IP Library Granted Patent US 12,287,880
Granted Patent B2
US 12,287,880 · App. 17/903,064 · Granted Apr 29, 2025

Automatic root key and certificate update during firmware update procedure

Inventor: Oren Tanami (Ra'anana, IL)
Assignee: Nuvoton Technology Corp.
G06F21/572G06F8/65H04L9/0631H04L9/0891H04L9/3268
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,287,880
App. No.
17/903,064
Granted
Apr 29, 2025
Kind
B2
Abstract

A security device includes a memory and a processor. The memory is configured to store security firmware (FW), an active cryptographic key and an inactive cryptographic key. The active cryptographic key is associated with an active authentication certificate for authenticating the active cryptographic key, and the inactive cryptographic key is associated with an inactive authentication certificate for authenticating the inactive cryptographic key. The processor is configured to carry out security tasks by executing the security FW, and, provided a security-update indication is received, to (i) inactivate the active cryptographic key and the active authentication certificate, and (ii) activate the inactive cryptographic key and the inactive authentication certificate.

Claims (21)

1. A security device, comprising:

a memory, configured to store security firmware (FW), an active cryptographic key and an encrypted inactive cryptographic key, pre-provisioned in the memory during production of the security device, wherein the active cryptographic key is associated with an active authentication certificate for authenticating the active cryptographic key, and the inactive cryptographic key is associated with an inactive authentication certificate for authenticating the inactive cryptographic key; and

a processor, configured to carry out security tasks by executing the security FW, and, provided a security-update indication is received from a vendor of the security device, with a request to update the active cryptographic key, to (i) inactivate the active cryptographic key and the active authentication certificate, (ii) receive a decryption key from the vendor, (iii) decrypt the inactive cryptographic key, with the key received from the vendor and (iv) activate the inactive cryptographic key and the inactive authentication certificate.

2. The security device according to claim 1 , wherein the processor is further configured to authenticate the decrypted inactive cryptographic key.

3. The security device according to claim 1 , wherein the inactive cryptographic key is encrypted using Advanced Encryption Standard (AES) encryption.

4. The security device according to claim 1 , wherein the inactive cryptographic key comprises a Rivest-Shamir-Adleman (RSA) key.

5. The security device according to claim 1 , wherein the inactive cryptographic key comprises an Elliptic-Curve-Cryptography (ECC) key.

6. The security device according to claim 1 , wherein the security device is configured not to allow altering the active cryptographic key.

7. The security device according to claim 1 , wherein the processor is configured to activate the inactive cryptographic key as part of a complete update of the FW and the active cryptographic key.

8. The security device according to claim 1 , wherein the processor erases or overwrites the active cryptographic key, responsively to the security-update indication.

9. A method for firmware updating in a secure device, the method comprising:

storing in the secure device security firmware (FW), during production, an active cryptographic key and an encrypted inactive cryptographic key, wherein the active cryptographic key is associated with an active authentication certificate for authenticating the active cryptographic key, and the inactive cryptographic key is associated with an inactive authentication certificate for authenticating the inactive cryptographic key;

carrying out security tasks by executing the security FW; and

provided a security-update indication is received, from a vendor of the security device, with a request to update the active cryptographic key, inactivating the active cryptographic key and the active authentication certificate, receiving a decryption key from the vendor, decrypting the inactive cryptographic key with the key received from the vendor, and activating the inactive cryptographic key and the inactive authentication certificate.

10. The method according to claim 7 , further comprising authenticating the decrypted inactive cryptographic key.

11. The method according to claim 7 , wherein the inactive cryptographic key is encrypted using Advanced Encryption Standard (AES) encryption.

12. The method according to claim 9 , wherein the inactive cryptographic key comprises a Rivest-Shamir-Adleman (RSA) key.

13. The method according to claim 9 , wherein the inactive cryptographic key comprises an Elliptic-Curve-Cryptography (ECC) key.

14. The method according to claim 9 , wherein the secure device is configured not to allow altering the active cryptographic key.

15. The method according to claim 9 , comprising updating the FW with the activation of the inactive cryptographic key.

16. The method according to claim 9 , further comprising erasing or overwriting the active cryptographic key, responsively to the security-update indication.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 7, 2022
From: TANAMI, OREN
To: NUVOTON TECHNOLOGY CORPORATION
Reel/Frame 061008/0183 →
Continuity (1)
Related Publication 20240080206A1 · Mar 7, 2024
References Cited (13)
US 8560823B1 · Aytek · 2013 [cited by examiner]
US 9325708B2 · Koyun et al. · 2016 [cited by applicant]
US 9503431B2 · Chen et al. · 2016 [cited by applicant]
US 10009179B2 · Acar et al. · 2018 [cited by applicant]
US 11416639B2 · Tanami et al. · 2022 [cited by applicant]
US 20050021968A1 · Zimmer · 2005 [cited by examiner]
US 20050138374A1 · Zheng et al. · 2005 [cited by applicant]
US 20090119785A1 · Challener et al. · 2009 [cited by applicant]
US 20120151199A1 · Shriver · 2012 [cited by examiner]
EP 1967979A2 · 2008 [cited by applicant]
WO 2009070339A1 · 2009 [cited by applicant]
Arthur et al., “A Practical Guide to TPM 2.0—Using the Trusted Platform Module in the New Age of Security,” ApressOpen, Apress Media, LLC, pp. 1-375, year 2015. [cited by applicant]
“Trusted Platform Module (TPM)—Summary,” version 04292008, White Paper by Trusted Computing Group (TCG), pp. 1-3, Apr. 29, 2008, as downloaded from https://trustedcomputinggroup.org/resource/trusted-platform-module-tpm-… [cited by applicant]