IP Library › Granted Patent US 12,254,123
Granted Patent B2
US 12,254,123 · App. 17/335,245 · Granted Mar 18, 2025

Using a trust anchor to verify an identity of an ASIC

Inventors: Chirag Shroff (Cary, NC); David McGrew (Poolesville, MD)
Assignee: CISCO TECHNOLOGY, INC.
G06F21/73G06F7/588G06F21/72
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,254,123
App. No.
17/335,245
Granted
Mar 18, 2025
Kind
B2
Abstract

According to certain embodiments, a method comprises performing a posture assessment at a trust anchor in order to determine whether a hardware component is authorized to run on a product. Performing the posture assessment comprises determining a random value (K), encrypting the random value (K) using a long-term key associated with the hardware component in order to yield an encrypted value, communicating the encrypted value to the hardware component, and receiving, from the hardware component, a message encrypted using the random value (K). The message comprises an identifier associated with the hardware component. Performing the posture assessment further comprises determining whether the hardware component is authorized to run on the product based at least in part on the identifier associated with the hardware component. The method further comprises performing an action that depends on whether the hardware component is authorized to run on the product.

Claims (75)

1. A system, the system comprising:

one or more processors; and

one or more computer-readable non-transitory storage media, the one or more computer-readable non-transitory storage media comprising instructions that, when executed by the one or more processors, cause one or more components of the system to perform operations comprising:

receiving, by a trust anchor, a long-term key originating within a hardware component, wherein the long-term key has been encrypted using a public key of the trust anchor;

performing a posture assessment at the trust anchor in order to determine whether the hardware component is authorized to run on a product, wherein performing the posture assessment comprises:

determining a random value (K);

encrypting the random value (K) using the long-term key associated with the hardware component in order to yield an encrypted value;

communicating the encrypted value to the hardware component;

receiving, from the hardware component, a message encrypted using the random value (K), wherein the message comprises an identifier associated with the hardware component; and

determining whether the hardware component is authorized to run on the product based at least in part on the identifier associated with the hardware component; and

performing an action that depends on whether the hardware component is authorized to run on the product.

2. The system of claim 1 , wherein the identifier associated with the hardware component comprises:

an electronic chip identifier (ECID) of the hardware component; or

an identity of a product that the hardware component is provisioned to run on.

3. The system of claim 1 , wherein:

the hardware component is an application-specific integrated circuit (ASIC); and

the long-term key is:

burned into the ASIC during manufacturing; or

created using physical unclonable function (PUF) technology.

4. The system of claim 1 , wherein determining whether the hardware component is authorized to run on the product based at least in part on the identifier associated with the hardware component comprises:

comparing the identifier received from the hardware component to one or more authorized identifiers, each authorized identifier read from a respective authorized hardware component and imprinted on the trust anchor during manufacturing of the product.

5. The system of claim 1 , wherein performing the action that depends on whether the hardware component is authorized to run on the product comprises:

allowing the hardware component to run on the product in response to determining that the hardware component is authorized to run on the product.

6. The system of claim 1 , wherein performing the action that depends on whether the hardware component is authorized to run on the product comprises:

preventing the hardware component from running on the product in response to determining that the hardware component is not authorized to run on the product.

7. The system of claim 1 , wherein performing the action that depends on whether the hardware component is authorized to run on the product comprises:

providing an attestation to a recipient in response to determining that the hardware component is authorized to run on the product, the attestation indicating to the recipient that the hardware component is authorized to run on the product.

8. A method, the method comprising:

receiving, by a trust anchor, a long-term key originating within a hardware component, wherein the long-term key has been encrypted using a public key of the trust anchor;

performing a posture assessment at the trust anchor in order to determine whether the hardware component is authorized to run on a product, wherein performing the posture assessment comprises:

determining a random value (K);

encrypting the random value (K) using the long-term key associated with the hardware component in order to yield an encrypted value;

communicating the encrypted value to the hardware component;

receiving, from the hardware component, a message encrypted using the random value (K), wherein the message comprises an identifier associated with the hardware component; and

determining whether the hardware component is authorized to run on the product based at least in part on the identifier associated with the hardware component; and

performing an action that depends on whether the hardware component is authorized to run on the product.

9. The method of claim 8 , wherein the identifier associated with the hardware component comprises:

an electronic chip identifier (ECID) of the hardware component; or

an identity of a product that the hardware component is provisioned to run on.

10. The method of claim 8 , wherein:

the hardware component is an application-specific integrated circuit (ASIC); and

the long-term key is:

burned into the ASIC during manufacturing; or

created using physical unclonable function (PUF) technology.

11. The method of claim 8 , wherein determining whether the hardware component is authorized to run on the product based at least in part on the identifier associated with the hardware component comprises:

comparing the identifier received from the hardware component to one or more authorized identifiers, each authorized identifier read from a respective authorized hardware component and imprinted on the trust anchor during manufacturing of the product.

12. The method of claim 8 , wherein performing the action that depends on whether the hardware component is authorized to run on the product comprises:

allowing the hardware component to run on the product in response to determining that the hardware component is authorized to run on the product.

13. The method of claim 8 , wherein performing the action that depends on whether the hardware component is authorized to run on the product comprises:

preventing the hardware component from running on the product in response to determining that the hardware component is not authorized to run on the product.

14. One or more computer-readable non-transitory storage media embodying instructions that, when executed by a processor, cause performance of operations including:

receiving, by a trust anchor, a long-term key originating within a hardware component, wherein the long-term key has been encrypted using a public key of the trust anchor;

performing a posture assessment at the trust anchor in order to determine whether the hardware component is authorized to run on a product, wherein performing the posture assessment comprises:

determining a random value (K);

encrypting the random value (K) using the long-term key associated with the hardware component in order to yield an encrypted value;

communicating the encrypted value to the hardware component;

receiving, from the hardware component, a message encrypted using the random value (K), wherein the message comprises an identifier associated with the hardware component; and

determining whether the hardware component is authorized to run on the product based at least in part on the identifier associated with the hardware component; and

performing an action that depends on whether the hardware component is authorized to run on the product.

15. The one or more computer-readable non-transitory storage media of claim 14 , wherein the identifier associated with the hardware component comprises:

an electronic chip identifier (ECID) of the hardware component; or

an identity of a product that the hardware component is provisioned to run on.

16. The one or more computer-readable non-transitory storage media of claim 14 , wherein:

the hardware component is an application-specific integrated circuit (ASIC); and

the long-term key is:

burned into the ASIC during manufacturing; or

created using physical unclonable function (PUF) technology.

17. The one or more computer-readable non-transitory storage media of claim 14 , wherein determining whether the hardware component is authorized to run on the product based at least in part on the identifier associated with the hardware component comprises:

comparing the identifier received from the hardware component to one or more authorized identifiers, each authorized identifier read from a respective authorized hardware component and imprinted on the trust anchor during manufacturing of the product.

18. The one or more computer-readable non-transitory storage media of claim 14 , wherein performing the action that depends on whether the hardware component is authorized to run on the product comprises:

allowing the hardware component to run on the product in response to determining that the hardware component is authorized to run on the product.

19. The one or more computer-readable non-transitory storage media of claim 14 , wherein performing the action that depends on whether the hardware component is authorized to run on the product comprises:

preventing the hardware component from running on the product in response to determining that the hardware component is not authorized to run on the product.

20. The one or more computer-readable non-transitory storage media of claim 14 , wherein performing the action that depends on whether the hardware component is authorized to run on the product comprises:

providing an attestation to a recipient in response to determining that the hardware component is authorized to run on the product, the attestation indicating to the recipient that the hardware component is authorized to run on the product.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 1, 2021
From: SHROFF, CHIRAG; MCGREW, DAVID
To: CISCO TECHNOLOGY, INC.
Reel/Frame 056399/0676 →
Continuity (1)
Related Publication 20220382912A1 · Dec 1, 2022
References Cited (36)
US 7558966B2 · Durham · 2009 [cited by examiner]
US 8370959B2 · Gunadisastra · 2013 [cited by examiner]
US 8694687B2 · Hammouri · 2014 [cited by examiner]
US 9940486B2 · Grieco · 2018 [cited by examiner]
US 10102356B1 · Sahin · 2018 [cited by examiner]
US 10896266B1 · BeSerra · 2021 [cited by examiner]
US 20040049468A1 · Walmsley · 2004 [cited by examiner]
US 20040049678A1 · Walsmley · 2004 [cited by examiner]
US 20080258864A1 · Hattori · 2008 [cited by examiner]
US 20110060947A1 · Song et al. · 2011 [cited by applicant]
US 20120303941A1 · Grieco · 2012 [cited by examiner]
US 20130019281A1 · Jacobs · 2013 [cited by examiner]
US 20130097663A1 · Finger et al. · 2013 [cited by applicant]
US 20140026206A1 · Pazhyannur · 2014 [cited by examiner]
US 20140032907A1 · Smith · 2014 [cited by examiner]
US 20140064480A1 · Hartley et al. · 2014 [cited by applicant]
US 20150095631A1 · Rahardjo et al. · 2015 [cited by applicant]
US 20150319150A1 · Smith et al. · 2015 [cited by applicant]
US 20160006735A1 · La Fever et al. · 2016 [cited by applicant]
US 20160048462A1 · O'Loughlin et al. · 2016 [cited by applicant]
US 20160085995A1 · Poornachandran · 2016 [cited by examiner]
US 20160171223A1 · Covey et al. · 2016 [cited by applicant]
US 20160245862A1 · Grieco et al. · 2016 [cited by applicant]
US 20160247002A1 · Grieco et al. · 2016 [cited by applicant]
US 20170250827A1 · Opschroef et al. · 2017 [cited by applicant]
US 20190050601A1 · Zeh et al. · 2019 [cited by applicant]
US 20200021447A1 · Ih et al. · 2020 [cited by applicant]
US 20200220865A1 · Finger · 2020 [cited by examiner]
US 20200228351A1 · Kreft · 2020 [cited by applicant]
US 20200228388A1 · Schulz et al. · 2020 [cited by applicant]
US 20200322176A1 · Bhandari et al. · 2020 [cited by applicant]
US 20220100908A1 · N · 2022 [cited by examiner]
CN 108768963A · 2018 [cited by applicant]
Reconfigurable trusted computing in hardware; See discussions, stats, and author profiles for this publication at: https://www.researchgate.net/publication/221609772; Conference Paper ⋅ Jan. 2007. [cited by applicant]
Electronic Chip ID, FPGA Security FPGA anti-counterfeit technology, Device DNA, Silicon ID; https:// www.intellitech.com/ic/; 2 pages; 60 Rochester Hill Rd, Rochester, NH 03867, U.S.A. Tel: (603 )403-8030 Copyright © 19… [cited by applicant]
Advanced Modes in AES: Are they Safe from Power Analysis based Side Channel Attacks ?; https://ieeexplore.ieee.org/abstract/document/6974678; Published in: 2014 IEEE 32nd International Conference on Computer Design (ICC… [cited by applicant]