IP Library Patent Application 19067028
Patent Application
App. No. 19/067,028

Software Version-Aware Encryption Key For Secure Mutable Partitions

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
19/067,028
Abstract

Described herein are systems for software version-aware encryption key for secure mutable partitions. For example, some methods include verifying a digital signature of a header for an application image, wherein the header includes a hash of the application image; generating an encryption key based on the hash; encrypting, using the encryption key, data to be written to a writable partition that is mounted with a filesystem of the application image; and decrypting, using the encryption key, data read from the writable partition.

Claims (38)

1 . An unmanned aerial vehicle comprising:

a processing apparatus configured to:

verify a digital signature of a header for an application image, wherein the header includes a hash of the application image;

generate an encryption key based on the hash; and

decrypt, using the encryption key, data read from an overlay mount of a filesystem of the application image.

2 . The unmanned aerial vehicle of claim 1 , wherein the header includes a version string for the application image and the encryption key is generated based on the version string for the application image.

3 . The unmanned aerial vehicle of claim 1 , wherein the processing apparatus is configured to:

input a context string that includes the hash to a trusted operating system device that is configured to apply a key generation algorithm to determine the encryption key based on the context string and a fuse key of the trusted operating system device.

4 . The unmanned aerial vehicle of claim 3 , wherein the context string includes at least one of an overlay name, a slot number, or a lock state for the overlay mount.

5 . The unmanned aerial vehicle of claim 1 , wherein the hash is a root hash of a hash tree.

6 . The unmanned aerial vehicle of claim 1 , wherein the processing apparatus is configured to:

encrypt, using the encryption key, data to be written to the overlay mount.

7 . The unmanned aerial vehicle of claim 1 , wherein the processing apparatus is configured to:

detect corruption of the overlay mount; and

reformat the overlay mount responsive to the detection of corruption.

8 . A method comprising:

verifying a digital signature of a header for an application image, wherein the header includes a hash of the application image;

generating an encryption key based on the hash; and

decrypting, using the encryption key, data read from a writable partition that is mounted with a filesystem of the application image.

9 . The method of claim 8 , wherein the header includes a version string for the application image and the encryption key is generated based on the version string for the application image.

10 . The method of claim 8 , wherein generating the encryption key comprises:

inputting a context string that includes the hash to a trusted operating system device that is configured to apply a key generation algorithm to determine the encryption key based on the context string and a fuse key of the trusted operating system device.

11 . The method of claim 10 , wherein the context string includes at least one of an overlay name, a slot number, or a lock state for the writable partition.

12 . The method of claim 8 , wherein the hash is a root hash of a hash tree.

13 . The method of claim 8 , wherein the writable partition is an overlay mount of the filesystem of the application image.

14 . The method of claim 8 , comprising:

encrypting, using the encryption key, data to be written to the writable partition.

15 . The method of claim 8 , comprising:

detecting corruption of the writable partition; and

reformatting the writable partition responsive to the detection of corruption.

16 . A system for secure data storage comprising:

a data storage device comprising a read-only partition storing signature-verified software, and a writable partition configured to store cache data;

a trusted execution environment configured to: store a device-specific secret key, generate an identifier string for a software version, and derive an encryption key based on the device-specific secret key and the identifier string; and

a processor configured to: encrypt data written to the writable partition using the derived encryption key, integrate the writable partition with the read-only partition in a filesystem structure, detect corruption of the writable partition upon software version change, and reformat the writable partition responsive to the detection of corruption.

17 . The system of claim 16 , wherein the signature-verified software comprises a secure bootchain configured to verify digital signatures of successive boot stages before execution.

18 . The system of claim 16 , wherein the writable partition is mounted over the read-only partition using overlay mounting.

19 . The system of claim 16 , wherein the trusted execution environment comprises a hardware-isolated secure processing region.

20 . The system of claim 16 , wherein the identifier string comprises a random value uniquely associated with the software version.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 11, 2025
From: ZHANG, JERRY XIRI; KUBISIAK, BRIAN DAVID; MALLERY, ALEX
To: SKYDIO, INC.
Reel/Frame 070808/0497 →