IP Library Granted Patent US 11,323,275
Granted Patent B2
US 11,323,275 · App. 16/363,196 · Granted May 3, 2022

Verification of identity using a secret key

Inventors: Antonino Mondello (Messina, IT); Alberto Troia (Munich, DE)
Assignee: Micron Technology, Inc.
H04L9/3268H04L9/0825H04L9/0869H04L9/3236H04L9/3278H04L63/0442
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,323,275
App. No.
16/363,196
Granted
May 3, 2022
Kind
B2
Abstract

A method includes receiving, by a computing device, a message from a host device. In response to receiving the message, the computing device generates an identifier, a certificate, and a key. The identifier is associated with an identity of the computing device, and the certificate is generated using the message. The computing device sends the identifier, the certificate, and the key to the host device. The host device verifies the identity of the computing device using the identifier, the certificate, and the key.

Claims (52)

1. A method comprising:

receiving, by a computing device, a message from a host device;

generating, by the computing device, a public identifier, a certificate, and a public key, wherein the public identifier is associated with an identity of the computing device, the certificate is generated using the message, and generating the certificate comprises:

concatenating the message with the public key to provide first data;

encrypting the first data using a private identifier to provide second data; and

encrypting the second data using a private key to provide the certificate; and

sending, by the computing device, the public identifier, the certificate, and the public key to the host device, wherein the host device is configured to verify the identity of the computing device using the public identifier, the certificate, and the public key.

2. The method of claim 1 , wherein verifying the identity of the computing device comprises concatenating the message and the certificate to provide third data.

3. The method of claim 2 , wherein verifying the identity of the computing device further comprises decrypting the third data using the public key to provide fourth data.

4. The method of claim 3 , wherein verifying the identity of the computing device further comprises decrypting the fourth data using the public identifier to provide a result, and comparing the result to the public key.

5. The method of claim 1 , wherein the computing device stores a secret key, the method further comprising:

using the secret key as an input to a message authentication code to generate a derived secret;

wherein the public identifier is generated using the derived secret as an input to an asymmetric generator.

6. The method of claim 1 , wherein the public identifier is a first public identifier, and the computing device stores a first device secret used to generate the first public identifier, the method further comprising:

receiving a replace command from the host device;

in response to receiving the replace command, replacing the first device secret with a second device secret; and

sending, to the host device, a second public identifier generated using the second device secret.

7. The method of claim 1 , wherein:

a first asymmetric generator generates the public identifier and the private identifier as an associated pair; and

a second asymmetric generator generates the public key and the private key as an associated pair.

8. The method of claim 1 , further comprising generating a random number as an input to an asymmetric key generator, wherein the public key and the private key are generated using the asymmetric key generator.

9. The method of claim 8 , wherein the random number is generated using a physical unclonable function (PUF).

10. A system comprising:

at least one processor; and

memory containing instructions configured to instruct the at least one processor to:

send a message to a computing device;

receive, from the computing device, a public identifier, a certificate, and a public key, wherein the public identifier is associated with an identity of the computing device, the certificate is generated by the computing device, and the computing device is configured to:

concatenate the message with the public key to provide first data;

encrypt the first data using a private identifier to provide second data; and

encrypt the second data using a private key to provide the certificate; and

verify the identity of the computing device using the public identifier, the certificate, and the public key.

11. The system of claim 10 , wherein verifying the identity of the computing device comprises:

concatenating the message and the certificate to provide third data;

decrypting the third data using the key to provide fourth data;

decrypting the fourth data using the identifier to provide a result; and

comparing the result to the key.

12. The system of claim 10 , wherein the public identifier is a first public identifier, the computing device stores a first device secret used to generate the first public identifier, and the instructions are further configured to instruct the at least one processor to:

send a replace command to the computing device, the replace command to cause the computing device to replace the first device secret with a second device secret, and

receive, from the computing device, a second public identifier generated using the second device secret.

13. The system of claim 12 , wherein the computing device is configured to use the second device secret as an input to a message authentication code that provides a derived secret, and to generate the second public identifier using the derived secret.

14. The system of claim 12 , wherein the replace command includes a field having a value based on the first device secret.

15. The system of claim 10 , further comprising a freshness mechanism configured to generate a freshness, wherein the message sent to the computing device includes the freshness.

16. The system of claim 10 , wherein the identity of the computing device includes an alphanumeric string.

17. A non-transitory computer storage medium storing instructions which, when executed on a computing device, cause the computing device to at least:

receive a message from a host device;

generate a public identifier, a certificate, and a public key, wherein the public identifier corresponds to an identity of the computing device, the certificate is generated using the message, and generating the certificate comprises:

concatenating the message with the public key to provide first data;

encrypting the first data using a private identifier to provide second data; and

encrypting the second data using a private key to provide the certificate; and

send the public identifier, the certificate, and the public key to the host device for use in verifying the identity of the computing device.

18. The non-transitory computer storage medium of claim 17 , wherein the public identifier is associated with the private identifier, and the public key is associated with the private key.

19. The non-transitory computer storage medium of claim 17 , wherein verifying the identity of the computing device comprises performing a decryption operation using the public identifier to provide a result, and comparing the result to the key.

Assignments (5)
RELEASE OF SECURITY INTEREST Recorded Nov 15, 2019
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MICRON TECHNOLOGY, INC.
Reel/Frame 051041/0317 →
RELEASE OF SECURITY INTEREST Recorded Oct 14, 2019
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MICRON TECHNOLOGY, INC.
Reel/Frame 050724/0392 →
SUPPLEMENT NO. 12 TO PATENT SECURITY AGREEMENT Recorded Apr 19, 2019
From: MICRON TECHNOLOGY, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 048948/0677 →
SUPPLEMENT NO. 3 TO PATENT SECURITY AGREEMENT Recorded Apr 19, 2019
From: MICRON TECHNOLOGY, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 048951/0902 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 9, 2019
From: MONDELLO, ANTONINO; TROIA, ALBERTO
To: MICRON TECHNOLOGY, INC.
Reel/Frame 048837/0959 →
Cited By (4)
US 12,284,292 US 12,536,905 US 12,664,282 US 12,676,761