IP Library Granted Patent US 11,048,801
Granted Patent B2
US 11,048,801 · App. 15/938,701 · Granted Jun 29, 2021

Method and apparatus for secure computing device start up

Inventor: Lawrence Joseph Leblanc (Burnaby, CA)
Assignee: SIERRA WIRELESS, INC.
G06F21/575B28C7/024B28C7/0418G01N27/44791H04L9/0825H04L9/0861H04L9/0891H04L9/321H04L9/3247H04L9/3263H04L9/3268H04L9/3297E21B33/13H04L63/08H04L63/0823H04L2463/121
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,048,801
App. No.
15/938,701
Granted
Jun 29, 2021
Kind
B2
Abstract

The present invention provides methods and devices for secure computing device start up. The method includes generating a public/private key pair and signing a software image and obtaining a first time stamp and a second time stamp. The method further includes combining the signed software image, the first time stamp and the second time stamp into a bundle and deploying the bundle. During secure start up, the method includes authenticating the signed software image, the first time stamp and the second time stamp and booting the computing device if authentication passes. The computing device aborts booting the computing device if the authentication process fails.

Claims (33)

1. A method for secure computing device start up, the method comprising:

generating a public/private key pair and signing a software image using the private key of the public/private key pair;

obtaining a first time stamp and a second time stamp;

discarding or destroying the private key of the public/private key pair prior to obtaining the second time stamp;

combining the signed software image, the first time stamp and the second time stamp into a bundle;

deploying the bundle; during secure start up, authenticating the signed software image, the first time stamp and the second time stamp; and

booting the computing device if authentication passes.

2. The method according to claim 1 , further including formatting a certificate signing request (CSR) which includes the public key of the public/private key pair and signing the CSR with the private key.

3. The method according to claim 1 , wherein the first time stamp is received from a time stamp authority.

4. The method according to claim 1 , wherein the second time stamp is received from an intermediate certification authority.

5. The method according to claim 1 , wherein authenticating the signed software image includes determining if the first time stamp is present and trusted.

6. The method according to claim 5 , wherein authenticating the signed software image includes determining if the second time stamp is present and trusted.

7. The method according to claim 6 , wherein authenticating the signed software image includes determining if the first time stamp is less than the second time stamp.

8. The method according to claim 7 , wherein authenticating the signed software image includes determining if the second time stamp minus the first time stamp is less or equal to a predetermined value.

9. The method according to claim 1 , wherein the first time stamp and the second time stamp are obtained from a same time stamp authority.

10. A method for signing a software image for use during computing device start up, the method comprising:

generating a public/private key pair and signing a software image using the private key of the public/private key pair;

obtaining a first time stamp and a second time stamp;

discarding or destroying the private key of the public/private key pair prior to obtaining the second time stamp;

combining the signed software image, the first time stamp and the second time stamp into a bundle; and

deploying the bundle for use during computing device start up.

11. The method according to claim 10 , further including formatting a certificate signing request CSR) which includes the public key of the public/private key pair and signing the CSR with the private key.

12. The method according to claim 10 , wherein the first time stamp is received from a time stamp authority.

13. The method according to claim 10 , wherein the second time stamp is received from an intermediate certification authority.

14. The method according to claim 10 , wherein the first time stamp and the second time stamp are obtained from a same time stamp authority.

15. A device for signing a software image for use during computing device start up, the device comprising:

a processor; and

machine readable memory storing machine executable instructions which when executed by the processor configure the device to:

generate a public/private key pair and sign a software image using the private key of the public/private key pair;

obtain a first time stamp and a second time stamp;

discard or destroy the private key of the public/private key pair prior to obtaining the second time stamp;

combine the signed software image, the first time stamp and the second time stamp into a bundle; and

deploy the bundle for use during computing device start up.

Assignments (8)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 28, 2023
From: SIERRA WIRELESS, INC.
To: SEMTECH CORPORATION
Reel/Frame 062886/0528 →
CHANGE OF NAME Recorded Feb 28, 2023
From: SIERRA WIRELESS, INC.
To: SIERRA WIRELESS, ULC
Reel/Frame 062886/0422 →
MERGER AND CHANGE OF NAME Recorded Feb 28, 2023
From: SIERRA WIRELESS, ULC; 4462475 NOVA SCOTIA LIMITED; SIERRA WIRELESS, INC.
To: SIERRA WIRELESS, INC.
Reel/Frame 062886/0492 →
RELEASE OF SECURITY INTEREST Recorded Feb 10, 2023
From: CANADIAN IMPERIAL BANK OF COMMERCE
To: SIERRA WIRELESS AMERICA, INC.; SIERRA WIRELESS, INC.
Reel/Frame 062702/0496 →
RELEASE OF SECURITY INTEREST Recorded Jan 12, 2023
From: CANADIAN IMPERIAL BANK OF COMMERCE
To: SIERRA WIRELESS AMERICA INC.; SIERRA WIRELESS INC.
Reel/Frame 062389/0067 →
SECURITY INTEREST Recorded Mar 16, 2022
From: SIERRA WIRELESS, INC.; SIERRA WIRELESS AMERICA INC.
To: CANADIAN IMPERIAL BANK OF COMMERCE
Reel/Frame 059908/0311 →
SECURITY INTEREST Recorded Feb 25, 2022
From: SIERRA WIRELSS, INC.
To: CANADIAN IMPERIAL BANK OF COMMERCE
Reel/Frame 059250/0448 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 28, 2018
From: LEBLANC, LAWRENCE JOSEPH
To: SIERRA WIRELESS, INC.
Reel/Frame 045377/0993 →