IP Library Granted Patent US 8,918,893
Granted Patent B2
US 8,918,893 · App. 13/662,678 · Granted Dec 23, 2014

Managing a fault condition by a security module

Inventor: Ted A. Hadley (Sunnyvale, CA)
Assignee: Hewlett-Packard Development Company, L.P.
G06F21/60G06F21/602
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,918,893
App. No.
13/662,678
Granted
Dec 23, 2014
Kind
B2
Abstract

A microcontroller is awakened from a lower power state in response to a trigger indication indicative of a fault condition. After the awakening, the microcontroller performs a security action with respect to secret information in the security module in response to the fault condition.

Claims (54)

1. A method for managing a fault condition, comprising:

in response to detecting the fault condition, activating, by a monitoring circuit of a security module, a trigger indication;

awakening a microcontroller of the security module from a lower power state in response to the trigger indication, wherein the microcontroller has a storage to store secret information; and

performing, by the microcontroller after awakening from the lower power state, a security action with respect to the secret information in response to the fault condition, wherein performing the security action comprises:

determining whether the fault condition is a first type of fault condition or a second type of fault condition; and

in response to determining that the fault condition is the second type of fault condition, locking access to the secret information to prevent access to the secret information that remains stored in the storage of the microcontroller.

2. The method of claim 1 , further comprising:

transitioning the microcontroller to the lower power state in response to detecting that the security module is being powered by a battery but not an external power source.

3. The method of claim 1 , further comprising:

after performing the security action, transitioning the microcontroller to the lower power state.

4. The method of claim 1 , wherein performing the security action further comprises, in response to determining that the fault condition is the first type of fault condition, erasing the secret information from the storage of the microcontroller.

5. The method of claim 4 , wherein the first type of fault condition is a fatal fault condition.

6. The method of claim 5 , wherein the second type of fault condition is a non-fatal fault condition.

7. A method for managing a fault condition, comprising:

in response to detecting the fault condition, activating, by a monitoring circuit of a security module, a trigger indication;

awakening a microcontroller of the security module from a lower power state in response to the trigger indication, wherein the microcontroller has a storage to store secret information;

performing, by the microcontroller after awakening from the lower power state, a security action with respect to the secret information in response to the fault condition;

transitioning the microcontroller to the lower power state in response to detecting that the security module is being powered by a battery but not an external power source;

preventing input/output access of information in the microcontroller by a processor of the security module in response to detecting that the security module is powered by the battery but not the external power source; and

allowing input/output access of information in the microcontroller by the processor in response to detecting that the security module is powered by the external power source.

8. The method of claim 1 , further comprising:

repeatedly moving data values of the secret information to different locations in the storage to avoid imprinting of data in the storage.

9. The method of claim 8 , further comprising:

issuing, by a timer, timer trigger indications on a periodic basis,

wherein repeatedly moving the data values of the secret information is in response to the timer trigger indications.

10. A security module for managing a fault condition, comprising:

a monitoring circuit to monitor for the fault condition; and

a microcontroller having an active state and a lower power state, and a storage to store secret information, the microcontroller to:

awaken from the lower power state to the active state in response to a trigger indication from the monitoring circuit that indicates presence of the fault condition; and

perform a security action with respect to the secret information to handle the fault condition, wherein to perform the security action, the microcontroller is to:

determine whether the fault condition is a first type of fault condition or a second type of fault condition;

in response to determining that the fault condition is the first type of fault condition, erase the secret information from the storage of the microcontroller; and

in response to determining that the fault condition is the second type of fault condition, lock access to the secret information to prevent access to the secret information that remains stored in the storage of the microcontroller.

11. The security module of claim 10 , wherein the fault condition is at least one selected from among a condition indicative of tampering with the security module, a condition indicative of physical penetration through a cover of the security module, a temperature out-of-range condition, and a battery out-of-range condition.

12. The security module of claim 10 , further comprising a processor to request access of the secret information and to perform a security function using the secret information.

13. The security module of claim 12 , wherein the secret information is a cryptographic key, and the security function includes a cryptographic computation.

14. The security module of claim 10 , wherein the microcontroller is to perform a non-imprinting action to avoid data imprinting at the storage.

15. The security module of claim 14 , wherein the microcontroller is to repeatedly perform the non-imprinting action in response to trigger indications activated by corresponding expirations of a timer.

16. The security module of claim 10 , further comprising a battery, wherein the security module is powered by the battery when the security module is not powered by an external power source, and wherein the microcontroller is to:

transition from the active state to the lower power state in response to the microcontroller being idle and the security module being powered by the battery but not the external power source.

17. The security module of claim 10 , further comprising:

a battery; and

a processor separate from the microcontroller, wherein the microcontroller is to further:

prevent input/output access of information in the microcontroller by the processor in response to detecting that the security module is powered by the battery but not by an external power source that is external of the security module; and

allow input/output access of information in the microcontroller by the processor in response to detecting that the security module is powered by the external power source.

18. An article comprising at least one non-transitory machine-readable storage medium storing instructions for managing a fault condition, the instructions upon execution causing a microcontroller to:

awaken the microcontroller from a lower power state based on a trigger indication indicative of the fault condition of a security module; and

after the awakening, perform a security action with respect to secret information stored in a storage in the security module in response to the fault condition, wherein to perform the security action the instructions upon execution cause the microcontroller to:

determine whether the fault condition is a first type of fault condition or a second type of fault condition;

in response to determining that the fault condition is a first type of fault condition, erase the secret information from the storage; and

in response to determining that the fault condition is the second type of fault condition, block access to the secret information to prevent access to the secret information that remains stored in the storage.

19. The article of claim 18 , wherein the security module includes a battery and a processor separate from the microcontroller, wherein the instructions upon execution cause the microcontroller to further:

prevent input/output access of information in the microcontroller by the processor in response to detecting that the security module is powered by the battery but not an external power source that is external of the security module; and

allow input/output access of information in the microcontroller by the processor in response to detecting that the security module is powered by the external power source.

Assignments (13)
CORRECTIVE ASSIGNMENT TO CORRECT THE COMPANY NAME OF RECEIVING PARTY PREVIOUSLY RECORDED ON REEL 72653 FRAME 454. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 9, 2026
From: ENTIT SOFTWARE LLC
To: UTIMACO INC.
Reel/Frame 074912/0610 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 23, 2025
From: ENTIT SOFTWARE LLC
To: UTIMACO, INC.
Reel/Frame 072653/0454 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0577 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC)
Reel/Frame 063560/0001 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
RELEASE OF SECURITY INTEREST Recorded Aug 22, 2019
From: NIBC BANK N.V., AS SECURITY AGENT
To: UTIMACO INC.
Reel/Frame 050135/0404 →
SECURITY INTEREST Recorded Feb 5, 2019
From: UTIMACO INC.
To: NIBC BANK N.V.
Reel/Frame 048240/0281 →
RELEASE OF SECURITY INTEREST Recorded Oct 24, 2018
From: JPMORGAN CHASE BANK, N.A. (AS SUCCESSOR TO BANK OF AMERICA, N.A.)
To: ENTIT SOFTWARE LLC
Reel/Frame 047297/0843 →
RELEASE OF SECURITY INTEREST Recorded Oct 24, 2018
From: JPMORGAN CHASE BANK, N.A. (AS SUCCESSOR TO BANK OF AMERICA, N.A.)
To: ENTIT SOFTWARE LLC
Reel/Frame 047299/0055 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ENTIT SOFTWARE LLC; ARCSIGHT, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0577 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2017
From: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
To: ENTIT SOFTWARE LLC
Reel/Frame 042746/0130 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 9, 2015
From: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 037079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 2, 2012
From: HADLEY, TED A.
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 029231/0860 →
Continuity (1)
Related Publication 20140123322A1 · May 1, 2014