IP Library Patent Application 14505418
Patent Application
App. No. 14/505,418

PROVISIONING OF SECURITY CREDENTIALS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
14/505,418
Abstract

A security component for authenticating a device, within which it is incorporated, with another device, the security component comprising a root identity generator configured to generate a root identity comprising a public root identity and a private root identity for the security component and an output configured to output the public root identity for sharing with the other device and to not output the private root identity.

Claims (25)

1 . A security component for authenticating a device, within which it is incorporated, with another device, the security component comprising:

a root identity generator configured to generate a root identity comprising a public root identity and a private root identity; and

an output configured to output the public root identity for sharing with the other device and to not output the private root identity.

2 . The security component as claimed in claim 1 , the root identity generator being configured to generate, as part of the private root identity, a private key of an asymmetric key set.

3 . The security component as claimed in claim 1 , the root identity generator being configured to generate, as part of the public root identity, one or more of a unique identifier for the security component, a public key of an asymmetric key set, and a symmetric key.

4 . The security component as claimed in claim 1 , the root identity generator being configured to generate multiple unique root identities for the security component.

5 . The security component as claimed in claim 1 , the root identity generator being capable of repeatably generating the root identity.

6 . The security component as claimed in claim 1 , the security component being configured not to store the root identity.

7 . The security component as claimed in claim 1 , the root identity generator being configured to, when the security component requires the root identity, regenerate the root identity.

8 . The security component as claimed in claim 1 , the security component comprising a memory configured to store the root identity and being configured to, when it requires the root identity, retrieve it from memory.

9 . The security component as claimed in claim 1 , comprising an enrolment indicator, the security component being configured to, when the public root identity is shared with the other device, set the enrolment indicator.

10 . The security component as claimed in claim 9 , the security component being configured not to share the public root identity if the enrolment indicator is set.

11 . The security component as claimed in claim 9 , the root identity generator being configured to, each time that the security component is required to generate a root identity when the enrolment indicator is not set, generate a new root identity.

12 . The security component as claimed in claim 9 , the root identity generator being configured to, each time that the security component is required to generate a root identity when the enrolment indicator is set, regenerate a previously generated root identity.

13 . The security component as claimed in claim 9 , the root identity generator being configured to, each time that the security component is required to generate a root identity when the enrolment indicator is set, regenerate the root identity that comprises the public root identity shared with the other device.

14 . The security component as claimed in claim 1 , the root identity generator being configured to generate a root identity during a self-test of the security component.

15 . The security component as claimed in claim 1 , the security component being configured not to share the private root identity with parts of the device that are outside of the security component.

16 . The security component as claimed in claim 1 , comprising an encryption unit configured to encrypt and/or decrypt communications with the other device using the private root identity.

17 . The security component as claimed in claim 16 , the encryption unit being configured to encrypt any data that it shares with the other device with a public key of the other device.

18 . The security component as claimed in claim 1 , the output being configured to output the public root identity for sharing with a certificate authority.

19 . The security component as claimed in claim 1 , in which the root identity generator comprises an entropy source.

20 . A method for provisioning a device with security credentials to enable it to authorise itself with another device, comprising:

incorporating a security component in the device;

generating, by the security component, a root identity comprising a public root identity and a private root identity; and

the security component outputting the public root identity for sharing with the other device and not outputting the private root identity.

Assignments (2)
CHANGE OF NAME Recorded Sep 22, 2015
From: CAMBRIDGE SILICON RADIO LIMITED
To: QUALCOMM TECHNOLOGIES INTERNATIONAL, LTD.
Reel/Frame 036663/0211 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 6, 2014
From: SCAGNOL, MAURO; GRAUBE, NICOLAS GUY ALBERT; BOSCOVIC, DRAGAN
To: CAMBRIDGE SILICON RADIO LIMITED
Reel/Frame 033892/0819 →