IP Library Granted Patent US 12,088,741
Granted Patent B2
US 12,088,741 · App. 16/948,101 · Granted Sep 10, 2024

Mutual authentication protocol for systems with low-throughput communication links, and devices for performing the same

Inventor: Paolo Trere (San Jose, CA)
Assignee: Microchip Technology Incorporated
H04L9/3273H04L9/0825H04L9/16H04L9/3247H04L9/3263
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,088,741
App. No.
16/948,101
Granted
Sep 10, 2024
Kind
B2
Abstract

Discussed is a mutual authentication protocol, and systems, methods and devices implementing the same. Such a protocol may be used, as a non-limiting example, by devices coupled by low throughput connections for speedy authentication to establish a secure communication session.

Claims (83)

1. A method of performing a side of a mutual authentication handshake, the method comprising:

at a device of a first party,

exchanging identity information with a device of a second party via a first messaging of a handshake messaging phase, the first messaging comprising:

sending a first message, the first message comprising a first cryptographic nonce and a first signed device certificate portion associated with the first party; and

receiving a second message, the second message comprising a second cryptographic nonce and a second signed device certificate portion associated with the second party;

verifying the second party's identity at the device of the first party at least partially based on the second signed device certificate portion;

exchanging signed key agreement exchange information of a signed key agreement exchange with the device of the second party via a second messaging of the handshake messaging phase, the second messaging comprising:

sending a third message, the third message comprising a first signed ephemeral public key including a first digital signature, the first digital signature generated with a first private key of the first party using a first ephemeral public key of the first party and the second cryptographic nonce from the second message; and

receiving a fourth message, the fourth message comprising a second signed ephemeral public key including a second digital signature, the second digital signature generated with a second private key of the second party using a second ephemeral public key of the second party and the first cryptographic nonce from the first message; and

obtaining the second ephemeral public key of the second party at least partially based on the second signed ephemeral public key and a public key of the second party, the public key of the second party obtained at least partially from the second signed device certificate portion associated with the second party.

2. The method of claim 1 , further comprising:

at the device of the first party,

selecting information stored in one or more specific fields of a first device certificate;

generating a first device certificate portion comprising the selected information; and

signing the first device certificate portion responsive to a trusted third-party's digital signature to generate the first signed device certificate portion.

3. The method of claim 1 , further comprising:

at the device of the first party,

obtaining a device certificate of the second party by combining the second signed device certificate portion and a partially pre-filled device certificate.

4. The method of claim 3 , wherein combining the second signed device certificate portion and the partially pre-filled device certificate comprises: combining the second signed device certificate portion with a portion of the partially pre-filled device certificate that is complimentary to the second signed ephemeral public key and second signed device certificate portion.

5. The method of claim 1 ,

wherein the exchanging of the identity information and the exchanging of the signed key agreement exchange information is performed through a low-throughput connection of the device of the first party.

6. The method of claim 1 , wherein:

a total number of first handshake messages for verification of identity is two messages including the first message and the second message, and

a total number of second handshake messages for signed key agreement exchange is two messages including the third message and the fourth message.

7. The method of claim 1 , further comprising:

at the device of the first party,

generating a session secret responsive to the second ephemeral public key and an ephemeral private key; and

participating in a secure communication session with the device of the second party based on the session secret.

8. The method of claim 1 , further comprising:

at the device of the first party,

rotate session keys of a secure communication session responsive to initiating a second handshake messaging phase.

9. A computing apparatus, comprising:

a processor; and

a memory having thereon machine-executable instructions that, when executed by the processor, configure the computing apparatus of a first party to:

exchange identity information with a computing apparatus of a second party via first handshake messages, the first handshake messages comprising:

a first message, the first message comprising a first cryptographic nonce and a first signed device certificate portion associated with the first party; and

a second message, the second message comprising a second cryptographic nonce and a second signed device certificate portion associated with the second party;

verify the second party's identity at the computing apparatus of the first party at least partially based on the second signed device certification portion;

exchange first signed key agreement exchange information with the computing apparatus of the second party via second handshake messages, the second handshake messages comprising:

a third message, the third message comprising a first signed ephemeral public key including a first digital signature, the first digital signature generated with a first private key of the first party using a first ephemeral public key of the first party and the second cryptographic nonce from the second message; and

a fourth message, the fourth message comprising a second signed ephemeral public key including a second digital signature, the second digital signature generated with a second private key of the second party using a second ephemeral public key of the second party and the first cryptographic nonce from the first message; and

obtain the second ephemeral public key of the second party at least partially based on the second signed ephemeral public key and a public key of the second party, the public key of the second party obtained at least partially from the second signed device certificate portion associated with the second party.

10. The computing apparatus of claim 9 , wherein the machine-executable instructions comprise further machine-executable instructions that, when executed by the processor, configure the computing apparatus of the first party to:

select information stored in one or more specific fields of a first device certificate;

generate a first device certificate portion comprising the selected information; and

sign the first device certificate portion responsive to a trusted third-party's digital signature to generate the first signed device certificate portion.

11. The computing apparatus of claim 9 , wherein the machine-executable instructions comprise further machine-executable instructions that, when executed by the processor, configure the computing apparatus of the first party to:

obtain a device certificate of the party by combining the second signed device certificate portion and a partially pre-filled device certificate.

12. The computing apparatus of claim 11 , wherein the partially pre-filled device certificate is complimentary to the second signed device certificate portion.

13. The computing apparatus of claim 11 , wherein the machine-executable instructions comprise further machine-executable instructions that, when executed by the processor, configure the computing apparatus of the first party to:

verify the party's identity responsive to the obtained device certificate of the party.

14. The computing apparatus of claim 9 , wherein

a total number of first handshake messages for verification of identity is two messages including the first message and the second message, and

a total number of second handshake messages for signed key agreement exchange is two messages including the third message and the fourth message.

15. The computing apparatus of claim 9 , wherein the machine-executable instructions comprise further machine-executable instructions that, when executed by the processor, configure the computing apparatus of the first party to:

generate a session secret responsive to the second ephemeral public key and an ephemeral private key; and

participate in a secure communication session with the computing apparatus of the second party based on the session secret.

16. The computing apparatus of claim 9 , wherein the machine-executable instructions comprise further machine-executable instructions that, when executed by the processor, configure the computing apparatus of the first party to:

rotate session keys of a secure communication session responsive to initiation of a second handshake messaging phase.

17. A data storage device, the data storage device associated with a first party and including instructions that, when executed by a processor, cause the processor to:

exchange identity information with a data storage device of a second party via first handshake messages, the first handshake messages comprising:

a first message comprising a first cryptographic nonce and a first signed device certificate portion associated with the first party; and

a second message comprising a second cryptographic nonce and a second signed device certificate portion associated with the second party;

verify the second party's identity at the data storage device of the first party at least partially based on the second signed device certificate portion, and

exchange first signed key agreement exchange information with the party via second handshake messages, the second handshake messages comprising:

a third message comprising a first signed ephemeral public key including a first digital signature, the first digital signature generated with a first private key of the first party using a first ephemeral public key of the first party and the second cryptographic nonce from the second message; and

a fourth message comprising a second signed ephemeral public key including a second digital signature, the second digital signature generated with a second private key of the second party using a second ephemeral public key of the second party and the first cryptographic nonce from the first message; and

obtain a second ephemeral public key of the second party at least partially based on the second signed ephemeral public key and a public key of the second party, the public key of the second party obtained at least partially from the second signed device certificate portion associated with the second party.

18. A computing apparatus, comprising:

one or more processors; and

a memory having thereon machine-executable instructions that, when executed by the one or more processors, configure the computing apparatus of a first party of a mutual authentication handshake to:

exchange identity information with a computing apparatus of a second party via first handshake messages, the first handshake messages comprising:

a first message, the first message comprising a first cryptographic nonce and a first signed device certificate portion associated with the first party; and

a second message, the second message comprising a second cryptographic nonce and a second signed device certificate portion associated with the second party;

exchange first signed key agreement exchange information with the computing apparatus of the second party via second handshake messages, the second handshake messages comprising:

a third message, the third message comprising a first signed ephemeral public key including a first digital signature, the first digital signature generated with a first private key of the first party using a first ephemeral public key of the first party and the second cryptographic nonce from the second message; and

a fourth message, the fourth message comprising a second signed ephemeral public key including a second digital signature, the second digital signature generated with a second private key of the second party using a second ephemeral public key of the second party and the first cryptographic nonce from the first message.

19. The computing apparatus of claim 18 , wherein the machine-executable instructions comprise machine-executable instructions that, when executed by the processor, configure the computing apparatus of the first party to:

verify the second party's identity at the computing apparatus of the first party at least partially based on the second signed device certification portion; and

obtain the second ephemeral public key of the second party at least partially based on the second signed ephemeral public key and a public key of the second party, the public key of the second party obtained at least partially from the second signed device certificate portion associated with the second party.

20. The computing apparatus of claim 18 , wherein:

a total number of first handshake messages for verification of identity is two messages including the first message and the second message, and

a total number of second handshake messages for signed key agreement exchange is two messages including the third message and the fourth message.

Assignments (11)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 2, 2022
From: TRERE, PAOLO
To: MICROCHIP TECHNOLOGY INCORPORATED
Reel/Frame 059778/0262 →
RELEASE OF SECURITY INTEREST Recorded Mar 11, 2022
From: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: MICROCHIP TECHNOLOGY INCORPORATED; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION; MICROSEMI STORAGE SOLUTIONS, INC.
Reel/Frame 059363/0001 →
RELEASE OF SECURITY INTEREST Recorded Mar 10, 2022
From: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: MICROCHIP TECHNOLOGY INCORPORATED; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION; MICROSEMI STORAGE SOLUTIONS, INC.
Reel/Frame 059863/0400 →
RELEASE OF SECURITY INTEREST Recorded Mar 9, 2022
From: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: MICROCHIP TECHNOLOGY INCORPORATED; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION; MICROSEMI STORAGE SOLUTIONS, INC.
Reel/Frame 059358/0335 →
RELEASE OF SECURITY INTEREST Recorded Mar 9, 2022
From: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: MICROCHIP TECHNOLOGY INCORPORATED; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION; MICROSEMI STORAGE SOLUTIONS, INC.
Reel/Frame 059357/0823 →
RELEASE OF SECURITY INTEREST Recorded Feb 28, 2022
From: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
To: MICROCHIP TECHNOLOGY INCORPORATED; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION; MICROSEMI STORAGE SOLUTIONS, INC.
Reel/Frame 059264/0384 →
GRANT OF SECURITY INTEREST IN PATENT RIGHTS Recorded Nov 19, 2021
From: MICROCHIP TECHNOLOGY INCORPORATED; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION; MICROSEMI STORAGE SOLUTIONS, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 058214/0238 →
GRANT OF SECURITY INTEREST IN PATENT RIGHTS Recorded Nov 19, 2021
From: MICROCHIP TECHNOLOGY INCORPORATED; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION; MICROSEMI STORAGE SOLUTIONS, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 058214/0625 →
GRANT OF SECURITY INTEREST IN PATENT RIGHTS Recorded Nov 19, 2021
From: MICROCHIP TECHNOLOGY INCORPORATED; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION; MICROSEMI STORAGE SOLUTIONS, INC.
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 058214/0380 →
SECURITY INTEREST Recorded Jun 4, 2021
From: MICROCHIP TECHNOLOGY INCORPORATED; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION; MICROSEMI STORAGE SOLUTIONS, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 057935/0474 →
SECURITY INTEREST Recorded Dec 24, 2020
From: MICROCHIP TECHNOLOGY INCORPORATED; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION; MICROSEMI STORAGE SOLUTIONS, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 055671/0612 →