IP Library › Granted Patent US 12,267,416
Granted Patent B2
US 12,267,416 · App. 17/403,778 · Granted Apr 1, 2025

Onboarding software on secure devices to generate device identities for authentication with remote servers

Inventor: Olivier Duval (Pacifica, CA)
Assignee: Micron Technology, Inc.
H04L9/083H04L9/0825H04L9/3236H04L9/3263
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,267,416
App. No.
17/403,778
Granted
Apr 1, 2025
Kind
B2
Abstract

Systems, methods and apparatuses to configure a computing device for identification and authentication are described. For example, a key management server (KMS) has a certificate generator and is coupled to a registration portal. A copy of secret implemented into a secure component during its manufacture in a factory is stored in the KMS. After leaving the factory, the component can be assembled into the device. The portal receives registration of the component and a hash of software of the device. The certificate generator generates, independent of the device, public keys of the device, using the copy of the secret stored in the KMS and hashes of the software received via the registration portal, and then sign a digital certificate of the public key of the device. Authentication of the device can then be performed via the private key of the device and the certified public key.

Claims (37)

1. A system, comprising:

a key management server having a certificate generator; and

a registration portal coupled to the key management server;

wherein the key management server is configured to receive and store first information implemented into a component during manufacturing of the component;

wherein the component is configured to be assembled into a computing device having software;

wherein the registration portal is configured to receive registration information of the component being used with the software and to receive second information about the software;

wherein the computing device is configured to generate an asymmetrical key pair from the first information and the second information.

2. The system of claim 1 , wherein the registration portal is configured to receive, from a remote server, the second information about the software and provide the certificate of the public key to the remote server.

3. The system of claim 2 , wherein the remote server is configured with a provisioning tool, the provisioning tool is configured to generate the second information about the software.

4. The system of claim 3 , wherein the provisioning tool is configured to install the software in the computing device.

5. The system of claim 3 , wherein the provisioning tool is configured to transmit the second information about the software to the registration portal.

6. The system of claim 3 , wherein the provisioning tool is configured to activate a feature in the component in accordance with the registration information.

7. The system of claim 6 , wherein after the feature in the component is activated, the computing device is capable of authenticating with the remote server using the private key of the computing device.

8. The system of claim 6 , wherein after the feature in the component is activated, the computing device is capable of computing the asymmetrical key pair.

9. The system of claim 8 , wherein the computing device is configured to generate the asymmetrical key pair in accordance with a standard.

10. The system of claim 8 , wherein the first information is unique to the component among components manufacturing in a factory.

11. The system of claim 10 , wherein the component includes a memory device.

12. A method, comprising:

receiving and storing, in a key management server, first information implemented in a component during manufacturing of the component, wherein the component is configured to be assembled into a computing device;

receiving, in a registration portal coupled to the key management server, registration information of the component;

receiving, in the registration portal, second information, wherein the computing device is configured to generate an asymmetric key pair from the first information and the second information, the asymmetric key pair including a public key of the computing device and a private key of the computing device; and

generating, in the key management server and independent of the computing device, the asymmetric key pair from the first information stored in the key management server and the second information received via the registration portal.

13. The method of claim 12 , further comprising:

providing, by the registration portal, the certificate of the public key to a remote server that provides the second information.

14. The method of claim 13 , further comprising:

configuring a provisioning tool in the remote server, the provisioning tool is configured to generate the second information, and transmit the second information about the software to the registration portal.

15. The method of claim 14 , further comprising:

activating, by the provisioning tool, a feature in the component in accordance with the registration information.

16. The method of claim 15 , wherein activation of the feature in the component enables the computing device to authenticate with the remote server using the private key of the computing device.

17. The method of claim 15 , wherein activation of the feature in the computing device enables the computing device to compute the asymmetric key pair.

18. The method of claim 17 , wherein the computing device is configured to generate the asymmetric key pair in accordance with a standard.

19. The method of claim 18 , wherein the first information is unique to the component among components manufacturing in a factory; and the component includes a flash memory device.

20. A non-transitory computer storage medium storing instructions which, when executed in a computer system, cause the computer system to perform a method, the method comprising:

receiving and storing, in a key management server, first information implemented in a component during manufacturing of the component, wherein the component is configured to be assembled into a computing device;

receiving, in a registration portal coupled to the key management server, registration information of the component;

receiving, in the registration portal, second information, wherein the computing device is configured to generate an asymmetric key pair from the first information and the second information, the asymmetric key pair including a public key of the computing device and a private key of the computing device; and

generating, in the key management server and independent of the computing device, the asymmetric key pair from the first information stored in the key management server and the second information received via the registration portal.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 17, 2021
From: DUVAL, OLIVIER
To: MICRON TECHNOLOGY, INC.
Reel/Frame 057204/0937 →
Continuity (2)
Continuation 16374905 · Apr 4, 2019
Related Publication 20210377004A1 · Dec 2, 2021
References Cited (48)
US 9430658B2 · Covey · 2016 [cited by examiner]
US 10439816B2 · van der Maas · 2019 [cited by examiner]
US 10749680B1 · Troia et al. · 2020 [cited by applicant]
US 11101984B2 · Duval · 2021 [cited by applicant]
US 20060013402A1 · Sutton, II et al. · 2006 [cited by applicant]
US 20060117181A1 · Brickell · 2006 [cited by applicant]
US 20070223704A1 · Brickell et al. · 2007 [cited by applicant]
US 20080320308A1 · Kostiainen et al. · 2008 [cited by applicant]
US 20100325704A1 · Etchegoyen · 2010 [cited by applicant]
US 20110173684A1 · Hurry et al. · 2011 [cited by applicant]
US 20110219232A1 · Yamaguchi et al. · 2011 [cited by applicant]
US 20120331287A1 · Bowman et al. · 2012 [cited by applicant]
US 20130007443A1 · Grab et al. · 2013 [cited by applicant]
US 20140114497A1 · Miyake · 2014 [cited by applicant]
US 20140189890A1 · Koeberl et al. · 2014 [cited by applicant]
US 20140317417A1 · Ashkenazi · 2014 [cited by applicant]
US 20140365763A1 · Manohar et al. · 2014 [cited by applicant]
US 20150244709A1 · Goldman · 2015 [cited by applicant]
US 20160171223A1 · Covey · 2016 [cited by examiner]
US 20170111177A1 · Oguma et al. · 2017 [cited by applicant]
US 20170244562A1 · He · 2017 [cited by applicant]
US 20170302459A1 · Fenner et al. · 2017 [cited by applicant]
US 20170366359A1 · Scarlata et al. · 2017 [cited by applicant]
US 20180039795A1 · Gulati · 2018 [cited by applicant]
US 20180167208A1 · Le Saint et al. · 2018 [cited by applicant]
US 20180351948A1 · De Jong · 2018 [cited by examiner]
US 20180375667A1 · Sovio et al. · 2018 [cited by applicant]
US 20190007220A1 · Falk · 2019 [cited by applicant]
US 20190052464A1 · Doliwa · 2019 [cited by examiner]
US 20190087577A1 · Doliwa · 2019 [cited by examiner]
US 20200021431A1 · Mondello et al. · 2020 [cited by applicant]
US 20200021981A1 · Mondello et al. · 2020 [cited by applicant]
US 20200193065A1 · Smith · 2020 [cited by examiner]
US 20200322134A1 · Duval · 2020 [cited by applicant]
CN 103825741 · 2014 [cited by applicant]
CN 105790938 · 2016 [cited by applicant]
JP 2008185616 · 2008 [cited by applicant]
WO 2017153990 · 2017 [cited by applicant]
WO 2017153990A1 · 2017 [cited by applicant]
Google translation of KR20150083179A published on Jul. 17, 2015, 19 pages (Year: 2015). [cited by examiner]
International Search Report and Written Opinion, PCT/US2020/021824, mailed Jul. 6, 2020. [cited by applicant]
J. Israelsohn, “Components of Risk: Counterfeit Electronic Parts”, Electronic Component News, Apr. 2015. [cited by applicant]
R. Aigner, P. England, K. Kane, A. Marochko, D. Mattoon, R. Spiger, S. Thom, and G. Zaverucha: Device Identity with DICE and RIoT Keys and Certificates, Sep. 2017. [cited by applicant]
Trusted Computing Group, Trusted Platform Architecture Hardware Requirements for a Device Identifier Composition Engine, Dec. 16, 2016. [cited by applicant]
Extended European Search Report, EP20783569.5, mailed on Nov. 16, 2022. [cited by applicant]
Esposito, Christian, “Integrity for an Event Notification Within the Industrial Internet of Things by Using Group Signatures.” IEEE Transactions on Industrial Informatics, IEEE, Jan. 11, 2018. [cited by applicant]
Qiu, Chenggang, et al., “A certified encryption scheme based on public key self-proof.” Computing and Information Technology, Abstract only, Jan. 20, 2007. [cited by applicant]
Zhang, Xin, et al., “Trusted Property Remote Attestation Based on ABS.” Advanced Engineering Sciences, Abstract only, Jun. 30, 2017. [cited by applicant]