IP Library Granted Patent US 11,030,280
Granted Patent B2
US 11,030,280 · App. 16/052,463 · Granted Jun 8, 2021

Hardware based identities for software modules

Inventors: Eustace Ngwa Asanghanwa (Kirkland, WA); Arjmand Samuel (Redmond, WA)
Assignee: Microsoft Technology Licensing, LLC
G06F21/123H04L9/0819H04L9/0866H04L63/123
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,030,280
App. No.
16/052,463
Granted
Jun 8, 2021
Kind
B2
Abstract

Creating a certificate for a software module. A method includes obtaining a public key for a software module. The method includes obtaining a public key for a software module implemented on a hardware device. The method further includes creating a certificate using the public key by signing the public key using a hardware protected key and hardware protected compute elements. The hardware protected key is protected by a protected portion of the hardware device, and not accessible outside of the protected portion of the hardware device.

Claims (48)

1. A computer system comprising:

one or more processors; and

one or more computer-readable media having stored thereon instructions for executing a computer process comprising:

obtaining a public key for a first software module implemented on a hardware device, the first software module comprising a Module Management Agent (MMA) software module; and

providing the public key to a hardware secure module (HSM) of the hardware device;

receiving a signature from the HSM, the signature being based on the public key and further based on a hardware protected key for the MMA software module, wherein the hardware protected key for the MMA software module is stored within the HSM at a location inaccessible to read entities external to the HSM;

creating a certificate for the first software module using the public key, the signature, and the hardware protected key for the MMA software module;

obtaining a different public key for a second software module; and

using the certificate as a verifiable identify for the first software module when the first software module is communicating with the second software module.

2. The computer system of claim 1 , wherein the certificate is an X.509 certificate.

3. The computer system of claim 1 , wherein one or more computer-readable media further have stored thereon instructions that are executable by the one or more processors to configure the computer system to perform at least the following:

creating an integrity digest, the integrity digest comprising a hash of static bits of the first software module and the certificate;

signing the integrity digest using the hardware protected private key for the first software module at the hardware device to create an integrity signature; and

associating the integrity signature with the first software module.

4. The computer system of claim 3 , wherein associating the integrity signature with the first software module comprises associating the integrity signature as a property of the first software module.

5. The computer system of claim 3 , wherein one or more computer-readable media further have stored thereon instructions that are executable by the one or more processors to configure the computer system to use the integrity signature to verify the first software module in conjunction with loading the first software module into memory of the hardware device.

6. The computer system of claim 1 , wherein the instructions are further executable to:

transmit a request to the HSM to generate a public/private key pair for the first software module.

7. A method comprising:

obtaining a public key for a first software module implemented on a hardware device, the first software module including a Module Management Agent (MMA) software module;

providing the public key to a hardware secure module (HSM) of the hardware device;

receiving a signature from the HSM, the signature being based on the public key and further based on a hardware protected key for the MMA software module, wherein the hardware protected key for the MMA is stored within the HSM at a location inaccessible to read entities external to the HSM;

creating a certificate for the first software module using the public key, the signature, and the hardware protected key for the MMA software module;

obtaining a different public key for a second software module; and

using the certificate as a verifiable identify for the first software module when the first software module is communicating with the second software module.

8. The method of claim 7 , wherein the certificate is an X.509 certificate.

9. The method of claim 7 , further comprising:

creating an integrity digest, the integrity digest comprising a hash of static bits of the first software module and the certificate;

signing the integrity digest using the hardware protected private key for the first software module at the hardware device to create an integrity signature; and

associating the integrity signature with the first software module.

10. The method of claim 9 , wherein associating the integrity signature with the first software module comprises associating the integrity signature as a property of the first software module.

11. The method of claim 9 , further comprising using the integrity signature to verify the first software module in conjunction with loading the first software module into memory of the hardware device.

12. A hardware device comprising:

a hardware secure module (HSM);

a hardware protected secret store, wherein the hardware protected secret store comprises a hardware protected key, and wherein the hardware protected secret store is stored within the hardware secure module (HSM) at a location inaccessible to read entities external to the HSM; and

hardware protected compute elements in the HSM comprising secure storage and secure processors, wherein the hardware protected compute elements are configured to execute a computer processing comprising:

obtaining a public key for a first software module implemented on the hardware device, the first software module comprising a Module Management Agent (MMA) software module, wherein the hardware protected key is a hardware protected key for the MMA;

providing the public key to the hardware secure module (HSM) of the hardware device;

receiving a signature from the HSM, the signature being based on the public key and further based on the hardware protected key for the MMA; and

creating a first certificate for the first software module using the public key, the signature, and the hardware protected key for the MMA software module;

obtaining a different public key for a second software module; and

using the first certificate as a verifiable identify for the first software module when the first software module is communicating with the second software module.

13. The hardware device of claim 12 , wherein the certificate is an X.509 certificate.

14. The hardware device of claim 12 , wherein the hardware protected compute elements are further configured to:

create an integrity digest, the integrity digest comprising a hash of static bits of the first software module and the certificate;

sign the integrity digest using the hardware protected private key for the first software module at the hardware device to create an integrity signature; and

associate the integrity signature with the first software module.

15. The hardware device of claim 14 , wherein associating the integrity signature with the first software module comprises associating the integrity signature as a property of the first software module.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 2, 2018
From: ASANGHANWA, EUSTACE NGWA; SAMUEL, ARJMAND
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 046534/0962 →
Continuity (1)
Related Publication 20200042675A1 · Feb 6, 2020