IP Library Granted Patent US 11,876,791
Granted Patent B2
US 11,876,791 · App. 16/835,173 · Granted Jan 16, 2024

Message authentication with secure code verification

Inventors: Kerry Maletsky (Monument, CO); Oscar Sanchez (Colorado Springs, CO); Nicolas Schieli (Los Gatos, CA)
Assignee: Amtel Corporation
H04L63/08H04L9/3242H04L9/3247H04L63/12H04L67/01H04L67/025H04L67/125H04L67/60
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,876,791
App. No.
16/835,173
Granted
Jan 16, 2024
Kind
B2
Abstract

Systems, methods, circuits and computer-readable mediums for message authentication with secure code verification are provided. In one aspect, a system includes a client device storing a code and a security device coupled to the client device. The security device is configured to receive a property of the code generated by the client device, verify correctness of the property of the code based on information associated with an authorized code to determine that the code is authorized, the information being stored within the security device. In response to determining that the code is authorized, the security device enables to access data stored within the security device and generate a property of a message based on the data.

Claims (53)

1. A system comprising:

a client device storing a code; and

a security device coupled to the client device and to:

select a plurality of memory address ranges of an authorized code;

determine a respective portion of the authorized code for each of the plurality of memory address ranges;

calculate a respective first property of each determined portion of the authorized code;

store first information indicative of the respective first properties of the portions of the authorized code and second information indicative of the respective memory address ranges in the security device; and

respectively associate memory address ranges from among the plurality of memory address ranges with first properties from among the first properties of the portions;

receive a first property of a code generated by the client device;

verify correctness of the first property of the code based on information associated with the authorized code to determine that the code is authorized, the information being stored within the security device;

in response to determining that the code is authorized, enable the security device to access first secret data stored within secure storage of the security device; and

generate a second property of a first message based on the first secret data,

wherein the client device is to:

receive the second property of the first message from the security device;

generate the second property of a second message based on second secret data stored within the client device, the second secret data corresponding to the first secret data stored within the security device;

determine whether the second property of the second message is valid based on a comparison of the second property of the second message and the second property of the first message; and

determine whether or not to run an application on the client device using the code based on a result of determining whether the second property of the second message is valid.

2. The system of claim 1 , wherein the security device is to:

select a particular memory address range from among the plurality of memory address ranges; and

cause data indicating the particular memory address range to be sent to the client device, the particular memory address range corresponding to a particular portion of the authorized code.

3. The system of claim 2 , wherein the first property of the code comprises a digest of a portion of the code, and

wherein the security device is to verify the correctness of the first property of the code by determining that the digest of the portion of the code matches a digest of the particular portion of the authorized code stored in the security device.

4. The system of claim 2 , wherein the first property of the code comprises scrambled data of a portion of the code,

wherein the security device is to:

descramble the scrambled data of the portion of the code to get a descrambled portion of the code,

generate a digest of the descrambled portion of the code, and

determine that the generated digest of the descrambled portion of the code matches the stored digest of the particular portion of the authorized code to verify the correctness of the first property of the code.

5. A method comprising:

providing a client device storing a code and a security device coupled to the client device;

selecting, by the security device, a plurality of memory address ranges of an authorized code;

determining, by the security device, a respective portion of the authorized code for each of the plurality of memory address ranges;

calculating, by the security device, a respective first property of each determined portion of the authorized code;

storing, by the security device, first information indicative of the respective first properties of the portions of the authorized code and second information indicative of the respective memory address ranges in the security device; and

respectively associating, by the security device, memory address ranges from among the plurality of memory address ranges with first properties from among the first properties of the portions;

receiving, by the security device, a first property of a code generated by the client device;

verifying, by the security device, correctness of the first property of the code based on information associated with the authorized code to determine that the code is authorized, the information being stored within the security device;

in response to determining that the code is authorized, enabling the security device to access first secret data stored within secure storage of the security device;

generating, by the security device, a second property of a first message based on the first secret data;

receiving, by the client device, the second property of the first message from the security device;

generating, by the client device, the second property of a second message based on second secret data stored within the client device, the second secret data corresponding to the first secret data stored within the security device;

determining, by the client device, whether the second property of the second message is valid based on a comparison of the second property of the second message and the second property of the first message; and

determining, by the client device, whether or not to run an application on the client device using the code based on a result of determining whether the second property of the second message is valid.

6. The method of claim 5 , comprising:

selecting, by the security device, a particular memory address range from among the plurality of memory address ranges; and

causing, by the security device, data indicating the particular memory address range to be sent to the client device, the particular memory address range corresponding to a particular portion of the authorized code.

7. The method of claim 6 , wherein the first property of the code comprises a digest of a portion of the code.

8. The method of claim 7 , wherein verifying the correctness of the first property of the code comprises:

determining, by the security device, that the digest of the portion of the code matches a digest of the particular portion of the authorized code stored in the security device.

9. The method of claim 6 , wherein the first property of the code comprises scrambled data of a portion of the code.

10. The method of claim 9 , comprising:

descrambling, by the security device, the scrambled data of the portion of the code to get a descrambled portion of the code,

generating, by the security device, a digest of the descrambled portion of the code, and

determining, by the security device, that the generated digest of the descrambled portion of the code matches the stored digest of the particular portion of the authorized code to verify the correctness of the first property of the code.

Assignments (10)
RELEASE OF SECURITY INTEREST Recorded Mar 14, 2022
From: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: MICROCHIP TECHNOLOGY INCORPORATED; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION; MICROSEMI STORAGE SOLUTIONS, INC.
Reel/Frame 060894/0437 →
RELEASE OF SECURITY INTEREST Recorded Mar 11, 2022
From: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: MICROCHIP TECHNOLOGY INCORPORATED; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION; MICROSEMI STORAGE SOLUTIONS, INC.
Reel/Frame 059363/0001 →
RELEASE OF SECURITY INTEREST Recorded Mar 10, 2022
From: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: MICROCHIP TECHNOLOGY INCORPORATED; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION; MICROSEMI STORAGE SOLUTIONS, INC.
Reel/Frame 059863/0400 →
RELEASE OF SECURITY INTEREST Recorded Mar 9, 2022
From: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: MICROCHIP TECHNOLOGY INCORPORATED; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION; MICROSEMI STORAGE SOLUTIONS, INC.
Reel/Frame 059358/0335 →
RELEASE OF SECURITY INTEREST Recorded Feb 28, 2022
From: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
To: MICROCHIP TECHNOLOGY INCORPORATED; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION; MICROSEMI STORAGE SOLUTIONS, INC.
Reel/Frame 059263/0001 →
GRANT OF SECURITY INTEREST IN PATENT RIGHTS Recorded Nov 19, 2021
From: MICROCHIP TECHNOLOGY INCORPORATED; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION; MICROSEMI STORAGE SOLUTIONS, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 058214/0625 →
SECURITY INTEREST Recorded Jun 4, 2021
From: MICROCHIP TECHNOLOGY INCORPORATED; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION; MICROSEMI STORAGE SOLUTIONS, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 057935/0474 →
SECURITY INTEREST Recorded Dec 24, 2020
From: MICROCHIP TECHNOLOGY INCORPORATED; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION; MICROSEMI STORAGE SOLUTIONS, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 055671/0612 →
SECURITY INTEREST Recorded Jun 5, 2020
From: MICROCHIP TECHNOLOGY INC.; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION; MICROSEMI STORAGE SOLUTIONS, INC.
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 052856/0909 →
SECURITY INTEREST Recorded Jun 5, 2020
From: MICROCHIP TECHNOLOGY INC.; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION; MICROSEMI STORAGE SOLUTIONS, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION
Reel/Frame 053468/0705 →
Continuity (2)
Continuation 15131919 · Apr 18, 2016
Related Publication 20200236097A1 · Jul 23, 2020