IP Library Granted Patent US 9,881,182
Granted Patent B2
US 9,881,182 · App. 15/416,833 · Granted Jan 30, 2018

Programming on-chip non-volatile memory in a secure processor using a sequence number

Inventors: Pramila Srinivasan (Pleasanton, CA); John Princen (Cupertino, CA)
Assignee: Acer Cloud Technology, Inc.
G06F21/72G06F21/33H04L9/0869H04L9/3066H04L9/3213H04L9/3263
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,881,182
App. No.
15/416,833
Granted
Jan 30, 2018
Kind
B2
Abstract

A method may be executed by a secure processor having secure cryptography hardware implemented thereon. The method may be executed in a security kernel of a secure on-chip non-volatile (NV) memory coupled to the secure processor. The method may include: storing a rewritable state and a device private key based at least in part on a programmed secret seed and the rewritable state, the device private key being part of a cryptographic key pair comprising a public key associated with the device private key, and the rewritable state being a state of a secure application encrypted with the public key; providing one or more instructions to gather the device private key and from the private key datastore; and using the device private key to generate a device certificate, the device certificate providing the device with access to the secure application.

Claims (28)

1. A device comprising:

a secure processor having secure cryptography hardware implemented thereon;

a secure on-chip non-volatile (NV) memory coupled to the secure processor, the secure on-chip NV memory having a security kernel receiving instructions from the secure processor, the security kernel containing:

a private key datastore configured to store a rewritable state and a device private key based at least in part on a programmed secret seed and the rewritable state, the device private key being part of a cryptographic key pair comprising a public key associated with the device private key, and the rewritable state being a state of a secure application encrypted with the public key;

an authenticated security Application Programming Interface (API) coupled to the private key datastore, the authenticated security API configured to provide one or more instructions to gather the device private key from the private key datastore;

a certificate construction engine coupled to the authenticated security API, the certificate construction engine configured to use the device private key to generate a device certificate, the device certificate providing the device with access to the secure application.

2. The device of claim 1 , wherein the programmed secret seed comprises a pseudorandom number.

3. The device of claim 1 , wherein the programmed secret seed is stored on on-chip read-only memory (ROM) coupled to the secure processor.

4. The device of claim 1 , wherein the security kernel uses the programmed secret seed and the rewritable state to generate the device private key.

5. The device of claim 1 , wherein the cryptographic key pair comprises an elliptical cryptographic key pair.

6. The device of claim 1 , wherein the security kernel identifies the public key in response to a request to execute the secure application.

7. The device of claim 1 , wherein the device private key comprises a variable key.

8. The device of claim 1 , wherein the certificate construction engine uses the device private key to generate the device certificate in response to a request to validate an electronic ticket provided by the secure application.

9. The device of claim 1 , wherein the secure processor loads the security kernel into the secure on-chip NV memory in response to a start-up of the device.

10. The device of claim 1 , wherein the device comprises a game console or a media player.

11. A method executed by a secure processor having secure cryptography hardware implemented thereon, the method executed in a security kernel of a secure on-chip non-volatile (NV) memory coupled to the secure processor, the method comprising:

storing a rewritable state and a device private key based at least in part on a programmed secret seed and the rewritable state, the device private key being part of a cryptographic key pair comprising a public key associated with the device private key, and the rewritable state being a state of a secure application encrypted with the public key;

providing one or more instructions to gather the device private key from a private key datastore;

using the device private key to generate a device certificate, the device certificate providing a device with access to the secure application.

12. The method of claim 11 , wherein the programmed secret seed comprises a pseudorandom number.

13. The method of claim 11 , wherein the programmed secret seed is stored on on-chip read-only memory (ROM) coupled to the secure processor.

14. The method of claim 11 , wherein the security kernel uses the programmed secret seed and the rewritable state to generate the device private key.

15. The method of claim 11 , wherein the cryptographic key pair comprises an elliptical cryptographic key pair.

16. The method of claim 11 , wherein the security kernel identifies the public key in response to a request to execute the secure application.

17. The method of claim 11 , wherein the device private key comprises a variable key.

18. The method of claim 11 , wherein using the device private key to generate the device certificate comprises using the device private key to generate the device certificate in response to a request to validate an electronic ticket provided by the secure application.

19. The method of claim 11 , wherein the secure processor loads the security kernel into the secure on-chip NV memory in response to a start-up of the device.

20. The method of claim 11 , wherein the secure processor and the secure on-chip NV memory are incorporated into a game console or a media player.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 26, 2021
From: ACER CLOUD TECHNOLOGY INC.
To: SAMSUNG ELECTRONICS CO., LTD.
Reel/Frame 055029/0142 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 26, 2017
From: SRINIVASAN, PRAMILA; PRINCEN, JOHN
To: BROADON COMMUNICATIONS CORP.
Reel/Frame 041096/0558 →
CHANGE OF NAME Recorded Jan 26, 2017
From: BROADON COMMUNICATIONS CORP.
To: IGWARE INC.
Reel/Frame 041512/0595 →
MERGER Recorded Jan 26, 2017
From: IGWARE INC.
To: ACER CLOUD TECHNOLOGY, INC.
Reel/Frame 041512/0724 →
Continuity (5)
Continuation 14325266 · Jul 7, 2014
Continuation 12576356 · Oct 9, 2009
Division 11601323 · Nov 16, 2006
Provisional Application 60857840 · Nov 9, 2006
Related Publication 20170132433A1 · May 11, 2017