IP Library Granted Patent US 10,956,621
Granted Patent B2
US 10,956,621 · App. 16/571,558 · Granted Mar 23, 2021

Secure system having a multi-locking mechanism for devices having embedded systems

Inventors: Shoaib S. Khan (Miami, FL); Khurram Humayun Chawdhry (Miami, FL)
Assignee: TracFone Wireless, Inc.
G06F21/74G06F21/86G06F21/88
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,956,621
App. No.
16/571,558
Granted
Mar 23, 2021
Kind
B2
Abstract

A device configured to implement multiple locks to increase security of assets associated with the device including an embedded system, a multi-lock mechanism configured to provide a plurality of locks to prevent an authorized access to the assets associated with the embedded system, each of the plurality of locks of the multi-lock mechanism having an different unlock parameters, a memory configured to securely store at least one of the lock parameters of the plurality of locks of the multi-lock mechanism, the memory further configured to securely store at least one of the unlock parameters of the multi-lock mechanism, and the embedded system further configured to provide access to the assets after each of the lock parameters of the plurality of locks of the multi-lock mechanism is provided the unlock parameters of the multi-lock mechanism.

Claims (34)

1. A device configured to implement multiple locks to increase security of assets associated with the device comprising:

an embedded system;

a multi-lock mechanism configured to provide a plurality of locks to prevent an unauthorized access to assets associated with the embedded system and wherein at least one of the plurality of locks of the multi-lock mechanism comprises a secure default lock state;

each of the plurality of locks of the multi-lock mechanism having lock parameters and each of the plurality of locks of the multi-lock mechanism having different unlock parameters;

a memory in communication with the embedded system, the memory configured to securely store at least one of the following: the lock parameters of the plurality of locks of the multi-lock mechanism and the unlock parameters of the plurality of locks of the multi-lock mechanism;

the memory further configured to securely store at least one of the unlock parameters of the multi-lock mechanism, wherein the memory comprises one of the following: a NAND flash memory, double data rate (DDR2) random access memory (RAM), a replay protected memory block (RPMB) memory, an encrypted memory portion, a random access memory (RAM), and an embedded (MultiMediaCard) memory; and

the embedded system further configured to provide access to the assets associated with the embedded system after each of the lock parameters of the plurality of locks of the multi-lock mechanism is provided the unlock parameters of the multi-lock mechanism,

wherein the device comprises one of the following: a wireless device, an appliance, a consumer electronic, a vehicle related device, a server, and a medical device.

2. The device according to claim 1 wherein the plurality of locks of the multi-lock mechanism are implemented with at least two of the following: a trustzone security extension, a trusted execution environment, and a network over the air (OTA) high level operating system (HLOS) client.

3. The device according to claim 1 wherein the plurality of locks of the multi-lock mechanism are implemented with at least two of the following: a trustzone security extension, a trusted execution environment, a network over the air (OTA) high level operating system (HLOS) client, a service provider code lock, a master subsidy lock, and a port security permission set lock.

4. The device according to claim 1 wherein the plurality of locks of the multi-lock mechanism are implemented with at least three of the following: a trustzone security extension, a trusted execution environment, a network over the air (OTA) high level operating system (HLOS) client, a service provider code lock, a master subsidy lock, and a port security permission set lock.

5. The device according to claim 1 further comprising hardware fuses implemented with the embedded system configured to blow in response to tampering.

6. The device according to claim 1 further comprising a crypto/security engine implemented with the embedded system.

7. The device according to claim 1 wherein the embedded system is implemented with a high level operating system (HLOS); and wherein the embedded system comprises a system on a chip.

8. The device according to claim 1 wherein the embedded system is configured to execute run-time integrity checking.

9. The device according to claim 1 wherein the embedded system is configured to execute a tamper detection feature that transparently runs to monitor a security profile.

10. The device according to claim 1 wherein the embedded system comprises a timing parameter that requires each of the lock parameters to be provided the unlock parameters in a timely manner.

11. A process configured to implement multiple locks to increase security of assets associated with a device comprising:

implementing the device with an embedded system;

providing a multi-lock mechanism with a plurality of locks to prevent an unauthorized access to assets associated with the embedded system and wherein at least one of the plurality of locks of the multi-lock mechanism comprises a secure default lock state;

implementing each of the plurality of locks of the multi-lock mechanism with lock parameters and implementing each of the plurality of locks of the multi-lock mechanism with different unlock parameters;

securely storing at least one of the following: the lock parameters of the plurality of locks of the multi-lock mechanism and the unlock parameters of the plurality of locks of the multi-lock mechanism;

securely storing at least one of the unlock parameters of the multi-lock mechanism in a memory in communication with the embedded system, wherein the memory comprises one of the following: a NAND flash memory, double data rate (DDR2) random access memory (RAM), a replay protected memory block (RPMB) memory, an encrypted memory portion, a random access memory (RAM), and an embedded (MultiMediaCard) memory; and

providing access to the assets associated with the embedded system after each of the lock parameters of the plurality of locks of the multi-lock mechanism is provided the unlock parameters of the multi-lock mechanism of the embedded system,

wherein the device comprises one of the following: a wireless device, an appliance, a consumer electronic, a vehicle related device, a server, and a medical device.

12. The process according to claim 11 wherein the plurality of locks of the multi-lock mechanism are implemented with at least two of the following: a trustzone security extension, a trusted execution environment, and a network over the air (OTA) high level operating system (HLOS) client.

13. The process according to claim 11 wherein the plurality of locks of the multi-lock mechanism are implemented with at least two of the following: a trustzone security extension, a trusted execution environment, a network over the air (OTA) high level operating system (HLOS) client, a service provider code lock, a master subsidy lock, and a port security permission set lock.

14. The process according to claim 11 wherein the plurality of locks of the multi-lock mechanism are implemented with at least three of the following: a trustzone security extension, a trusted execution environment, a network over the air (OTA) high level operating system (HLOS) client, a service provider code lock, a master subsidy lock, and a port security permission set lock.

15. The process according to claim 11 further comprising implementing hardware fuses with the embedded system configured to blow in response to tampering.

16. The process according to claim 11 further comprising implementing a crypto/security engine with the embedded system.

17. The process according to claim 11 wherein the embedded system is implemented with a high level operating system (HLOS); and wherein the embedded system comprises a system on a chip.

18. The process according to claim 11 further comprising implementing a run-time integrity checking with the embedded system.

19. The process according to claim 11 further comprising implementing a tamper detection feature that transparently runs to monitor a security profile with the embedded system.

20. The process according to claim 11 further comprising implementing a timing parameter that requires each of the lock parameters to be provided the unlock parameters in a timely manner with the embedded system.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 15, 2025
From: VERIZON VALUE, INC.
To: VERIZON PATENT AND LICENSING INC.
Reel/Frame 073109/0190 →
CHANGE OF NAME Recorded Aug 5, 2025
From: TRACFONE WIRELESS, INC.
To: VERIZON VALUE, INC.
Reel/Frame 072348/0937 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 16, 2019
From: KHAN, SHOAIB S.; CHAWDHRY, KHURRAM HUMAYUN
To: TRACFONE WIRELESS, INC.
Reel/Frame 050383/0357 →