IP Library › Granted Patent US 11,947,681
Granted Patent B2
US 11,947,681 · App. 17/488,589 · Granted Apr 2, 2024

Cryptographic secret generation and provisioning

Inventor: Christopher Paul Gorog (Pueblo, CO)
Assignee: BLOCKFRAME, INC.
G06F21/602G06F16/2379G06F21/604G06F21/6209G06Q10/0835G06Q10/087G06Q20/389G06Q20/401H04L9/0827H04L9/085H04L9/0861H04L9/0877H04L63/0442H04L63/0823H04L63/0838
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,947,681
App. No.
17/488,589
Granted
Apr 2, 2024
Kind
B2
Abstract

A system includes a memory device and a processor, operatively coupled with the memory device, to perform operations including receiving, from a device via a brokering agent, a request to provide an encrypted version of a set of secrets data corresponding to a target state of the device, determining whether to authorize the request in view of the brokering agent, and in response to authorizing the request, providing the encrypted version of the set of secrets data and permission to transition to the target state.

Claims (65)

1. A system comprising:

a memory device; and

a processor, operatively coupled with the memory device, to perform operations comprising:

receiving, via a brokering agent, a request to provide a device, in a current supply chain state corresponding to a current stage of a supply chain of the device, with a set of secrets data corresponding to a target supply chain state of the device corresponding to a target stage of the supply chain, wherein the device in the current supply chain state is associated with a first entity corresponding to the current stage;

determining whether to authorize the request; and

in response to authorizing the request, causing the set of secrets data to be provided to the device to cause the device to transition from the current supply chain state to the target supply chain state, wherein the device in the target supply chain state is associated with a second entity corresponding to the target stage.

2. The system of claim 1 , wherein the operations further comprise maintaining, on a distributed ledger, a record indicative of the set of secrets data being provided to the device.

3. The system of claim 1 , wherein the operations further comprise, in response to not authorizing the request:

denying access to the set of secrets data; and

maintaining, on a distributed ledger, a record indicative of denying access to the set of secrets data.

4. The system of claim 1 , wherein:

determining whether to authorize the request further comprises:

determining whether the brokering agent is authorized to handle the request;

in response to determining that the brokering agent is authorized to handle the request, receiving, from the device via the brokering agent, a supersession package corresponding to the device being in a supersession state; and

determining whether the device has permission to transition to the target supply chain state based on the supersession package; and

causing the set of secrets data to be provided further comprises:

in response to determining that the device has permission to transition to the target supply chain state based on the supersession package, sending, to the device via the brokering agent, a commit package to commit the set of secrets data.

5. The system of claim 1 , wherein the target supply chain state is one of:

a manufacturer provisioning state corresponding to a manufacturing stage of a supply chain, the second entity being associated with a manufacturer of the device;

a vendor provisioning state corresponding to a vendor stage of the supply chain the second entity being associated with a vendor in possession of the device;

an end-use provisioning state corresponding to an end-use stage of the supply chain;

or an operational state corresponding to an operational stage of the supply chain.

6. The system of claim 1 , wherein the set of secrets data is generated by a hardware security module.

7. The system of claim 1 , wherein the device in the current supply chain state maintains a second set of secrets data corresponding to the current supply chain state.

8. A method comprising:

receiving, by a processor via a brokering agent, a request to initiate a supply chain state progression of a device from a current supply chain state corresponding to a current stage of a supply chain of the device to a target supply chain state corresponding to a target stage of the supply chain, wherein the device in the current supply chain state is associated with a first entity corresponding to the current stage;

determining, by the processor, whether to authorize the request; and

in response to authorizing the request, causing, by the processor, the device to transition from the current supply chain state to the target supply chain state by providing a set of secrets data corresponding to the target supply chain state, wherein the device in the target supply chain state is associated with a second entity corresponding to the target stage.

9. The method of claim 8 , further comprising maintaining, by the processor on a distributed ledger, a record indicative of the transition of the device to the target supply chain state.

10. The method of claim 8 , further comprising, in response to not authorizing the request, preventing, by the processor, the device from transitioning to the target supply chain state.

11. The method of claim 8 , wherein:

determining whether to authorize the request further comprises:

determining whether the brokering agent is authorized to handle the request;

in response to determining that the brokering agent is authorized to handle the request, receiving, from the device via the brokering agent, a supersession package corresponding to the device being in a supersession state; and

determining whether the device has permission to transition to the target supply chain state based on the supersession package; and

causing the device to transition from the current supply chain state to the target supply chain state comprises:

in response to determining that the device has permission to transition to the target supply chain state based on the supersession package, sending, to the device via the brokering agent, a commit package to commit the set of secrets data.

12. The method of claim 8 , wherein the set of secrets data is generated by a hardware security module.

13. The method of claim 8 , wherein the target supply chain state is one of:

a manufacturer provisioning state corresponding to a manufacturing stage of a supply chain, the second entity being associated with a manufacturer of the device;

a vendor provisioning state corresponding to a vendor stage of the supply chain, the second entity being associated with a vendor in possession of the device;

an end-use provisioning state corresponding to an end-use stage of the supply chain;

or an operational state corresponding to an operational stage of the supply chain.

14. The method of claim 8 , wherein the device in the current supply chain state maintains a second set of secrets data corresponding to the current supply chain state.

15. A non-transitory computer-readable storage medium comprising instructions that, when executed by a processing device, cause the processing device to perform operations comprising:

receiving, via a brokering agent, a request to provide a device, in a current supply chain state corresponding to a current stage of a supply chain of the device, with a set of secrets data corresponding to a target supply chain state of the device corresponding to a target stage of the supply chain, wherein the device in the current supply chain state is associated with a first entity corresponding to the current stage;

determining whether to authorize the request; and

in response to authorizing the request, causing the set of secrets data to be provided to the device to cause the device to transition from the current supply chain state to the target supply chain state, wherein the device in the target supply chain state is associated with a second entity corresponding to the target stage.

16. The non-transitory computer-readable storage medium of claim 15 , wherein the operations further comprise maintaining, on a distributed ledger, a record indicative of the set of secrets data being provided to the device.

17. The non-transitory computer-readable storage medium of claim 15 , wherein the operations further comprise, in response to not authorizing the request:

denying access to the set of secrets data; and

maintaining, on a distributed ledger, a record indicative of denying access to the set of secrets data.

18. The non-transitory computer-readable storage medium of claim 15 , wherein:

determining whether to authorize the request further comprises:

determining whether the brokering agent is authorized to handle the request;

in response to determining that the brokering agent is authorized to handle the request, receiving, from the device via the brokering agent, a supersession package corresponding to the device being in a supersession state; and

determining whether the device has permission to transition to the target supply chain state based on the supersession package; and

causing the set of secrets data to be provided further comprises:

in response to determining that the device has permission to transition to the target supply chain state based on the supersession package, sending, to the device via the brokering agent, a commit package to commit the set of secrets data.

19. The non-transitory computer-readable storage medium of claim 15 , wherein the target supply chain state is one of:

a manufacturer provisioning state corresponding to a manufacturing stage of a supply chain, the second entity being associated with a manufacturer of the device;

a vendor provisioning state corresponding to a vendor stage of the supply chain the second entity being associated with a vendor in possession of the device;

an end-use provisioning state corresponding to an end-use stage of the supply chain;

or an operational state corresponding to an operational stage of the supply chain.

20. The non-transitory computer-readable storage medium of claim 15 , wherein the set of secrets data is generated by a hardware security module.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 30, 2021
From: GOROG, CHRISTOPHER PAUL
To: BLOCKFRAME, INC.
Reel/Frame 057651/0210 →
Continuity (6)
Provisional Application 63086904 · Oct 2, 2020
Provisional Application 63086925 · Oct 2, 2020
Provisional Application 63086926 · Oct 2, 2020
Provisional Application 63086928 · Oct 2, 2020
Provisional Application 63123067 · Dec 9, 2020
Related Publication 20220108027A1 · Apr 7, 2022