IP Library Granted Patent US 10,567,170
Granted Patent B2
US 10,567,170 · App. 14/757,894 · Granted Feb 18, 2020

Hardware-generated dynamic identifier

Inventors: Matthew L. Rosenquist (Folsom, CA); Igor Tatourian (Santa Clara, CA)
Assignee: McAfee, LLC
H04L9/0861H04L9/065H04L9/083H04L9/0877H04L9/14H04L9/3226H04L9/3263H04L63/062H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,567,170
App. No.
14/757,894
Granted
Feb 18, 2020
Kind
B2
Abstract

In an example, there is disclosed an electronic apparatus, comprising: a hardware-encoded internal private key; and one or more logic elements comprising a key generation engine to: receive an third-party key; and operate on the third-party key and the internal private key to generate a hardware-generated dynamic identifier (HGDI). There is also disclosed a method of providing an HGDI engine, and one or more computer-readable mediums having stored thereon executable instructions for providing an HGDI.

Claims (34)

1. An electronic apparatus, comprising:

a hardware-encoded internal private key, comprising a hardware-encoded fuse array not reasonably directly readable without destructively examining the electronic apparatus; and

one or more logic elements comprising a passive key generation engine, the key generation engine having write permission only to one or more special-purpose memory locations for storing pseudo-unique hardware-generated dynamic identifiers (HGDIs), the key generation engine comprising:

circuitry to receive an unencrypted third-party key from a third party;

function circuitry to apply a one-directional operation to the third-party key and the internal private key to generate a pseudo-unique HGDI, wherein the HGDI is unique and persistent with respect to the third party key; and

derivation circuitry to derive a cypher of the public key and the function circuitry.

2. The electronic apparatus of claim 1 , wherein the one or more logic elements are immutable hardware logic elements.

3. The electronic apparatus of claim 1 , wherein the key generation engine is further to encrypt the HGDI.

4. The electronic apparatus of claim 1 , wherein the key generation engine is further to encrypt the HGDI with a salt.

5. The electronic apparatus of claim 1 , further comprising a filter to reject third-party keys not provided by a key authority.

6. The electronic apparatus of claim 1 , wherein the one or more special-purpose memory locations are not read restricted.

7. The electronic apparatus of claim 1 , wherein the one or more special-purpose memory locations are not read restricted to system-level resources.

8. The electronic apparatus of claim 1 , further comprising means to mitigate a replay attack.

9. The electronic apparatus of claim 8 , wherein the means comprise a temporal counter.

10. One or more tangible, non-transitory computer-readable storage mediums having stored thereon executable instructions for a processor of a hardware platform to provide passive key generation, wherein the instructions are to write only to one or more special-purpose memory locations for storing pseudo-unique hardware-generated dynamic identifiers (HGDIs), further operable to:

provide an internal private key, comprising a hardware-encoded fuse array not reasonably directly readable without destructively examining the hardware platform;

receive an unencrypted third-party key from a third party; and

apply a one-directional operation to the third-party key and the internal private key to generate a pseudo-unique HGDI, wherein the HGDI is unique and persistent with respect to the third party key; and

derive a cypher of the public key and the function circuitry.

11. The one or more tangible, non-transitory computer-readable storage mediums of claim 10 , wherein the one or more storage mediums comprise immutable hardware logic elements.

12. The one or more tangible, non-transitory computer-readable storage mediums of claim 10 , wherein the instructions are further to encrypt the HGDI with a salt.

13. The one or more tangible, non-transitory computer-readable storage mediums of claim 10 , wherein the instructions are further to reject third-party keys not provided by a key authority.

14. The one or more tangible, non-transitory computer-readable storage mediums of claim 10 wherein the one or more special-purpose memory locations are not read restricted to system-level resources.

15. The one or more tangible, non-transitory computer-readable storage mediums of claim 10 , wherein the instructions are further to mitigate a replay attack.

16. The one or more tangible, non-transitory computer-readable storage mediums of claim 15 , wherein the instructions are further to mitigate a replay attack comprising inspecting a temporal counter.

17. The one or more tangible, non-transitory computer-readable storage mediums of claim 10 , wherein providing the internal private key comprises deriving the internal private key from a value encoded in hardware.

18. The one or more tangible, non-transitory computer-readable storage mediums of claim 17 , wherein deriving the internal private key from the value encoded in hardware comprises applying a one-way function to the value encoded in hardware.

19. A method of providing a hardware-generated device identifier (HGDI) engine within immutable hardware of an electronic apparatus, the HGDI engine having write permission only to one or more special-purpose memory locations for storing pseudo-unique HGDIs, comprising providing passive key generation, and further comprising:

providing a hardware-encoded internal private key, comprising a hardware-encoded fuse array not reasonably directly readable without destructively examining the electronic apparatus;

receiving an unencrypted third-party key from a third party; and

applying a one-directional operation to the third-party key and the internal private key to generate a pseudo-unique HGDI, wherein the HGDI is unique and persistent with respect to the third party key; and

deriving a cypher of the public key and the function circuitry.

20. The method of claim 19 , further comprising encrypting the HGDI with a salt.

21. The method of claim 19 , further comprising rejecting third-party keys not provided by a key authority.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 14, 2016
From: ROSENQUIST, MATTHEW L.; TATOURIAN, IGOR
To: MCAFEE, INC.
Reel/Frame 038908/0161 →