

retrieving the certificate;

for each of the devices:

retrieving a digital fingerprint of the device; and

including the digital fingerprint in the certificate; and

sending the certificate with the included digital fingerprints to the remote device through the computer network,

wherein the server computer in response to the request serves a device driver cryptographically signed with the certificate so that any of the devices can install the device only upon a condition in which one of the digital fingerprints corresponds to the installing device.

2. The method of claim 1 wherein the remote device determines whether any of the digital fingerprints that are included in the certificate corresponds to the remote device and, upon a condition in which at least one of the digital fingerprint fingerprints corresponds to the remote device, accepts the certificate as legitimate.

3. The method of claim 2 wherein the remote device determines whether any of the digital fingerprints that are included in the certificate corresponds to a requesting device from which the remote device has received a request for access to secure content of the remote device and, upon a condition in which at least one of the digital fingerprints corresponds to the requesting device and the remote device is preconfigured to recognize the requesting device as authorized to access the secure content, grants the request.

4. The method of claim 1 wherein the remote device determines whether any of the digital fingerprints that are included in the certificate corresponds to a requesting device from which the remote device has received a request for access to secure content of the remote device and, upon a condition in which at least one of the digital fingerprints corresponds to the requesting device and the remote device is preconfigured to recognize the requesting device as authorized to access the secure content, grants the request.

5. The method of claim 1 wherein the remote device determines whether any of the digital fingerprints that is are included in the certificate corresponds to a requesting device from which the remote device has received a request for access to secure content of the remote device and, upon a condition in which at least one of the digital fingerprint fingerprints corresponds to the requesting device and the remote device is preconfigured to recognize the requesting device as authorized to access the secure content, grants the request.

6. A non-transitory computer readable medium useful in association with a computer which includes one or more processors and a memory, the computer readable medium including computer instructions which are configured to cause the computer, by execution of the computer instructions in the one or more processors from the memory, to bind a digital certificate that can be stored on a computer readable medium to multiple devices by at least:

receiving at the computer a request from a remote device through a computer network wherein the request identifies the certificate and identifies each of the devices by a device identifier created by the server computer, each device identifier being uniquely associated with a digital fingerprint of one of the devices;

retrieving the certificate;

for each of the one or more devices:

retrieving a digital fingerprint of the device; and

including the digital fingerprint in the certificate; and

sending the certificate with the one or more included digital fingerprints to the remote device through the computer network,

wherein the server computer in response to the request serves a device driver cryptographically signed with the certificate so that any of the devices can install the device only upon a condition in which one of the digital fingerprints corresponds to the installing device.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING AND RECEIVING REVERSED PREVIOUSLY RECORDED AT REEL: 042123 FRAME: 0864. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded May 31, 2017
From: FORTRESS CREDIT CO LLC
To: UNILOC LUXEMBOURG S.A.
Reel/Frame 042644/0085 →
RELEASE OF SECURITY INTEREST Recorded Apr 24, 2017
From: UNILOC LUXEMBOURG, S.A.
To: FORTRESS CREDIT CO LLC
Reel/Frame 042123/0864 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 24, 2017
From: UNILOC LUXEMBOURG S.A.
To: NETAUTHORITY, INC.
Reel/Frame 041470/0468 →
CHANGE OF NAME Recorded Dec 30, 2016
From: CRYPTOSOFT LIMITED
To: DEVICE AUTHORITY LTD
Reel/Frame 040811/0355 →
MERGER Recorded Dec 30, 2016
From: DEVICEAUTHORITY, INC.
To: CRYPTOSOFT LIMITED
Reel/Frame 040811/0001 →
SECURITY INTEREST Recorded Jan 9, 2015
From: UNILOC LUXEMBOURG, S.A.; UNILOC CORPORATION PTY LIMITED; UNILOC USA, INC.
To: FORTRESS CREDIT CO LLC
Reel/Frame 034747/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 2, 2015
From: UNILOC LUXEMBOURG S.A.
To: DEVICEAUTHORITY, INC.
Reel/Frame 034719/0462 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 11, 2014
From: HARJANTO, DONO
To: UNILOC LUXEMBOURG S.A.
Reel/Frame 032194/0660 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 27, 2013
From: NETAUTHORITY, INC.
To: UNILOC LUXEMBOURG S.A.
Reel/Frame 031688/0633 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 2, 2013
From: ETCHEGOYEN, CRAIG S.
To: UNILOC LUXEMBOURG S.A.
Reel/Frame 030136/0512 →