IP Library Granted Patent US 9,152,797
Granted Patent B2
US 9,152,797 · App. 13/718,083 · Granted Oct 6, 2015

Device and method for secure memory access

Inventors: Paul Bilke (Frisco, TX); Steven Bradley (Knutsford, GB); Andrew Crichton (Knutsford, GB); George French (Northampton, GB); Arthur Leung (London, GB); Michael Naggar (Frisco, TX); Ashutosh Sureka (Frisco, TX)
Assignee: BARCLAYS BANK PLC
G06F21/60G06F21/34G06F21/575G06F21/6209H04L63/0853G06F2221/2143
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,152,797
App. No.
13/718,083
Granted
Oct 6, 2015
Kind
B2
Abstract

In a secure computing environment, a method, system and device are provided for loading stored encryption key data from a protected non-volatile memory of a portable device. A boot loader program is initiated after the portable device is powered on, encryption key data is loaded from the protected non-volatile memory of the portable device, and access to the protected non-volatile memory is disabled after a predetermined time after the portable device is powered on. In this way, the encryption key data is loaded from the protected non-volatile memory of a portable device before the boot operating system is loaded.

Claims (16)

1. A computer-implemented method of loading stored

encryption key data from a protected non-volatile memory of an electronic device, comprising the steps of:

executing boot loader code after the electronic device is powered on, then loading the stored encryption key data from the protected non-volatile memory of the electronic device;

after said loading, determining that a pre-defined number of clock cycles has elapsed from the time the electronic device is powered on;

disabling access to the stored encryption key data and the protected non-volatile memory of the electronic device after it is determined that the pre-defined number of clock cycles has elapsed; and

processing routine boot loading operations after the encryption key data is loaded to working memory, the routine boot loading operations including initiating at least one external communication interface of the electronic device, whereby the at least one external communication interface cannot be operated prior to the loading of the encryption key, the disabling of access to the stored encryption key, and the disabling of the protected non-volatile memory.

2. The method of claim 1 , wherein the stored encryption key data is loaded from the protected non-volatile memory of a protected storage chip the electronic device.

3. The method of claim 2 , wherein the stored encryption key data is loaded to a volatile memory on the electronic device.

4. The method of claim 3 , wherein the volatile memory is provided on a processor of the electronic device.

5. The method of claim 1 , wherein the at least one external communication interface comprises one or more of a Universal Serial Bus (USB) interface, a modem and a Near Field Communication (NFC) interface.

6. The method of claim 1 , wherein the electronic device is powered through a USB interface when connected to a host computer.

7. The method of claim 2 , wherein the protected storage chip further comprises a microcontroller for disabling access to the protected non-volatile memory.

8. The method of claim 7 , wherein the microcontroller controls access to the protected non-volatile memory by enabling and disabling access to memory addresses of the protected non-volatile memory.

9. The method of claim 1 , further comprising loading and running application program code stored in the electronic device when the electronic device is plugged into a host computer.

10. The method of claim 9 , wherein the application program code uses the stored encryption key data to encrypt data for communication over the at least one external communication interface.

11. The method of claim 1 , wherein stored encryption key data in the protected non-volatile memory are wrapped using device specific keys, and unwrapped after loading from the protected non-volatile memory.

Assignments (5)
CHANGE OF NAME Recorded Nov 22, 2019
From: BARCLAYS SERVICES LIMITED
To: BARCLAYS EXECUTION SERVICES LIMITED
Reel/Frame 051085/0309 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 2, 2018
From: BARCLAYS BANK PLC
To: BARCLAYS SERVICES LIMITED
Reel/Frame 047400/0169 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 8, 2018
From: BILKE, PAUL
To: BARCLAYS BANK PLC
Reel/Frame 046328/0493 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 3, 2015
From: CRICHTON, ANDREW
To: BARCLAYS BANK PLC
Reel/Frame 035779/0350 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 9, 2014
From: BRADLEY, STEVEN; FRENCH, GEORGE; LEUNG, ARTHUR; NAGGAR, MICHAEL; SUREKA, ASHUTOSH
To: BARCLAYS BANK PLC
Reel/Frame 033269/0451 →
Priority Claims (1)
GB 1219514.5 · Oct 30, 2012 · national
Continuity (1)
Related Publication 20140122901A1 · May 1, 2014