IP Library Granted Patent US 10,019,556
Granted Patent B2
US 10,019,556 · App. 14/757,398 · Granted Jul 10, 2018

EPID attestation using RFID

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,019,556
App. No.
14/757,398
Granted
Jul 10, 2018
Kind
B2
Abstract

Technologies for verification include storage with private keys, wherein each private key is associated with a group affiliation. The storage also includes characteristic information about an apparatus. The technologies also include a wireless interface configured to receive a request from a reader for verification of membership of the apparatus within a group affiliation. The technologies further include a controller with programmable logic for configuring the controller to determine whether to verify membership of the apparatus within a given group affiliation. The controller is also configured to verify membership of the apparatus within the given group affiliation by signing data with a private key associated with the given group affiliation. The signed data is sent to the reader. Membership within the given group affiliation conveys a subset of the characteristic information.

Claims (58)

1. An apparatus, comprising:

a storage including:

a plurality of private keys, each private key associated with a respective group affiliation of which the apparatus is a member; and

a plurality of characteristic information associated with the apparatus;

a wireless interface configured to receive a request from a reader for verification of membership of the apparatus within one of the group affiliations; and

a controller including programmable logic for configuring the controller to:

determine whether to verify membership of the apparatus within a first group affiliation;

verify membership of the apparatus within the first group affiliation by signing data with a first private key, the first private key associated with the first group affiliation, wherein membership within the first group affiliation is configured to convey a subset of the characteristic information; and

send the signed data to the reader.

2. The apparatus of claim 1 , wherein:

the wireless interface is further configured to receive an additional request from the reader for verification of membership of the apparatus within another one of the group affiliations; and

the controller is further configured to:

determine whether to verify membership of the apparatus within any second group affiliations; and

ignore the additional request based upon a determination that the apparatus is not a member of any second group affiliations to be reported to the reader.

3. The apparatus of claim 1 , wherein:

the signed data is configured to be verified by a public key, the public key a counterpart to the first private key; and

the public key is configured to verify a plurality of private keys configured to denote membership in the first group affiliation by respective members of the first group affiliation.

4. The apparatus of claim 1 , wherein the first private key is unique to the apparatus.

5. The apparatus of claim 1 , wherein membership in the first group affiliation is verifiable by the first private key and by a second private key, the first private key different from the second private key.

6. The apparatus of claim 1 , wherein:

signing the data with the first private key verifies membership of the apparatus within the first group affiliation and in a second group affiliation;

the first group affiliation is a subset of the second group affiliation;

the signed data is configured to be verified by a public key, the public key a counterpart to the first private key; and

the public key is configured to verify that the signed data correctly identifies membership in the first group affiliation.

7. The apparatus of claim 1 , wherein:

signing the data with the first private key verifies membership of the apparatus within the first group affiliation and in a second group affiliation;

the first group affiliation is a subset of the second group affiliation;

the signed data is configured to be verified by a first public key, the first public key a counterpart to the first private key;

the first public key is configured to verify the signed data correctly identifies membership in the first group affiliation;

the signed data is further configured to be verified by a second public key; and

the second public key is configured to verify that the signed data correctly identifies membership in the second group affiliation.

8. The apparatus of claim 1 , wherein the controller is further configured to refuse to verify membership of the apparatus within any group affiliation based on a security evaluation of the reader.

9. The apparatus of claim 1 , wherein the controller is configured to identify the first private key from the plurality of private keys based upon a determination to share the subset of the characteristic information with the reader.

10. The apparatus of claim 1 , wherein the wireless interface includes a radio-frequency identification (RFID) circuit.

11. The apparatus of claim 1 , wherein the private keys are Enhanced Privacy Identification (EPID) keys.

12. The apparatus of claim 1 , wherein the programmable logic of the controller is embodied in one or more of:

instructions in a memory for execution by a processor;

an Application-Specific Integrated Circuit (ASIC); or

a Field-Programmable Gate Array (FPGA).

13. At least one non-transitory machine-readable medium, comprising instructions for execution on a processor, the instructions, when loaded and executed by the processor, cause the processor to:

receive a request from a reader through a wireless interface, wherein:

the request is for verification of membership of an apparatus within one of a plurality of group affiliations of which the apparatus is a member;

the apparatus includes a plurality of characteristic information associated with the apparatus;

determine whether to verify membership of the apparatus within a first group affiliation;

verify membership of the apparatus within the first group affiliation by signing data with a first private key, the first private key associated with the first group affiliation; and

send the signed data to the reader;

wherein membership within the first group affiliation is configured to convey a subset of the characteristic information.

14. The medium of claim 13 , wherein:

the signed data is configured to be verified by a public key, the public key a counterpart to the first private key; and

the public key is configured to verify a plurality of private keys configured to denote membership in the first group affiliation by respective members of the first group affiliation.

15. The medium of claim 13 , wherein:

signing the data with the first private key verifies membership of the apparatus within the first group affiliation and in a second group affiliation;

the first group affiliation is a subset of the second group affiliation;

the signed data is configured to be verified by a first public key, the first public key a counterpart to the first private key;

the first public key is configured to verify the signed data correctly identifies membership in the first group affiliation;

the signed data is further configured to be verified by a second public key; and

the second public key is configured to verify that the signed data correctly identifies membership in the second group affiliation.

16. The medium of claim 13 , further comprising instructions for causing the processor to identify the first private key from the plurality of private keys based upon a determination to share the subset of the characteristic information with the reader.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 8, 2016
From: SMITH, NED; SCHRECKER, SVEN; WISEMAN, WILLARD; CLARK, DAVID; GILBURG DE MAGNIA, JENNIFER; HERBERT, HOWARD
To: MCAFEE, INC.
Reel/Frame 039365/0975 →