IP Library › Granted Patent US 11,356,281
Granted Patent B2
US 11,356,281 · App. 15/931,306 · Granted Jun 7, 2022

Systems and methods for countering co-existence attack

Inventors: Henrique S. Ogawa (Sao Paulo, BR); Thomas E. Luther (Sunnyvale, CA); Jefferson E. Ricardini (Embu das Artes, BR); Helmiton Cunha, Jr. (Olinda, BR); Marcos A. Simplicio, Jr. (São Paulo, BR); Harsh Kupwade-Patil (Fremont, CA)
Assignees: LG ELECTRONICS, INC.; UNIVERSITY OF SAO PAULO
H04L9/3263H04L9/0877H04L9/14H04L9/3247H04L2209/84
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,356,281
App. No.
15/931,306
Granted
Jun 7, 2022
Kind
B2
Abstract

Embodiments described herein provide systems and methods to prevent, or provide a countermeasure, to a co-existence attack, for example, that may occur in a Security Credential Management System (SCMS) where both regular butterfly key (RBK) protocol and unified butterfly key (UBK) protocol are supported. Embodiments described herein provide, support, employ, or implement hardware acceleration for a Hardware Security Module (HSM), for example, for cryptographic operations (e.g., block ciphers, digital signature schemes, and key exchange protocols).

Claims (48)

1. A method for provisioning of digital certificates for use in authentication operations in an environment where both regular butterfly key (RBK) protocol and unified butterfly key (UBK) protocol are supported, the method comprising:

initializing, by a first entity, settings to operate according to the UBK protocol;

transmitting, by the first entity, a certificate request to a second entity on the basis that the second entity is operating according to the UBK protocol;

receiving, by the first entity, an encrypted response from the second entity, wherein the encrypted response includes at least one digital certificate and a protocol indicator, wherein the protocol indicator provides an indication of whether the digital certificate was generated according to the UBK protocol or the RBK protocol;

decrypting, by the first entity, the encrypted response to extract the digital certificate; and

checking, by the first entity, for the protocol indicator, wherein:

if the protocol indicator indicates that the digital certificate was generated according to the UBK protocol, enabling use of the digital certificate by the first entity; and

if the protocol indicator indicates that the digital certificate was generated according to the RBK protocol, discarding the digital certificate by the first entity.

2. The method of claim 1 , wherein the environment comprises a Security Credential Management System (SCMS).

3. The method of claim 2 , wherein the second entity comprises a device acting as a Registration Authority (RA) in the SCMS.

4. The method of claim 2 , wherein the digital certificate and the protocol indicator are generated by a device acting as an Authorization Certificate Authority (ACA) in the SCMS.

5. The method of claim 1 , wherein the protocol indicator comprises a single bit of information, wherein a first value for the bit indicates that the digital certificate was generated according to the UBK protocol, wherein a second value for the bit indicates that the digital certificate was generated according to the RBK protocol.

6. The method of claim 1 , wherein the protocol indicator is provided within metadata of the digital certificate.

7. The method of claim 1 , comprising generating, by the first entity, a caterpillar public key, wherein the caterpillar public key can be used by the second entity to process the certificate request.

8. The method of claim 1 , comprising reporting, by the first entity, of the second entity.

9. A computing device for provisioning of digital certificates for use in authentication operations in an environment where both regular butterfly key (RBK) protocol and unified butterfly key (UBK) protocol are supported, the computing device comprising:

a memory containing machine readable medium storing machine executable code;

one or more processors coupled to the memory and configured to execute the machine executable code to cause the one or more processors to:

initialize, by a first entity, settings to operate according to the UBK protocol;

transmit, by the first entity, a certificate request to a second entity on the basis that the second entity is operating according to the UBK protocol;

receive, by the first entity, an encrypted response from the second entity, wherein the encrypted response includes at least one digital certificate and a protocol indicator, wherein the protocol indicator provides an indication of whether the digital certificate was generated according to the UBK protocol or the RBK protocol;

decrypt, by the first entity, the encrypted response to extract the digital certificate; and

check, by the first entity, for the protocol indicator, wherein:

if the protocol indicator indicates that the digital certificate was generated according to the UBK protocol, enable use of the digital certificate by the first entity; and

if the protocol indicator indicates that the digital certificate was generated according to the RBK protocol, discard the digital certificate by the first entity.

10. The computing device of claim 9 , wherein the environment comprises a Security Credential Management System (SCMS).

11. The computing device of claim 10 , wherein the second entity comprises a device acting as a Registration Authority (RA) in the SCMS.

12. The computing device of claim 10 , wherein the digital certificate and the protocol indicator are generated by a device acting as an Authorization Certificate Authority (ACA) in the SCMS.

13. The computing device of claim 9 , wherein the protocol indicator comprises a single bit of information, wherein a first value for the bit indicates that the digital certificate was generated according to the UBK protocol, wherein a second value for the bit indicates that the digital certificate was generated according to the RBK protocol.

14. The computing device of claim 9 , wherein the protocol indicator is provided within metadata of the digital certificate.

15. The computing device of claim 9 , wherein the one or more processors are further configured to execute the machine executable code to cause the one or more processors to:

generate, by the first entity, a caterpillar public key, wherein the caterpillar public key can be used by the second entity to process the certificate request.

16. The computing device of claim 9 , wherein the one or more processors are further configured to execute the machine executable code to cause the one or more processors to:

report, by the first entity, of the second entity.

17. A tangible non-transitory machine readable storage medium comprising instructions executable by a first entity to perform a method for provisioning of digital certificates for use in authentication operations in an environment where both regular butterfly key (RBK) protocol and unified butterfly key (UBK) protocol are supported, the method comprising:

initializing settings to operate according to the UBK protocol;

transmitting a certificate request to a second entity on the basis that the second entity is operating according to the UBK protocol;

receiving an encrypted response from the second entity, wherein the encrypted response includes at least one digital certificate and a protocol indicator, wherein the protocol indicator provides an indication of whether the digital certificate was generated according to the UBK protocol or the RBK protocol;

decrypting the encrypted response to extract the digital certificate; and

checking for the protocol indicator, wherein:

if the protocol indicator indicates that the digital certificate was generated according to the UBK protocol, enabling use of the digital certificate; and

if the protocol indicator indicates that the digital certificate was generated according to the RBK protocol, discarding the digital certificate.

18. The tangible non-transitory machine readable storage medium of claim 17 , wherein the environment comprises a Security Credential Management System (SCMS).

19. The tangible non-transitory machine readable storage medium of claim 18 , wherein the second entity comprises a device acting as a Registration Authority (RA) in the SCMS.

20. The tangible non-transitory machine readable storage medium of claim 18 , wherein the digital certificate and the protocol indicator are generated by a device acting as an Authorization Certificate Authority (ACA) in the SCMS.

21. The tangible non-transitory machine readable storage medium of claim 17 , wherein the protocol indicator comprises a single bit of information, wherein a first value for the bit indicates that the digital certificate was generated according to the UBK protocol, wherein a second value for the bit indicates that the digital certificate was generated according to the RBK protocol.

22. The tangible non-transitory machine readable storage medium of claim 17 , wherein the protocol indicator is provided within metadata of the digital certificate.

23. The tangible non-transitory machine readable storage medium of claim 17 , wherein the method comprises generating a caterpillar public key, wherein the caterpillar public key can be used by the second entity to process the certificate request.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 3, 2020
From: OGAWA, HENRIQUE S.; LUTHER, THOMAS E.; RICARDINI, JEFFERSON E.; CUNHA, HELMITON; KUPWADE PATIL, HARSH
To: LG ELECTRONICS, INC.
Reel/Frame 053381/0160 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 3, 2020
From: SIMPLICIO, MARCOS ANTONIO, JR
To: UNIVERSITY OF SAO PAULO
Reel/Frame 053381/0613 →
Continuity (2)
Provisional Application 62832319 · Apr 11, 2019
Related Publication 20200382320A1 · Dec 3, 2020