IP Library Granted Patent US 11,876,895
Granted Patent B2
US 11,876,895 · App. 17/941,909 · Granted Jan 16, 2024

Secure installation of application keys

Inventors: Jean-Bernard Fischer (Cheseaux-sur-Lausanne, CH); Nicolas Fischer (Cheseaux-sur-Lausanne, CH); Fabien Gremaud (Cheseaux-sur-Lausanne, CH); Karine Villegas (Cheseaux-sur-Lausanne, CH)
Assignee: NAGRAVISION SARL
H04L9/0822H04L9/083H04L9/0825H04L9/14
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,876,895
App. No.
17/941,909
Granted
Jan 16, 2024
Kind
B2
Abstract

The present disclosure includes methods, devises and systems for preparing and installing one or more application keys owned by application owners in a remote device. The present disclosure further proposes methods, devices and systems for secure installation of subsequent application keys on a device utilising corresponding key derivation functions to associate an application with a respective policy and identifier using significantly Imv bandwidth for transfer of keys for execution of the respective application on the device.

Claims (38)

1. A method of creating an application key for use in a remote device, the method comprising:

transmitting a device public key to an application owner, wherein the device public key corresponds to a device private key stored on and specific to the remote device;

receiving an encrypted application key for an application associated with the application owner, the encrypted application key encrypted with the device public key; and

processing the received encrypted application key with a symmetric device key, wherein the symmetric device key is specific to and stored on the remote device,

wherein the app key is created at a key management system.

2. The method according to claim 1 , wherein processing the received encrypted application key further comprises encrypting the encrypted application key with a symmetric device encryption key.

3. The method according to claim 1 , wherein the received encrypted application key further comprises adding or associating an application policy or identifier for the respective application to the encrypted application key.

4. The method according to claim 1 , wherein processing the received encrypted application key further comprises signing the encrypted application key with a symmetric device signature key.

5. The method according to claim 3 , further comprising sending a key seed for generating a transport key for installing a second application key on the remote device wherein the key seed is generated using an application policy or an application identifier for the second application.

6. The method according to claim 1 , further comprising:

sending a key seed for generating a transport key for installation of a further application key on the remote device from the application owner, wherein the key seed is generated using an application policy or application identifier for a second application with a key derivation function stored at the key management system and remote device, wherein

processing the received encrypted application key further comprises

encrypting the encrypted application key with a symmetric device encryption key,

adding or associating the application policy or identifier for the second application to the encrypted application key, and

signing the encrypted application key with a symmetric device signature key, the symmetric device encryption key being different from the symmetric device signature key.

7. A method of installing an application key in a remote device, the method comprising:

receiving a device public key from a key management system, the device public key corresponding to a device private key stored on and specific to the device;

transmitting an encrypted application key associated with an application, the encrypted application key being encrypted with the device public key, to the key management system;

receiving the encrypted application key from the key management system, wherein the encrypted application key has been processed by the key management system with a symmetric device key and includes an application policy and identifier of the application by the key management system, wherein the symmetric device key is specific to and stored on the remote device; and

transmitting the encrypted application key to the remote device.

8. The method according to claim 7 , further comprising

receiving from the key management system a key seed, wherein the key seed is generated based on an application policy associated with the application key and application identifier using a key derivation function;

generating a transport key using a second key derivation function using the key seed and the application key, wherein the second key derivation function is also available at the remote device;

encrypting a second application key with the transport key; and

sending the encrypted application key to the remote device for installation.

9. A device for executing an application using one or more application keys, the device comprising:

a memory storing a private device key of a device public, private key pair, and a symmetric device key; and

a processor configured to:

receive an encrypted application key of an application,

process the received encrypted application key using the symmetric device key, and

decrypt the processed encrypted application key using the private device key.

10. The device according to claim 9 , wherein the processor is further configured to decrypt the encrypted application key with a symmetric device encryption key.

11. The device according to claim 9 , wherein the processor is further configured to decrypt an encrypted application policy and identifier with a symmetric device encryption key for enabling execution of the application on the device based on the decrypted application policy.

12. The device according to claim 9 , wherein the processor is further configured to verify a signature of the encrypted application key with a symmetric device signature key.

13. The device according to claim 9 , wherein the processor is configured to

receive a second application key encrypted with a transport key,

compute the transport key using a key derivation function applied to the application key and the output of a second key derivation function, wherein the output of the second key derivation function is computed by applying the second key derivation function to an application policy and identifier associated with the application key, and

decrypt the second application key with the transport key.

Assignments (2)
CHANGE OF NAME Recorded Aug 25, 2023
From: NAGRAVISION SA
To: NAGRAVISION SÀRL
Reel/Frame 064702/0471 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 12, 2022
From: FISCHER, JEAN-BERNARD; FISCHER, NICOLAS; GREMAUD, FABIEN; VILLEGAS, KARINE
To: NAGRAVISION S.A.
Reel/Frame 061060/0001 →
Priority Claims (1)
EP 17306983 · Dec 29, 2017 · regional
Continuity (2)
Continuation 16958104
Related Publication 20230070124A1 · Mar 9, 2023
Cited By (3)
US 12,316,757 US 12,328,305 US 12,598,067