IP Library Granted Patent US 11,119,905
Granted Patent B2
US 11,119,905 · App. 16/508,073 · Granted Sep 14, 2021

System and method for managing electronic assets

Inventors: Keelan Smith (Toronto, CA); Richard Gwynn Jones (San Diego, CA); Chinh Khac Nguyen (Toronto, CA); Thomas Rudolf Stiemerling (Toronto, CA)
Assignee: BlackBerry Limited
G06F11/3688G06F8/70G06F9/54G06F21/00G06F21/57G06Q10/06G06Q50/04Y02P90/30
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,119,905
App. No.
16/508,073
Granted
Sep 14, 2021
Kind
B2
Abstract

An asset management system is provided which comprises one or more controllers, which operate as main servers and can be located at the headquarters of an electronic device manufacturer to remotely control their operations at any global location. The controller can communicate remotely over the Internet or other network to control one or more secondary or remote servers, herein referred to as appliances. The appliances can be situated at different manufacturing, testing or distribution sites. The controller and appliances comprise hardware security modules (HSMs) to perform sensitive and high trust computations, store sensitive information such as private keys, perform other cryptographic operations, and establish secure connections between components. The HSMs are used to create secure end-points between the controller and the appliance and between the appliance and the secure point of trust in an asset control core embedded in a device.

Claims (33)

1. A method for distributing electronic assets to devices, the method comprising:

defining, with a hardware processor, a first asset to be added to a device;

defining, with the hardware processor, a second asset to be added to the device;

defining, with the hardware processor, a product type and associating the first asset and the second asset with the product type; and

distributing via a secure communication channel, by the hardware processor, the first asset and the second asset together to an asset control core (ACC) of the device associated with the product type, wherein the hardware processor is external to the device, and wherein the ACC is a hardware core having an ACC functional microcontroller that is embedded on an integrated circuit (IC) of the device and the ACC:

provides a cryptographic security engine with self-contained generation of keys used to open up the secure communication channel with the hardware processor,

provides a self-contained generation of a device ID (UID) that identifies the IC, and

performs device feature activation or deactivation based on the first asset and the second asset that are received over the secure communication channel.

2. The method according to claim 1 , wherein the first asset is one of a first serial number, a first key, and a first feature set.

3. The method according to claim 2 , wherein the second asset is one of a second serial number, a second key, and a second feature set.

4. The method according to claim 1 , wherein the second asset is one of a serial number, a key, and a feature set.

5. A non-transitory computer readable medium comprising computer executable instructions that when executed cause a computing device to:

define, by executing with a hardware processor, a first asset to be added to a device;

define, by executing with the hardware processor, a second asset to be added to the device;

define, by executing with the hardware processor, a product type and associating the first asset and the second asset with the product type; and

distribute via a secure communication channel, by executing with the hardware processor, the first asset and the second asset together to an asset control core (ACC) of the device associated with the product type, wherein the hardware processor is external to the device, and wherein the ACC is a hardware core having an ACC functional microcontroller that is embedded on an integrated circuit (IC) of the device and the ACC:

provides a cryptographic security engine with self-contained generation of keys used to open up the secure communication channel with the hardware processor

provides a self-contained generation of a device ID (UID) that identifies the IC, and

performs device feature activation or deactivation based on the first asset and the second asset that are received over the secure communication channel.

6. The non-transitory computer readable medium according to claim 5 , wherein the first asset is one of a first serial number, a first key, and a first feature set.

7. The non-transitory computer readable medium according to claim 6 , wherein the second asset is one of a second serial number, a second key, and a second feature set.

8. The non-transitory computer readable medium according to claim 5 , wherein the second asset is one of a serial number, a key, and a feature set.

9. A computer with a hardware processor for executing computer executable instructions that when executed cause the computer to:

define, by executing with the hardware processor, a first asset to be added to a device;

define, by executing with the hardware processor, a second asset to be added to the device;

define, by executing with the hardware processor, a product type and associating the first asset and the second asset with the product type; and

distribute via a secure communication channel, by executing with the hardware processor, the first asset and the second asset together to an asset control core (ACC) of the device associated with the product type, wherein the hardware processor is external to the device, and wherein the ACC is a hardware core having an ACC functional microcontroller that is embedded on an integrated circuit (IC) of the device and the ACC:

provides a cryptographic security engine with self-contained generation of keys used to open up the secure communication channel with the hardware processor

provides a self-contained generation of a device ID (UID) that identifies the IC, and

performs device feature activation or deactivation based on the first asset and the second asset that are received over the secure communication channel.

10. The computer with the hardware processor to claim 9 , wherein the first asset is one of a first serial number, a first key, and a first feature set.

11. The computer with the hardware processor to claim 10 , wherein the second asset is one of a second serial number, a second key, and a second feature set.

12. The computer with the hardware processor to claim 9 , wherein the second asset is one of a serial number, a key, and a feature set.

Assignments (6)
NUNC PRO TUNC ASSIGNMENT Recorded Jun 19, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064270/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064104/0103 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 2, 2019
From: CERTICOM CORP.
To: BLACKBERRY LIMITED
Reel/Frame 050610/0937 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 11, 2019
From: SMITH, KEELAN; STIEMERLING, THOMAS RUDOLF; NGUYEN, CHINH KHAC
To: CERTICOM CORP.
Reel/Frame 049724/0357 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 11, 2019
From: JONES, RICHARD GWYNN
To: CERTICOM (U.S.) LIMITED
Reel/Frame 049724/0481 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 11, 2019
From: CERTICOM (US) LIMITED
To: CERTICOM CORP.
Reel/Frame 049724/0564 →
Continuity (4)
Continuation 14734467 · Jun 9, 2015
Continuation 12834804 · Jul 12, 2010
Provisional Application 61224823 · Jul 10, 2009
Related Publication 20190370159A1 · Dec 5, 2019