IP Library › Granted Patent US 8,909,929
Granted Patent B2
US 8,909,929 · App. 13/485,678 · Granted Dec 9, 2014

Stored public key validity registers for cryptographic devices and systems

Inventors: Balaji Badam (Colorado Springs, CO); Kerry Maletsky (Monument, CO); David Durant (Colorado Springs, CO)
Assignee: Atmel Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,909,929
App. No.
13/485,678
Granted
Dec 9, 2014
Kind
B2
Abstract

Systems and techniques for performing cryptographic operations based on public key validity registers are described. A described system includes a controller and a memory structure to store one or more public keys. The memory structure includes one or more validity registers that respectively correspond to the one or more public keys. The controller has exclusive write access to the validity register. The controller can be configured to perform an authentication of a public key, write an authentication status value to the corresponding validity register based on a result of the authentication, and perform one or more cryptographic operations using the public key that are conditional on the validity register indicating an authenticated status for the public key.

Claims (55)

1. An apparatus comprising:

a memory structure to store a public key, wherein the memory structure comprises a validity register that corresponds to the public key; and

a controller configured to perform an authentication of the public key, write an authentication status value to the validity register based on a result of the authentication, the authentication status value corresponding to one of an authenticated status for the public key or an unauthenticated status for the public key, and perform one or more cryptographic operations using the public key that are conditional on the validity register indicating the authenticated status for the public key, wherein the apparatus has exclusive write access to the validity register,

wherein the validity register comprises two or more bits, and the controller is configured to write the authentication status value to each of the two or more bits, and

wherein the controller is configured to read the two or more bits from the validity register to determine an authentication status for the public key based on at least one of whether a majority agreement of the two or more bits indicates the authenticated status for the public key or whether any bit of the two or more bits indicates the unauthenticated status for the public key.

2. The apparatus of claim 1 , further comprising:

a host interface to communicate with a host, wherein the controller is configured to receive a command from the host via the host interface, the command indicating a cryptographic operation to be performed by the apparatus using the public key.

3. The apparatus of claim 2 , wherein the controller is configured to send a failure code to the host in response to the command if the validity register indicates the unauthenticated status for the public key.

4. The apparatus of claim 1 , further comprising:

a host interface to communicate with a host, wherein the controller is configured to grant the host read-only access to the validity register.

5. The apparatus of claim 1 , wherein the controller is configured to write an unauthenticated status value to the validity register in response to changing the public key.

6. The apparatus of claim 1 , further comprising:

an integrated circuit that comprises the memory structure and the controller.

7. The apparatus of claim 1 , wherein the memory structure contains a non-volatile memory, wherein the memory structure stores a plurality of public keys and corresponding validity registers in the non-volatile memory.

8. The apparatus of claim 1 , wherein the memory structure stores a first public key associated with a first validity register and a first parent key pointer and a second public key associated with a second validity register and a second parent key pointer,

wherein the second parent key pointer of the second public key is a multi-bit pointer to the first public key, and

wherein the controller is configured to write an unauthenticated status value to the second validity register in response to updating the first public key, the unauthenticated status value corresponding to an unauthenticated status for the second key.

9. The apparatus of claim 8 , wherein the memory structure is configured to store a first key configuration slot for the first public key, the first key configuration slot including at least one of an access permission list to allow or deny access or use of the first public key, a value indicating that the first public key has to be authenticated prior to use, or one or more bits indicating a policy of whether a random nonce is required for an authentication of the first public key.

10. The apparatus of claim 8 , wherein the controller is configured to:

generate a nonce in response to receiving a nonce command from a host via a host interface in the controller;

generate, by using a hash function, a hash of the nonce and the second public key in response to receiving a command to authenticate the second public key from the host, the second public key being generated based on the first public key;

produce, by using a verification algorithm, an authentication result based on the hash and the first public key; and

write a second authentication status value for the second public key to the second validity register based on the authentication result.

11. A method comprising:

retrieving a public key stored in a memory structure;

performing an authentication of the public key to determine an authentication status value, the authentication status value corresponding to one of an authenticated status for the public key or an unauthenticated status for the public key;

writing the authentication status value to a validity register of the memory structure that corresponds to the public key; and

performing one or more cryptographic operations using the public key that are conditional on the validity register indicating an authenticated status for the public key,

wherein the validity register comprises two or more bits,

wherein writing the authentication status value comprises writing the authentication status value to each of the two or more bits, and

wherein performing one or more cryptographic operations comprises reading the two or more bits from the validity register to determine the authentication status for the public key based on at least one of whether a majority agreement of the two or more bits indicates the authenticated status for the public key or whether any bit of the two or more bits indicates the unauthenticated status for the public key.

12. The method of claim 11 , further comprising:

receiving a command from a host, the command indicating a cryptographic operation to be performed using the public key.

13. The method of claim 12 , wherein performing one or more cryptographic operations comprises sending a failure code to the host in response to the command if the validity register indicates the unauthenticated status for the public key.

14. The method of claim 11 , further comprising:

writing an unauthenticated status value to the validity register in response to changing the public key.

15. The method of claim 11 , further comprising:

generating a nonce in response to receiving a nonce command from a host via a host interface;

generating, by using a hash function, a hash of the nonce and a second public key in response to receiving a command to authenticate the second public key from the host, the second public key being generated based on the public key;

producing, by using a verification algorithm, an authentication result based on the hash and the public key; and

writing a second authentication status value for the second public key to a second validity register for the second public key based on the authentication result.

16. A system comprising:

a host; and

a cryptographic device that comprises (i) a host interface to communicate with the host and (ii) a memory structure to store a public key and a validity register that corresponds to the public key, wherein the cryptographic device has exclusive write access to the validity register,

wherein the cryptographic device is configured to (i) perform an authentication of the public key, (ii) write an authentication status value to the validity register based on a result of the authentication, the authentication status value corresponding to one of an authenticated status for the public key or an unauthenticated status for the public key, (iii) receive a command from the host via the host interface, the command indicating a cryptographic operation to be performed by the cryptographic device using the public key, (iv) perform the cryptographic operation based on checking the validity register to determine the authentication status for the public key, and (v) send a failure code to the host in response to the command based on the validity register indicating the unauthenticated status for the public key,

wherein the validity register comprises two or more bits, and the cryptographic device is configured to write the authentication status value to each of the two or more bits, and

wherein the cryptographic device is configured to read the two or more bits from the validity register to determine an authentication status for the public key based on at least one of whether a majority agreement of the two or more bits indicates the authenticated status for the public key or whether any bit of the two or more bits indicates the unauthenticated status for the public key.

17. The system of claim 16 , wherein the cryptographic device is configured to grant the host read-only access to the validity register.

18. The system of claim 16 , wherein host is configured to load the public key in to the cryptographic device, wherein the cryptographic device is configured to write an unauthenticated status value to the validity register in response to the public key being loaded.

19. The system of claim 16 , wherein the memory structure stores a plurality of public keys, and wherein the memory structure comprises validity registers that respectively correspond to the public keys.

20. The system of claim 16 , wherein the cryptographic device is configured to:

generate a nonce in response to receiving a nonce command from the host via the host interface;

generate, by using a hash function, a hash of the nonce and a second public key in response to receiving a command to authenticate the second public key from the host, the second public key being generated based on the public key;

produce, by using a verification algorithm, an authentication result based on the hash and the public key; and

write a second authentication status value for the second public key to a second validity register for the second public key based on the authentication result.

Assignments (17)
RELEASE OF SECURITY INTEREST Recorded Mar 14, 2022
From: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: MICROCHIP TECHNOLOGY INCORPORATED; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION; MICROSEMI STORAGE SOLUTIONS, INC.
Reel/Frame 060894/0437 →
RELEASE OF SECURITY INTEREST Recorded Mar 11, 2022
From: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: MICROCHIP TECHNOLOGY INCORPORATED; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION; MICROSEMI STORAGE SOLUTIONS, INC.
Reel/Frame 059363/0001 →
RELEASE OF SECURITY INTEREST Recorded Mar 10, 2022
From: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: MICROCHIP TECHNOLOGY INCORPORATED; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION; MICROSEMI STORAGE SOLUTIONS, INC.
Reel/Frame 059863/0400 →
RELEASE OF SECURITY INTEREST Recorded Mar 9, 2022
From: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: MICROCHIP TECHNOLOGY INCORPORATED; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION; MICROSEMI STORAGE SOLUTIONS, INC.
Reel/Frame 059358/0001 →
RELEASE OF SECURITY INTEREST Recorded Feb 28, 2022
From: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
To: ATMEL CORPORATION
Reel/Frame 059262/0105 →
RELEASE OF SECURITY INTEREST Recorded Feb 25, 2022
From: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
To: MICROCHIP TECHNOLOGY INCORPORATED; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION; MICROSEMI STORAGE SOLUTIONS, INC.
Reel/Frame 059333/0222 →
SECURITY INTEREST Recorded Jun 4, 2021
From: MICROCHIP TECHNOLOGY INCORPORATED; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION; MICROSEMI STORAGE SOLUTIONS, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 057935/0474 →
SECURITY INTEREST Recorded Dec 24, 2020
From: MICROCHIP TECHNOLOGY INCORPORATED; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION; MICROSEMI STORAGE SOLUTIONS, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 055671/0612 →
SECURITY INTEREST Recorded Jun 5, 2020
From: MICROCHIP TECHNOLOGY INC.; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION; MICROSEMI STORAGE SOLUTIONS, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION
Reel/Frame 053468/0705 →
RELEASE OF SECURITY INTEREST Recorded May 30, 2020
From: JPMORGAN CHASE BANK, N.A, AS ADMINISTRATIVE AGENT
To: MICROCHIP TECHNOLOGY INC.; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION; MICROSEMI STORAGE SOLUTIONS, INC.
Reel/Frame 053466/0011 →
SECURITY INTEREST Recorded Apr 24, 2020
From: MICROCHIP TECHNOLOGY INC.; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION; MICROSEMI STORAGE SOLUTIONS, INC.
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 053311/0305 →
SECURITY INTEREST Recorded Sep 18, 2018
From: MICROCHIP TECHNOLOGY INCORPORATED; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION; MICROSEMI STORAGE SOLUTIONS, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 047103/0206 →
SECURITY INTEREST Recorded Jun 25, 2018
From: MICROCHIP TECHNOLOGY INCORPORATED; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION; MICROSEMI STORAGE SOLUTIONS, INC.
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 046426/0001 →
SECURITY INTEREST Recorded Feb 10, 2017
From: ATMEL CORPORATION
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 041715/0747 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL Recorded Apr 7, 2016
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: ATMEL CORPORATION
Reel/Frame 038376/0001 →
PATENT SECURITY AGREEMENT Recorded Jan 3, 2014
From: ATMEL CORPORATION
To: MORGAN STANLEY SENIOR FUNDING, INC. AS ADMINISTRATIVE AGENT
Reel/Frame 031912/0173 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 13, 2012
From: BADAM, BALAJI; MALETSKY, KERRY; DURANT, DAVID
To: ATMEL CORPORATION
Reel/Frame 028955/0399 →
Continuity (1)
Related Publication 20130326219A1 · Dec 5, 2013