IP Library Granted Patent US 10,678,908
Granted Patent B2
US 10,678,908 · App. 14/913,805 · Granted Jun 9, 2020

Trusted execution of an executable object on a local device

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,678,908
App. No.
14/913,805
Granted
Jun 9, 2020
Kind
B2
Abstract

In one example embodiment, an electronic device is provided and configured to: acquire authentication data for an authorized user; store the authentication data in an enclave; acquire identification data for a potential user; and compare, in the enclave, the identification data to the authentication data for recognizing if the potential user is the authorized user. In another embodiment, a server is provided and includes at least one processor; at least one memory; at least one driver, where the server is configured to: receive assertion data from an electronic device, where the assertion includes an authentication signing key and results from a comparison of acquired data and reference data; and determine if the assertion data is valid by: comparing the results to a threshold; and comparing the authentication signing key to an authentication signing key assigned to the electronic device.

Claims (39)

1. An electronic client device, comprising:

an enclave;

at least one processor;

at least one memory;

at least one driver, wherein the electronic client device is configured to:

obtain an authentication signing key from an attestation server;

store the authentication signing key in the enclave, wherein the authentication signing key verifies the identity of the enclave;

acquire, after storing the authentication signing key, authentication data for an authorized user;

store the authentication data in the enclave;

acquire identification data for a potential user;

compare, by locally executing, with the processor, a biometric algorithm in the enclave, the identification data to the authentication data to determine if the potential user is the authorized user; and

send results of the comparison and the authentication signing key to an authentication server.

2. The electronic client device of claim 1 , wherein the electronic client device is further configured to:

generate an assertion claim for the potential user using a claim building algorithm.

3. The electronic client device of claim 1 , wherein the results of the comparison are encrypted.

4. The electronic client device of claim 1 , wherein the results of the comparison are encrypted and stored in an untrusted memory that is separate from the enclave.

5. The electronic client device of claim 1 , wherein the identification data is biometric data.

6. The electronic client device of claim 1 , wherein the identification data is acquired outside of the enclave and a trusted services application program interface is used to bring the identification data into the enclave.

7. The electronic client device of claim 1 , wherein the electronic client device is further configured to:

access a secure application based on the results of the comparison.

8. The electronic client device of claim 1 , wherein the enclave operates in a trusted execution environment.

9. The electronic client device of claim 1 , wherein the enclave is a protected region of memory that is accessible through a trusted services application program interface.

10. The electronic client device of claim 1 , wherein the identification data is acquired by a hardware sensor.

11. One or more non-transitory computer readable medium having instructions stored thereon, the instructions, when executed by a processor, cause the processor to:

obtain an authentication signing key from an attestation server;

store the authentication signing key in the enclave, wherein the authentication signing key verifies the identity of the enclave;

acquire, after storing the authentication signing key, authentication data for an authorized user;

store the authentication data in an enclave on an electronic client device;

acquire identification data for a potential user; and

compare, by locally executing a biometric algorithm in the enclave, the identification data to the authentication data to determine if the potential user is the authorized user; and

send results of the comparison and the authentication signing key to an authentication server.

12. The medium of claim 11 , further including instructions that, when executed by the processor, cause the processor to:

generate an assertion claim for the potential user using a claim building algorithm.

13. The medium of claim 11 , wherein results of the comparison are encrypted and stored in an untrusted memory that is separate from the enclave.

14. The medium of claim 11 , wherein the identification data is biometric data.

15. The medium of claim 11 , wherein the identification data is acquired outside of the enclave and a trusted services application program interface is used to bring the identification data into the enclave.

16. The medium of claim 11 , further including instructions that, when executed by the processor, cause the processor to:

access a secure application based on results of the comparison.

17. The medium of claim 11 , wherein the enclave is a trusted execution environment.

Assignments (9)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →