IP Library › Granted Patent US 11,456,866
Granted Patent B2
US 11,456,866 · App. 16/938,367 · Granted Sep 27, 2022

Key ladder generating a device public key

Inventors: Alexander Medvinsky (San Diego, CA); Tat Keung Chan (San Diego, CA)
Assignee: ARRIS Enterprises LLC
H04L9/0866H04L9/3013H04L9/3066H04L9/3268
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,456,866
App. No.
16/938,367
Filed
Jul 24, 2020
Granted
Sep 27, 2022
Kind
B2
Art Unit
2499
USPC
713/156
Abstract

A method is provided for generating a key ladder for securely communicating between a first device and a second device using a first device symmetric key and a chip-unique private key. The method includes generating a second processor-specific first device symmetric key from a first processor-specific first device symmetric key and a first identifier (CPU_ID), generating a chip-unique first device application private key (CUAPrK) from a second identifier and the second processor-specific first device symmetric key, generating a chip-unique first device application public key (CUAPuK) from the chip-unique first device application private key (CUAPrK), and transmitting the chip-unique first device application public key (CUAPuK) and an identifier of the processor to the second device.

Claims (36)

1. A method of generating a key ladder for securely communicating between a first device and a second device, comprising:

generating, in the first device having a processor, a second processor-specific first device symmetric key from a first processor-specific first device symmetric key and a first identifier;

generating, in the first device, a chip-unique first device application private key from a second identifier and the second processor-specific first device symmetric key; and

generating, in the first device, a chip-unique first device application public key from the chip-unique first device application private key.

2. The method of claim 1 , further comprising providing the chip-unique first device application public key and an identifier of the processor to the second device.

3. The method of claim 1 , further comprising:

generating a certificate signing request file including the chip-unique first device application public key, the first identifier, and a signature corresponding to the chip-unique first device application private key;

submitting the generated certificate signing request file to a certificate authority; and

receiving, in the first device, an application specific device certificate from the certificate authority.

4. The method of claim 1 , wherein the chip-unique first device application private key is generated according to a discrete log-based cryptographic algorithm.

5. The method of claim 4 , wherein the discrete log-based cryptographic algorithm is a Diffie-Hellman, and the chip-unique first device application public key (CUAPuK) is computed as CUAPuK=g CuaPrK mod p, where g is a group generator and p is a prime number of at least 2048 bits.

6. The method of claim 4 , wherein the discrete log-based cryptographic algorithm is one of elliptic curve Diffie-Hellman and elliptic curve digital signature algorithm and the chip-unique first device application public key (CUAPuK) is computed as CUAPuK=CUAPrK*G where G is an elliptic curve base point and the operation * is a elliptic curve multiplication operation.

7. The method of claim 1 , wherein the first processor-specific first device symmetric key is generated by generating the processor-specific first device symmetric key from an identifier of the processor and a chip key.

8. The method of claim 1 , wherein deriving the processor- specific first device symmetric key comprises generating, in the first device, the processor-specific first device symmetric key from a chip private key and a global public key of the second device.

9. The method of claim 8 , further comprising generating, in the first device, a chip public key from the chip private key and providing the chip public key to the second device.

10. The method of claim 9 , wherein the second device generates the chip symmetric key from the global private key and the chip public key, and the method further comprises:

receiving, in the first device, an updated global public key from the second device; and

generating, in the first device an updated processor specific first device symmetric key from a chip private key and the updated public key of the second device.

11. The method of claim 8 , wherein the chip private key is generated by generating, in the first device, the chip private key from a one-time-programmable value of the first device and key parameters.

12. The method of claim 11 , wherein the key parameters are received from the second device.

13. The method of claim 12 , wherein the key parameters specify a public key algorithm for generating the chip private key.

14. The method of claim 1 , further comprising generating, in the first device, a chip-unique first device symmetric key from the processor-specific first device symmetric key and a second application identifier.

15. An apparatus for generating a key ladder for communications between devices, comprising:

a first device, comprising:

a processor;

a memory, communicatively coupled to the processor, the memory storing processor instructions comprising processor instructions for:

generating, in the first device, a second processor-specific first device symmetric key from a first processor-specific first device symmetric key and a first identifier;

generating, in the first device, a chip-unique first device application private key from a second identifier and the second processor-specific first device symmetric key; and

generating, in the first device, a chip-unique first device application public key from the chip-unique first device application private key.

16. The apparatus of claim 15 , wherein the processor instructions further comprise instructions for providing the chip-unique first device application public key and an identifier of the processor to a second device of the plurality of devices.

17. The apparatus of claim 15 , wherein the processor instructions for deriving the processor-specific first device symmetric key comprise processor instructions for generating the processor-specific first device symmetric key from an identifier of the processor and a chip key.

18. The apparatus of claim 15 , wherein the processor instructions for deriving the processor-specific first device symmetric key comprise processor instructions for generating, in the first device, the processor-specific first device symmetric key from a chip private key and a global public key of the second device.

19. The apparatus of claim 18 , wherein the processor instructions further comprise processor instructions for generating, in the first device, a chip public key from the chip private key and providing the chip public key to the second device.

20. The apparatus of claim 19 , wherein the second device generates the chip symmetric key from the global private key and the chip public key, and the processor instructions further comprise instructions for:

receiving, in the first device, an updated global public key from the second device; and

generating, in the first device an updated processor specific first device symmetric key from a chip private key and the updated public key of the second device.

Assignments (7)
RELEASE OF SECURITY INTEREST AT REEL/FRAME 058843/0712 Recorded Jan 12, 2026
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: ARRIS ENTERPRISES LLC; COMMSCOPE NORTH CAROLINA, LLC (F/K/A COMMSCOPE, INC. OF NORTH CAROLINA); COMMSCOPE TECHNOLOGIES LLC
Reel/Frame 074591/0389 →
RELEASE OF SECURITY INTEREST AT REEL/FRAME 058875/0449 Recorded Dec 19, 2024
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: ARRIS ENTERPRISES LLC (F/K/A ARRIS ENTERPRISES, INC.); COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC
Reel/Frame 069743/0057 →
SECURITY INTEREST Recorded Dec 17, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE INC., OF NORTH CAROLINA; OUTDOOR WIRELESS NETWORKS LLC; RUCKUS IP HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC
Reel/Frame 069889/0114 →
SECURITY INTEREST Recorded Nov 19, 2021
From: ARRIS SOLUTIONS, INC.; ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA; RUCKUS WIRELESS, INC.
To: WILMINGTON TRUST
Reel/Frame 060752/0001 →
TERM LOAN SECURITY AGREEMENT Recorded Nov 15, 2021
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 058875/0449 →
ABL SECURITY AGREEMENT Recorded Nov 15, 2021
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 058843/0712 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 24, 2020
From: MEDVINSKY, ALEXANDER; CHAN, TAT KEUNG
To: ARRIS ENTERPRISES LLC
Reel/Frame 053308/0231 →
Continuity (2)
Provisional Application 62878187 · Jul 24, 2019
Related Publication 20210028933A1 · Jan 28, 2021