IP Library Granted Patent US 9,129,536
Granted Patent B2
US 9,129,536 · App. 13/601,993 · Granted Sep 8, 2015

Circuit for secure provisioning in an untrusted environment

Inventors: Thomas E. Tkacik (Phoeniz, AZ); Lawrence L. Case (Austin, TX); Carlin R. Covey (Tempe, AZ); David H. Hartley (Seaview Downs, AU); Rodney D. Ziolkowski (Austin, TX)
Assignee: Freescale Semiconductor, Inc.
G09C1/00H04L9/0866G06F21/57H04L9/3247H04L2209/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,129,536
App. No.
13/601,993
Granted
Sep 8, 2015
Kind
B2
Abstract

Embodiments of electronic circuits enable security of sensitive data in a design and manufacturing process that includes multiple parties. An embodiment of an electronic circuit can include a private key embedded within the electronic circuit that is derived from a plurality of components including at least one component known only to the electronic circuit and at least one immutable value cryptographically bound into messages and residing on the electronic circuit, public key generation logic that generates a public key to match the private key, and message signing logic that signs messages with the private key.

Claims (38)

1. A first electronic circuit comprising:

first circuitry configured to store a message signing private key that is inaccessible external to the first electronic circuit;

second circuitry configured to store one or more immutable domain parameters;

third circuitry configured to store an immutable trust anchor that is derived from a code signing public key;

private key derivation logic configured to generate the message signing private key using a combination of the trust anchor and the one or more immutable domain parameters;

public key generation logic configured to generate a message signing public key to match the message signing private key;

secure boot logic configured to cause the private key derivation logic to generate the message signing private key, store the message signing private key in the first circuitry, derive a value from the code signing public key, compare the value derived from the code signing public key with the trust anchor stored in the third circuitry, and verify a signature of signed provisioning code using the code signing public key, wherein the signed provisioning code includes provisioning code and the signature;

transfer logic that receives a challenge message from a remote computer system, wherein the remote computer system has a message signing public key that was generated by a second electronic circuit, wherein the message signing public key was generated by the second electronic circuit using a message signing private key that was generated using the trust anchor and the one or more immutable domain parameters, which also are stored in the second electronic circuit, and wherein the message signing private key used by the second electronic circuit is the same as the message signing private key generated by the first electronic circuit; and

message signing logic that prepares, based on the challenge message, a signed response message using the message signing private key, and

wherein the transfer logic is further configured to send the signed response message to the remote computer system, and to receive sensitive provisioning information from the remote computer system when the remote computer system is able to verify the signed response message using the message signing public key.

2. The electronic circuit according to claim 1 , further comprising:

circuitry configured to store an immutable message tag that the message signing logic incorporates into the signed response message before the message signing logic signs the signed response message.

3. The electronic circuit according to claim 2 , further comprising:

a message tag register configured to be locked against modification after storing the message tag;

circuitry configured to store one or more immutable message tag components; and

message tag derivation logic configured to derive the message tag from the message tag components and to store the message tag in the message tag register.

4. The electronic circuit according to claim 3 , wherein:

the message signing logic is configured to cryptographically bind messages to the trust anchor by including the trust anchor as one of the message tag components.

5. The electronic circuit according to claim 3 , further comprising:

message tag component storage that can be provisioned with message tag components and protected against further modification, including one-time programmable fuses for a unique identifier or serial number, or the trust anchor, where the message tag components can be either common or specific to copies of the first electronic circuit.

6. The electronic circuit according to claim 3 , wherein:

the message derivation logic is configured to access the message tag components directly.

7. The electronic circuit according to claim 3 , wherein:

the secure boot logic or other logic of the first electronic circuit is configured to copy the message tag components to the message tag derivation logic.

8. The electronic circuit according to claim 1 , further comprising:

a private key register configured to store the message signing private key, wherein the private key register is configured to be locked against modification after storing the message signing private key, and the private key register is readable only by the public key generation logic and the message signing logic; and

circuitry configured to store one or more immutable private key components, wherein at least one of the one or more immutable private key components is secret.

9. The electronic circuit according to claim 8 , wherein:

the message signing logic is configured to cryptographically bind messages to the trust anchor by including the trust anchor as one of the private key components.

10. The electronic circuit according to claim 8 , further comprising:

circuitry configured to permanently store independent private key components, wherein the independent private key components are selected from a logic secret value embedded within the private key derivation logic or other electronic circuit logic, a read-only memory (ROM) secret value masked in ROM.

11. The electronic circuit according to claim 8 , further comprising:

private key component storage configured to be provisioned with independent private key components and protected against further modification, wherein the private key component storage includes one-time programmable fuses for a secret value or the trust anchor, and wherein the first electronic circuit, once provisioned with the private key components are either common to or specific to copies of the first electronic circuit.

12. The electronic according to claim 8 , wherein:

the private key derivation logic is further configured to access the private key components directly.

13. The electronic circuit according to claim 8 , wherein:

the secure boot logic or other logic of the first electronic circuit is configured to copy the private key components to the private key derivation logic; and

the private key derivation logic is configured to prevent further access to the private key components.

Assignments (22)
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 11759915 AND REPLACE IT WITH APPLICATION 11759935 PREVIOUSLY RECORDED ON REEL 040925 FRAME 0001. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Feb 17, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NXP, B.V. F/K/A FREESCALE SEMICONDUCTOR, INC.
Reel/Frame 052917/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 11759915 AND REPLACE IT WITH APPLICATION 11759935 PREVIOUSLY RECORDED ON REEL 040928 FRAME 0001. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Jan 17, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NXP B.V.
Reel/Frame 052915/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 11759915 AND REPLACE IT WITH APPLICATION 11759935 PREVIOUSLY RECORDED ON REEL 037486 FRAME 0517. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT AND ASSUMPTION OF SECURITY INTEREST IN PATENTS. Recorded Dec 10, 2019
From: CITIBANK, N.A.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 053547/0421 →
RELEASE OF SECURITY INTEREST Recorded Sep 10, 2019
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NXP B.V.
Reel/Frame 050744/0097 →
CORRECTIVE ASSIGNMENT TO CORRECT THE TO CORRECT THE APPLICATION NO. FROM 13,883,290 TO 13,833,290 PREVIOUSLY RECORDED ON REEL 041703 FRAME 0536. ASSIGNOR(S) HEREBY CONFIRMS THE THE ASSIGNMENT AND ASSUMPTION OF SECURITY INTEREST IN PATENTS.. Recorded Feb 20, 2019
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: SHENZHEN XINGUODU TECHNOLOGY CO., LTD.
Reel/Frame 048734/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENTS 8108266 AND 8062324 AND REPLACE THEM WITH 6108266 AND 8060324 PREVIOUSLY RECORDED ON REEL 037518 FRAME 0292. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT AND ASSUMPTION OF SECURITY INTEREST IN PATENTS. Recorded Feb 1, 2017
From: CITIBANK, N.A.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 041703/0536 →
CORRECTIVE ASSIGNMENT TO CORRECT THE NATURE OF CONVEYANCE PREVIOUSLY RECORDED AT REEL: 040652 FRAME: 0241. ASSIGNOR(S) HEREBY CONFIRMS THE MERGER AND CHANGE OF NAME. Recorded Jan 5, 2017
From: FREESCALE SEMICONDUCTOR, INC.
To: NXP USA, INC.
Reel/Frame 041260/0850 →
MERGER Recorded Nov 8, 2016
From: FREESCALE SEMICONDUCTOR, INC.
To: NXP USA, INC.
Reel/Frame 040652/0241 →
RELEASE OF SECURITY INTEREST Recorded Nov 7, 2016
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NXP B.V.
Reel/Frame 040928/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 21, 2016
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NXP, B.V., F/K/A FREESCALE SEMICONDUCTOR, INC.
Reel/Frame 040925/0001 →
SUPPLEMENT TO THE SECURITY AGREEMENT Recorded Jun 16, 2016
From: FREESCALE SEMICONDUCTOR, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 039138/0001 →
ASSIGNMENT AND ASSUMPTION OF SECURITY INTEREST IN PATENTS Recorded Jan 13, 2016
From: CITIBANK, N.A.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 037518/0292 →
ASSIGNMENT AND ASSUMPTION OF SECURITY INTEREST IN PATENTS Recorded Jan 12, 2016
From: CITIBANK, N.A.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 037486/0517 →
PATENT RELEASE Recorded Dec 21, 2015
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: FREESCALE SEMICONDUCTOR, INC.
Reel/Frame 037357/0652 →
PATENT RELEASE Recorded Dec 21, 2015
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: FREESCALE SEMICONDUCTOR, INC.
Reel/Frame 037357/0633 →
PATENT RELEASE Recorded Dec 21, 2015
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: FREESCALE SEMICONDUCTOR, INC.
Reel/Frame 037357/0614 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 26, 2014
From: HARTLEY, DAVID H.; TKACIK, THOMAS E.; COVEY, CARLIN R.; CASE, LAWRENCE L.; ZIOLKOWSKI, RODNEY D.
To: FREESCALE SEMICONDUCTOR, INC., AUSTIN, TEXAS
Reel/Frame 033190/0570 →
SECURITY AGREEMENT Recorded Nov 6, 2013
From: FREESCALE SEMICONDUCTOR, INC.
To: CITIBANK, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 031591/0266 →
SECURITY AGREEMENT Recorded Jun 18, 2013
From: FREESCALE SEMICONDUCTOR, INC.
To: CITIBANK, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 030633/0424 →
SUPPLEMENT TO IP SECURITY AGREEMENT Recorded Apr 20, 2013
From: FREESCALE SEMICONDUCTOR, INC.
To: CITIBANK, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 030256/0625 →
SUPPLEMENT TO IP SECURITY AGREEMENT Recorded Apr 20, 2013
From: FREESCALE SEMICONDUCTOR, INC.
To: CITIBANK, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 030256/0544 →
SUPPLEMENT TO IP SECURITY AGREEMENT Recorded Apr 20, 2013
From: FREESCALE SEMICONDUCTOR, INC.
To: CITIBANK, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 030256/0471 →
Continuity (1)
Related Publication 20140068246A1 · Mar 6, 2014