IP Library Patent Application 13842110
Patent Application
App. No. 13/842,110

METHOD AND APPARATUS FOR EMBEDDING SECRET INFORMATION IN DIGITAL CERTIFICATES

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
13/842,110
Abstract

A method and system is provided for embedding cryptographically modified versions of secret in digital certificates for use in authenticating devices and in providing services subject to conditional access conditions.

Claims (55)

1 . A method of enabling provision of a service to a first entity, comprising the steps of:

receiving a service request in a second entity from the first entity, the service request comprising a leaf digital certificate generated and digitally signed by a certification entity and provided to the first entity, the leaf digital certificate having a unique identifier of the first entity and a two-way cryptographic function of a secret generated according to a provision key unknown to the first entity and the digital certificate digitally signed by a private key of the certification entity according to an asymmetric crypto algorithm;

recovering the secret in the second entity from the leaf digital certificate; and

enabling provision of the service to the first entity according to the recovered secret.

2 . The method of claim 1 , wherein the step of recovering the secret comprises:

recovering the two-way cryptographic function of the secret from the digitally signed digital certificate; and

inverting the two-way cryptographic function to recover the secret.

3 . The method of claim 2 , wherein the step of inverting the two way cryptographic function comprises:

inverting the two-way cryptographic function according to the provision key.

4 . The method of claim 3 , wherein the two-way cryptographic function is a symmetric function and the provision key is a symmetric key known to the certification entity and the service enabling entity.

5 . The method of claim 3 , wherein the two-way cryptographic function is an asymmetric function and the provision key is an encryption key and the two-way cryptographic function is inverted according to a decryption key corresponding to the encryption key.

6 . The method of claim 2 , wherein the step of recovering the two-way cryptographic function of the secret from the digital certificate comprises:

attempting verifying the digitally signed leaf digital certificate; and

recovering the two way cryptographic function of the secret from the leaf digital certificate only if the leaf digital certificate is verified.

7 . The method of claim 6 , wherein the leaf digital certificate is verified according to a public key of the certification entity.

8 . The method of claim 6 , wherein:

the first entity is a member of a class of devices, and the certification entity comprises a sub-certification entity providing the leaf digital certificate to the first entity and other leaf digital certificates to each of the other devices in the class of devices;

each leaf digital certificate comprises a unique identifier of each associated device and an associated secret unique to the associated device;

each leaf digital certificate is digitally signed according to a trusted sub-certification entity digital certificate provided by the sub-certification entity; and

the method further comprises:

determining if the sub-certification entity certificate or any digital certificate in a chain up to a root of trust has been revoked; and

verifying the leaf digital certificate only if the trusted digital sub-certification entity digital certificate and any digital certificate in the chain up to the root of trust has not been revoked.

9 . The method of claim 8 , wherein the step of determining if the trusted sub-certificate has been revoked comprises:

receiving, from the second entity, a list identifying revoked sub-certification entity certificates; and

determining that the trusted sub-certification entity certificate has been revoked if the list identifies the trusted sub-certification entity certificate.

10 . The method of claim 1 , wherein the certification entity further provides the secret to the first entity and the provision of the service is enabled at least in part on a match between the secret provided to the first entity and the secret recovered by the second entity.

11 . The method of claim 10 , wherein the secret is provided to the first entity in a same message as the digital certificate.

12 . The method of claim 1 , wherein the provision of the service is enabled only if the digital certificate and all digital certificates in the chain from the digital certificate up to a root of trust are not a member of a set of revoked digital certificates.

13 . The method of claim 12 , further comprising the steps of:

receiving, in the second entity, a list identifying revoked digital certificates; and

determining if the digital certificate is among the identified the revoked digital certificates;

enabling the provision of the service only if the digital certificate and all digital certificates in the chain from the digital certificate up to a root of trust are not among the identified revoked digital certificates.

14 . An apparatus for enabling provision of a service to a first entity the apparatus disposed in a second entity and comprising:

a communications module, for transceiving information, wherein the information comprises:

a service request from the first entity, the service request comprising a leaf digital certificate generated and digitally signed by a certification entity and provided to the first entity, the leaf digital certificate having a unique identifier of the first entity and a two-way cryptographic function of a secret generated according to a provision key unknown to the first entity and the digital certificate digitally signed by a private key of the certification entity according to an asymmetric crypto algorithm;

a processor, for executing instructions stored in a memory communicatively coupled to the processor, the instructions including instructions for:

recovering the secret in the second entity from the leaf digital certificate; and

enabling provision of the service to the first entity according to the recovered secret.

15 . The apparatus of claim 14 , wherein the instructions for recovering the secret comprise instructions for:

recovering the two-way cryptographic function of the secret from the digitally signed digital certificate; and

inverting the two-way cryptographic function to recover the secret.

16 . The apparatus of claim 15 , wherein:

the instructions for inverting the two way cryptographic function comprise instructions for inverting the two-way cryptographic function according to the provision key;

17 . The apparatus of claim 16 , wherein the two-way cryptographic function is a symmetric function and the provision key is a symmetric key known to the certification entity and the service enabling entity.

18 . The apparatus of claim 16 , wherein the two-way cryptographic function is an asymmetric function and the provision key is an encryption key and the two-way cryptographic function is inverted according to a decryption key corresponding to the encryption key.

19 . The apparatus of claim 15 , wherein the instructions recovering the two-way cryptographic function of the secret from the digital certificate comprise instructions for:

attempting verifying the digitally signed leaf digital certificate; and

recovering the two way cryptographic function of the secret from the leaf digital certificate only if the leaf digital certificate is verified.

20 . The apparatus of claim 19 , wherein:

the first entity is a member of a class of devices, and the certification entity comprises a sub-certification entity providing the leaf digital certificate to the first entity and other leaf digital certificates to each of the other devices in the class of devices;

each leaf digital certificate comprises a unique identifier of each associated device and an associated secret unique to the associated device;

each leaf digital certificate is digitally signed according to a trusted sub-certification entity digital certificate provided by the sub-certification entity; and

the instructions further comprise instructions for:

determining if the sub-certification entity certificate or any digital certificate in a chain up to a root of trust has been revoked; and

verifying the leaf digital certificate only if the trusted digital sub-certification entity digital certificate and any digital certificate in the chain up to the root of trust has not been revoked.

Assignments (4)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Apr 8, 2019
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: ARRIS GROUP, INC.; ARRIS ENTERPRISES, INC.; ARRIS SOLUTIONS, INC.; ARRIS KOREA, INC.; ARRIS HOLDINGS CORP. OF ILLINOIS, INC.; BIG BAND NETWORKS, INC.; TEXSCAN CORPORATION; POWER GUARD, INC.; 4HOME, INC.; ACADIA AIC, INC.; AEROCAST, INC.; BROADBUS TECHNOLOGIES, INC.; GENERAL INSTRUMENT CORPORATION; GENERAL INSTRUMENT AUTHORIZATION SERVICES, INC.; GENERAL INSTRUMENT INTERNATIONAL HOLDINGS, INC.; IMEDIA CORPORATION; JERROLD DC RADIO, INC.; LEAPSTONE SYSTEMS, INC.; MODULUS VIDEO, INC.; MOTOROLA WIRELINE NETWORKS, INC.; NETOPIA, INC.; NEXTLEVEL SYSTEMS (PUERTO RICO), INC.; QUANTUM BRIDGE COMMUNICATIONS, INC.; SETJAM, INC.; SUNUP DESIGN SYSTEMS, INC.; UCENTRIC SYSTEMS, INC.; GIC INTERNATIONAL HOLDCO LLC; GIC INTERNATIONAL CAPITAL LLC; CCE SOFTWARE LLC; THE GI REALTY TRUST 1996
Reel/Frame 048825/0294 →
MERGER AND CHANGE OF NAME Recorded Mar 10, 2015
From: GENERAL INSTRUMENT CORPORATION; GENERAL INSTRUMENT CORPORATION
To: ARRIS TECHNOLOGY, INC.
Reel/Frame 035176/0620 →
SECURITY AGREEMENT Recorded May 28, 2013
From: ARRIS GROUP, INC.; ARRIS ENTERPRISES, INC.; ARRIS SOLUTIONS, INC.; ARRIS KOREA, INC.; ARRIS HOLDINGS CORP. OF ILLINOIS; BIGBAND NETWORKS, INC.; TEXSCAN CORPORATION; POWER GUARD, INC.; 4HOME, INC.; ACADIA AIC, INC.; AEROCAST, INC.; BROADBUS TECHNOLOGIES, INC.; GENERAL INSTRUMENT CORPORATION; GENERAL INSTRUMENT AUTHORIZATION SERVICES, INC.; GENERAL INSTRUMENT INTERNATIONAL HOLDINGS, INC.; IMEDIA CORPORATION; JERROLD DC RADIO, INC.; LEAPSTONE SYSTEMS, INC.; MODULUS VIDEO, INC.; MOTOROLA WIRELINE NETWORKS, INC.; NETOPIA, INC.; NEXTLEVEL SYSTEMS (PUERTO RICO), INC.; QUANTUM BRIDGE COMMUNICATIONS, INC.; SETJAM, INC.; SUNUP DESIGN SYSTEMS, INC.; UCENTRIC SYSTEMS, INC.; GIC INTERNATIONAL HOLDCO LLC; GIC INTERNATIONAL CAPITAL LLC; CCE SOFTWARE LLC; THE GI REALTY TRUST 1996
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 030498/0023 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 1, 2013
From: KEUNG CHAN, TAT; MEDVINSKY, ALEXANDER; SPRUNK, ERIC
To: GENERAL INSTRUMENT CORPORATION
Reel/Frame 030124/0490 →