IP Library Granted Patent US 10,447,486
Granted Patent B2
US 10,447,486 · App. 16/039,335 · Granted Oct 15, 2019

Remote attestation of a security module's assurance level

Inventors: Daniel Elvio Turissini (McLean, VA); William Reid Carlisle (St. Petersburg, FL); Burton George Tregub (Encino, CA)
Assignee: SPYRUS, Inc.
H04L9/3268G06F21/00G09C1/00H04L9/0877
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,447,486
App. No.
16/039,335
Granted
Oct 15, 2019
Kind
B2
Abstract

A method by which a hardware security module can attest remotely to its measure of trust as determined by its security certifications and the Level of Assurance it can be relied on to support without the human witnessing elements that are currently used to validate this trust. In a further embodiment the Level of Assurance can be transported to a second hardware security module.

Claims (8)

1. A method for manufacture of a hardware security module having a Level of Assurance and cryptographic software and storage within a secure boundary, which can remotely attest to its Level of Assurance, comprising the steps of:

a) creating a provisioned security module by provisioning a hardware security module to create a device attestation public key pair within the boundary of the hardware security module, said device attestation public key pair comprising a public key and a private key;

b) creating a signed certificate request by causing the cryptographic software within the provisioned security module to sign a request to a certificate authority with the private key of the device attestation public key pair, said request being for the issuance of a device attestation certificate which includes certification of the hardware security module's Level of Assurance;

c) enabling the hardware security module to transmit the signed certificate request to the certificate authority;

d) enabling the hardware security module to receive a signed device attestation certificate from the certificate authority responsive to the transmitted signed certificate request;

e) enabling the hardware security module to insert the signed device attestation certificate into the cryptographic storage;

f) enabling the hardware security module to service remote verification requests for the current ownership of the public key of the device attestation public key pair; and

g) enabling the hardware security module to service remote requests for the hardware security module's Level of Assurance by inspection of the signed device attestation certificate.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 24, 2018
From: TREGUB, BURTON G; CARLISLE, WILLIAM REID; TURISSINI, DANIEL ELVIO
To: SPYRUS, INC.
Reel/Frame 046439/0727 →
Continuity (2)
Provisional Application 62534317 · Jul 19, 2017
Related Publication 20190028281A1 · Jan 24, 2019
Cited By (1)
US 12,598,085