IP Library Granted Patent US 9,628,270
Granted Patent B2
US 9,628,270 · App. 14/481,787 · Granted Apr 18, 2017

Cryptographically-verifiable attestation label

Inventor: Kambiz Kouladjie (Woodinville, WA)
Assignee: MICROSOFT TECHNOLOGY LICENSING, LLC
H04L9/0838G06F12/1408G06F21/36G06F21/44G06F2212/1052H04L2209/24
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,628,270
App. No.
14/481,787
Granted
Apr 18, 2017
Kind
B2
Abstract

A label includes a first readable object encoding a trust anchor. The trust anchor is encrypted with a cryptographic key. The attestation label further includes a second readable object encoding attestation service information and encoding an identification code. The identification code is encrypted using the trust anchor. The attestation label further includes a non-encoded representation of the identification code.

Claims (24)

1. An attestation label, comprising:

a first readable object encoding a trust anchor encrypted with a cryptographic key, the first readable object printed on the attestation label by a secure printer;

a second readable object encoding attestation service information and an identification code encrypted using the trust anchor, the second readable object printed on the attestation label by a non-secure printer; and

a non-encoded representation of the identification code.

2. The attestation label of claim 1 , wherein the first readable object is a visually-readable object and the second readable object is a visually-readable object.

3. The attestation label of claim 1 , wherein the identification code is encrypted using the trust anchor in combination with the identification code.

4. The attestation label of claim 1 , wherein the identification code is encrypted using the trust anchor in combination with a cryptographic salt.

5. The attestation label of claim 1 , wherein the attestation service information includes an address of an attestation service computing device, and wherein the attestation service computing device is configured to verify whether the attestation label is authentic.

6. The attestation label of claim 5 , wherein the trust anchor is selected from a set of available trust anchors, and wherein if any trust anchor of the set of available trust anchors becomes compromised, the attestation service is configured to indicate that attestation labels including the trust anchor are compromised.

7. The attestation label of claim 1 , wherein the first readable object is a first matrix barcode having a first color, and wherein the second readable object is a second matrix barcode having a second color different from the first color.

8. A device, comprising:

a housing including:

a first portion, and

a second portion coupled to the first portion to form a seam; and

an attestation label affixed across the seam, the attestation label including:

a first visually-readable object encoding a trust anchor encrypted with a cryptographic key, the first readable object printed on the attestation label by a secure printer;

a second readable object encoding attestation service information and an identification code encrypted using the trust anchor, the second readable object printed on the attestation label by a non-secure printer; and

a non-encoded representation of the identification code.

9. The device of claim 8 , wherein the identification code is encrypted using the trust anchor in combination with the identification code.

10. The device of claim 8 , wherein the attestation service information includes an address of an attestation service computing device, and wherein the attestation service computing device is configured to verify whether the visually-readable identification code is authentic.

11. The device of claim 8 , wherein the attestation service computing device is configured to determine an eligibility status of the device.

12. The device of claim 11 , wherein the trust anchor is selected from a set of available trust anchors, and wherein if any trust anchor of the set of available trust anchors becomes compromised, the attestation service computing device is configured to indicate that devices having attestation labels including the trust anchor are compromised.

13. The device of claim 8 , wherein the attestation service computing device is configured to provide a plurality of attributes of the device based on the visually-readable identification code.

14. The device of claim 8 , wherein the first visually-readable object is a first matrix barcode having a first color and the second visually-readable object is a second matrix barcode having a second color different from the first color.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 9, 2015
From: MICROSOFT CORPORATION
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 039025/0454 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 16, 2014
From: KOULADJIE, KAMBIZ
To: MICROSOFT CORPORATION
Reel/Frame 033965/0322 →
Continuity (1)
Related Publication 20160072626A1 · Mar 10, 2016