IP Library Granted Patent US 11,568,091
Granted Patent B2
US 11,568,091 · App. 17/149,956 · Granted Jan 31, 2023

Method and system for integrity protected distributed ledger for component certificate attestation

Inventors: Charles D. Robison (Buford, GA); Vaibhav Soni (Austin, TX)
Assignee: Dell Products L.P.
G06F21/73H04L9/0643H04L9/3268H04L9/50
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,568,091
App. No.
17/149,956
Granted
Jan 31, 2023
Kind
B2
Abstract

A system, method, and computer-readable medium are disclosed for attesting component certificates to particular devices. An enterprise hosted integrity protected distributed ledger, such as a block chain, is provided to publish component certificates. Component vendors are provided authorization tokens to publish their component certificates. Manifests are generated by the original equipment manufacturer (OEM) that includes vendor component identifiers. End users discover the distributed ledger through a verification mechanism, and the component certificates are retrieved from the distributed ledger.

Claims (38)

1. A computer-implementable method for attesting component certificates to particular devices comprising:

configuring an enterprise hosted integrity protected distributed ledger to publish certificates including the component certificates;

providing authorization tokens that allow for component certificates to be published to the enterprise hosted integrity protected distributed ledger;

generating a manifest for a device that includes component identifiers and certificate identifiers used to access the component certificates on the distributed ledger;

providing a verification mechanism that discovers the enterprise hosted integrity protected distributed ledger; and

retrieving the component certificates from the enterprise hosted integrity protected distributed ledger using the certificate identifiers in the manifest.

2. The method of claim 1 , wherein the enterprise hosted integrity protected distributed ledger is a block chain.

3. The method of claim 1 , wherein the manifest further includes unique component information comprising one or more of serial numbers, service tags, unique identifiers, and lot number.

4. The method of claim 1 further comprising using a high security module to secure component certificates.

5. The method of claim 1 , wherein the verification mechanism includes a mobile application on an end user device.

6. The method of claim 1 , wherein the retrieving of the component certificates includes using decryption keys to access the enterprise hosted integrity protected distributed ledger.

7. The method of claim 1 further comprising publishing a signed device platform certificate to the enterprise hosted integrity protected distributed ledger.

8. A system comprising:

a processor;

a data bus coupled to the processor; and

a non-transitory, computer-readable storage medium embodying computer program code, the non-transitory, computer-readable storage medium being coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the processor and configured for:

configuring an enterprise hosted integrity protected distributed ledger to publish certificates including the component certificates;

providing authorization tokens that allow for component certificates to be published to the enterprise hosted integrity protected distributed ledger;

generating a manifest for a device that includes component identifiers and certificate identifiers used to access the component certificates on the distributed ledger;

providing a verification mechanism that discovers the enterprise hosted integrity protected distributed ledger; and

retrieving the component certificates from the enterprise hosted integrity protected distributed ledger using the certificate identifiers in the manifest.

9. The system of claim 8 , wherein the enterprise hosted integrity protected distributed ledger is a block chain.

10. The system of claim 8 , wherein the manifest further includes unique component information comprising one or more of serial numbers, service tags, unique identifiers, and lot number.

11. The system of claim 8 further comprising using a high security module to secure component certificates.

12. The system of claim 8 , wherein the verification mechanism includes a mobile application on an end user device.

13. The system of claim 8 , wherein the retrieving of the component certificates includes using decryption keys to access the enterprise hosted integrity protected distributed ledger.

14. The system of claim 8 further comprising publishing a signed device platform certificate to the enterprise hosted integrity protected distributed ledger.

15. A non-transitory, computer-readable storage medium embodying computer program code, the computer program code comprising computer executable instructions configured to:

configure an enterprise hosted integrity protected distributed ledger to publish certificates including the component certificates;

provide authorization tokens for the component certificates to be published to the enterprise hosted integrity protected distributed ledger;

generate a manifest for a device that includes component identifiers and certificate identifiers used to access the component certificates on the distributed ledger;

provide a verification mechanism that discovers the enterprise hosted integrity protected distributed ledger; and

retrieve the component certificates from the enterprise hosted integrity protected distributed ledger using the certificate identifiers in the manifest.

16. The non-transitory, computer-readable storage medium of claim 15 , wherein the manifest further includes unique component information comprising one or more of serial numbers, service tags, unique identifiers, and lot number.

17. The non-transitory, computer-readable storage medium of claim 15 further comprising using a high security module to secure component certificates.

18. The non-transitory, computer-readable storage medium of claim 15 , wherein the verification mechanism includes a mobile application on an end user device.

19. The non-transitory, computer-readable storage medium of claim 15 , wherein the retrieving of the component certificates includes using decryption keys to access the enterprise hosted integrity protected distributed ledger.

20. The non-transitory, computer-readable storage medium of claim 15 further comprising publishing a signed device platform certificate to the enterprise hosted integrity protected distributed ledger.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (055479/0342) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0460 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (055479/0051) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0663 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056136/0752) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0771 →
RELEASE OF SECURITY INTEREST AT REEL 055408 FRAME 0697 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0553 →
SECURITY INTEREST Recorded Mar 3, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056136/0752 →
SECURITY INTEREST Recorded Mar 3, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 055479/0051 →
SECURITY INTEREST Recorded Mar 3, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 055479/0342 →
SECURITY AGREEMENT Recorded Feb 25, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 055408/0697 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 15, 2021
From: ROBISON, CHARLES D.; SONI, VAIBHAV
To: DELL PRODUCTS L.P.
Reel/Frame 054931/0263 →
Continuity (1)
Related Publication 20220229938A1 · Jul 21, 2022