IP Library Granted Patent US 10,042,997
Granted Patent B2
US 10,042,997 · App. 13/817,641 · Granted Aug 7, 2018

Authentication device and system

Inventor: Peter Maria Franciscus Rombouts (Sint-Katelijne-Waver, BE)
Assignee: NXP B.V.
G06F21/44G06F21/33H04L9/007H04L9/3247H04L9/3265H04L63/0823H04L2209/38
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,042,997
App. No.
13/817,641
Granted
Aug 7, 2018
Kind
B2
Abstract

A public key architecture ( 160 ) includes a dual certificate hierarchy which facilitates two independent authentication functions. One of the authentication functions authenticates an authentication device ( 164 ) to a verification device ( 166 ). The other authentication function authenticates a configuration device ( 162 ) to the authentication device ( 164 ). In some embodiments, the authentication process uses a lightweight certificate formed in conjunction with a lightweight signature scheme ( 370 ).

Claims (31)

1. An authentication method comprising:

storing a device authentication private key on an authentication device;

storing a device authentication public key certificate linked to a trusted authentication root certificate on the authentication device, wherein the device authentication private key and the device authentication public key certificate facilitate authentication of the authentication device to a verification device according to a device authentication protocol; and

storing a configuration root certificate on the authentication device, wherein the configuration root certificate facilitates authentication of a configuration device to the authentication device according to a configuration authentication protocol, wherein the device authentication protocol and the configuration authentication protocol use two separate certificate chains that both originate from a trusted party as a root of trust.

2. The authentication method of claim 1 , further comprising:

receiving, at the authentication device, a configuration public key certificate from the configuration device; and

determining, at the authentication device, whether the configuration device has a configuration private key corresponding to the configuration public key certificate.

3. The authentication method of claim 2 , further comprising:

receiving, at the authentication device, a configuration parameter from the configuration device; and

storing the configuration parameter on the authentication device in response to a determination at the authentication device that the configuration device has the configuration private key.

4. The authentication method of claim 3 , wherein the configuration parameter from the configuration device comprises identification information for the authentication device.

5. The authentication method of claim 3 , further comprising:

coupling the authentication device to a product, wherein the configuration parameter from the configuration device comprises product information corresponding to the product.

6. The authentication method of claim 2 , further comprising:

storing the configuration private key on the configuration device; and

storing the configuration public key certificate on the configuration device.

7. The authentication method of claim 2 , wherein the configuration public key certificate comprises a restriction.

8. The authentication method of claim 1 , further comprising:

receiving, at the authentication device, a plurality of configuration public key certificates within a configuration certificate chain associated with the configuration device, wherein the configuration root certificate stored on the authentication device forms the root of trust for the configuration certificate chain; and

verifying, at the authentication device, each of the configuration public key certificates within the configuration certificate chain.

9. The authentication method of claim 1 , wherein the verification device comprises a near field communication (NFC) electronic device.

10. The authentication method of claim 9 , wherein the NFC electronic device comprises:

a mobile telephone having NFC communication functionality.

11. An authentication device comprising:

a memory device configured to store data; and

processing logic coupled to the memory device, wherein the processing logic is configured to store, in the memory device, the following: a device authentication private key; a device authentication public key certificate linked to a trusted authentication root certificate; and a configuration root certificate; wherein the processing logic is further configured to use the device authentication private key and the device authentication public key certificate to facilitate authentication of the authentication device to a verification device according to a device authentication protocol; wherein the processing logic is further configured to use the configuration root certificate to facilitate authentication of a configuration device to the authentication device according to a configuration authentication protocol, wherein the device authentication protocol and the configuration authentication protocol use two separate certificate chains that both originate from a trusted party as a root of trust.

12. The authentication device of claim 11 , wherein the processing logic is further configured to receive a configuration parameter from the configuration device, and store the configuration parameter in the memory device in response to a determination at the authentication device that the configuration device has the configuration private key corresponding to the configuration public key certificate.

13. The authentication device of claim 12 , wherein the configuration parameter comprises identification information for the authentication device.

14. The authentication device of claim 12 , wherein the configuration parameter comprises product information corresponding to a product to which the authentication device is coupled.

15. A system comprising the authentication device of claim 12 , wherein the verification device comprises a near field communication (NFC) electronic device.

16. The system of claim 15 , wherein the NFC electronic device comprises a mobile telephone having NFC communication functionality.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12298143 PREVIOUSLY RECORDED ON REEL 042985 FRAME 0001. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded Oct 22, 2019
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 051029/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12298143 PREVIOUSLY RECORDED ON REEL 042762 FRAME 0145. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded Oct 22, 2019
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 051145/0184 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12298143 PREVIOUSLY RECORDED ON REEL 038017 FRAME 0058. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded Oct 22, 2019
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 051030/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12298143 PREVIOUSLY RECORDED ON REEL 039361 FRAME 0212. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded Oct 22, 2019
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 051029/0387 →
RELEASE OF SECURITY INTEREST Recorded Sep 10, 2019
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NXP B.V.
Reel/Frame 050745/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12681366 PREVIOUSLY RECORDED ON REEL 038017 FRAME 0058. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded May 9, 2017
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 042985/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12681366 PREVIOUSLY RECORDED ON REEL 039361 FRAME 0212. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded May 9, 2017
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 042762/0145 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12092129 PREVIOUSLY RECORDED ON REEL 038017 FRAME 0058. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded Jul 14, 2016
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 039361/0212 →
SECURITY AGREEMENT SUPPLEMENT Recorded Mar 7, 2016
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 038017/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 19, 2013
From: ROMBOUTS, PETER MARIA FRANCISCUS
To: NXP B.V.
Reel/Frame 029831/0872 →
Continuity (2)
Provisional Application 61375756 · Aug 20, 2010
Related Publication 20130290735A1 · Oct 31, 2013