IP Library Granted Patent US 10,044,696
Granted Patent B2
US 10,044,696 · App. 14/978,920 · Granted Aug 7, 2018

Simplified sensor integrity

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,044,696
App. No.
14/978,920
Granted
Aug 7, 2018
Kind
B2
Abstract

An apparatus is provided that includes at least one processor device, an energy storage module to power the apparatus, memory to store a secret such that powering down and restarting the apparatus causes the secret to be lost, logic executable by the at least one processor device to generate attestation data using the secret that data abstracts the secret, and a communications interface to send the attestation data to another device.

Claims (32)

1. An attestation apparatus comprising:

at least one processor device;

an energy storage module to power the attestation apparatus;

a memory in which a secret is stored on the attestation apparatus, wherein the secret is provisioned in the memory via a trusted provisioning event by a management system corresponding to a specific use session from a plurality of use sessions of the attestation apparatus and wherein a loss of power event causes the secret to be deleted from the memory;

at least one sensor to sense characteristics of an environment of the apparatus and generate signals indicative of the sensed environmental characteristics;

logic, executable by the at least one processor device, in response to receiving a start of transfer request from a particular gateway device, to:

transmit the stored secret to the particular gateway device and use a signed secret returned from the particular gateway device to generate a custody transfer message to the management system;

generate log data from the signals and store the generated log data in the memory; and

generate attestation data derived from the stored secret along with log data of the attestation apparatus;

a communications interface to send the generated attestation data and the log data to the management system via the particular gateway device to verify integrity and authenticity of the attestation apparatus based on the received attestation data corresponding to said specific use session.

2. The apparatus of claim 1 , wherein the secret is stored in a first portion of the memory, the memory comprises a second portion, and the second portion of the memory comprises non-volatile memory.

3. The apparatus of claim 2 , wherein the memory comprises random access memory.

4. The apparatus of claim 2 , wherein the second portion of the memory is to store log data to be shared with the another device.

5. The apparatus of claim 1 , wherein the attestation data is to attest to integrity of the apparatus.

6. The apparatus of claim 5 , wherein the integrity of the apparatus is conditioned on the apparatus having maintained power throughout a session and the secret is provisioned to correspond to a start of the session.

7. The apparatus of claim 1 , wherein the attestation data is generated from a cryptographic hash of the log data using the secret.

8. The apparatus of claim 1 , wherein the attestation data is to represent integrity of the log data.

9. The apparatus of claim 1 , wherein the memory is provisioned with a random number and the attestation data is generated based on the random number and secret data.

10. The apparatus of claim 1 , wherein the communication interface is further to receive a signal from the another device and send the attestation data to the another device in response to the signal, and the another device is to forward the attestation data to a management system over a network.

11. The apparatus of claim 1 , wherein the apparatus comprises an in-package sensor device to sense conditions during a shipment of the package.

12. At least one non-transitory computer-readable storage medium having instructions stored thereon, the instructions when executed on a processor device, cause the processor device to:

receive, at an attestation device, a signal from a particular gateway device, the attestation device comprising:

an energy storage module to power the attestation device;

a memory in which a secret is stored on the attestation apparatus, wherein the secret is provisioned in the memory via a trusted provisioning event by a management system corresponding to a specific use session from a plurality of use sessions of the attestation apparatus and wherein a loss of power event causes the secret to be deleted from the memory; and

at least one sensor to sense characteristics of an environment of the apparatus and generate signals indicative of the sensed environmental characteristics;

transmit the stored secret to the particular gateway device and use a signed secret returned from the particular gateway device to generate a custody transfer message to the management system;

generate log data from the signals and store the generated log data in the memory; and

generate attestation data derived from the stored secret along with log data of the attestation apparatus;

a communications interface to send the generated attestation data and the log data to the management system via the particular gateway device to verify integrity and authenticity of the attestation apparatus based on the received attestation data corresponding to said specific use session.

13. The storage medium of claim 12 , wherein the instructions, when executed, further cause the machine to configure the attestation device to load the secret in the memory segment and load a firmware image on the attestation device.

14. The storage medium of claim 13 , wherein the secret and firmware image are provided by a remote management system.

15. The storage medium of claim 12 , wherein the instructions, when executed, further cause the machine to participate with the particular gateway device and at least one other collocated gateway device in a custody transfer protocol.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 15, 2016
From: WALKER, JESSE RANDALL; HERBERT, HOWARD C.; BRANNOCK, KIRK D.; PRICE, STEPHEN H.; COOPER, GEOFFREY H.; DEVRIES, DAVID A.; AMOLS, DAVID M.; SCHRECKER, SVEN
To: MCAFEE, INC.
Reel/Frame 037977/0089 →