IP Library Patent Application 16246691
Patent Application
App. No. 16/246,691

ATTESTATION DEVICE CUSTODY TRANSFER PROTOCOL

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
16/246,691
Abstract

A custody transfer of a device can include sending a start of transfer request to an attestation device over a short range wireless communication channel, a nonce is received from the attestation device in association with the start of transfer request, and the nonce is signed at the particular gateway device. The signed nonce is sent to the attestation device, a transfer confirmation message is received from the attestation device, and a transfer message is sent to a management system to report a transfer in custody of the attestation device involving the particular gateway device and another gateway device.

Claims (65)

1 .- 22 . (canceled)

23 . At least one non-transitory machine accessible storage medium having instructions stored thereon, the instructions when executed on a machine, cause the machine to:

receive, from a gateway device, an instance of attestation data, wherein the instance of attestation data includes a received value and is generated, by an attestation device, from secret data corresponding to a use session of the attestation device;

determine an expected value for the instance of attestation data based on, at least in part, the secret data corresponding to the use session of the attestation device;

compare the expected value and the received value; and

determine that the attestation device has integrity based on a determination that the expected value matches the received value; or

determine that the attestation device does not have integrity based on a determination that the expected value does not match the received value.

24 . The storage medium of claim 23 , wherein the secret data includes a configuration of the attestation device.

25 . The storage medium of claim 23 , wherein the secret data is stored on the attestation device.

26 . The storage medium of claim 25 , wherein the secret data stored on the attestation device is stored in volatile memory.

27 . The storage medium of claim 23 , wherein the instructions, when executed, further cause the machine to:

provision the secret data on the attestation device.

28 . The storage medium of claim 23 , wherein the gateway device communicates with the attestation device over a short range wireless connection.

29 . The storage medium of claim 23 , wherein the secret data is configured to be erased on a restart of the attestation device.

30 . At least one non-transitory machine accessible storage medium having instructions stored thereon, the instructions when executed on a machine, cause the machine to:

receive, from a first gateway device, a first instance of attestation data generated by an attestation device, wherein the first instance of attestation data includes a first received value;

determine a first expected value for the first instance of attestation data based on, at least in part, secret data associated with the attestation device;

compare the first expected value and the first received value;

determine that the attestation device has integrity based on a determination that the first expected value matches the first received value;

receive, from a second gateway device, a second instance of attestation data generated by the attestation device, wherein the second instance of attestation data includes a second received value;

determine a second expected value for the second instance of attestation data based on, at least in part, the secret data associated with the attestation device;

compare the second expected value and the second received value; and

determine that the attestation device has integrity based on a determination that the second expected value matches the second received value; or

determine that the attestation device does not have integrity based on a determination that the second expected value does not match the second received value.

31 . The storage medium of claim 30 , wherein the first gateway device and the second gateway device are controlled by a same entity.

32 . The storage medium of claim 30 , wherein the first gateway device is controlled by a first entity and the second gateway device is controlled by a second entity, and wherein the first entity is different than the second entity.

33 . The storage medium of claim 30 , wherein the secret data is configured to be erased on a restart of the attestation device.

34 . The storage medium of claim 30 , wherein the first received value is generated using a first value of a random number generator based on a particular seed and the second received value is generated using a second value of the random number generator based on the particular seed.

35 . A system comprising:

an attestation device comprising:

memory;

a hardware processor configured to:

generate an instance of attestation data that includes a received value, wherein the instance of attestation data is generated from secret data corresponding to a use session of the attestation device, and wherein the secret data is stored in the memory on the attestation device;

a gateway device comprising:

a short range communications module to:

send a signal to the attestation device; and

receive the instance of attestation data from the attestation device; and

an attestation module comprising:

memory; and

a hardware processor configured to:

receive, from the gateway device, the instance of attestation data including the received value;

determine an expected value for the instance of attestation data based on, at least in part, the secret data corresponding to the use session of the attestation device;

compare the expected value and the received value; and

determine that the attestation device has integrity based on a determination that the expected value matches the received value; or

determine that the attestation device does not have integrity based on a determination that the expected value does not match the received value.

36 . The system of claim 35 , wherein the secret data stored on the attestation device is stored in volatile memory.

37 . The system of claim 35 , wherein the secret data is configured to be erased on a restart of the attestation device.

38 . The system of claim 35 , wherein the attestation module hardware processor is further configured to:

store the secret data on the attestation device.

39 . The system of claim 35 , wherein the secret data is stored in memory on the attestation module.

40 . The system of claim 35 , wherein the gateway device is a first gateway device, the system further comprising:

a second gateway device comprising:

a short range communications module to:

send a signal to the attestation device; and

receive a second instance of attestation data from the attestation device; and

wherein the attestation device hardware processor is further configured to:

generate, from the secret data during the use session, the second instance of attestation data that includes a second received value, and

wherein the attestation module hardware processor is further configured to:

receive, from the second gateway device, the second instance of attestation data including the second received value;

determine a second expected value for the second instance of attestation data based on, at least in part, the secret data corresponding to the use session of the attestation device;

compare the second expected value and the second received value; and

determine that the attestation device has integrity based on a determination that the second expected value and the second received value match; or

determine that the attestation device does not have integrity based on a determination that the second expected value and the second received value do not match.

41 . The system of claim 40 , wherein the first gateway device and the second gateway device are controlled by a same entity.

42 . The system of claim 40 , wherein the first gateway device and the second gateway device are controlled by different entities.

Assignments (13)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 056990, FRAME 0960 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0430 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 057453, FRAME 0053 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0413 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 4, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 059855/0807 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →