IP Library › Granted Patent US 12,355,864
Granted Patent B1
US 12,355,864 · App. 17/490,382 · Granted Jul 8, 2025

Trust framework against systematic cryptographic breach

Inventors: Dalton James Nikitas (Seattle, WA); Steve Preston Lightner Norum (Richmond, VA); Avni Harilal Rambhia (Fairfax, VA)
Assignee: Amazon Technologies, Inc.
H04L9/0656G06F21/70H04L9/0643H04L9/088H04L9/0894H04L9/3247H04L9/3265H04L2209/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,355,864
App. No.
17/490,382
Granted
Jul 8, 2025
Kind
B1
Abstract

A computing system receives encrypted data that can be decrypted by a first secret to obtain data, wherein the first secret is securely stored by the system, determines that the data encodes a second secret and executable code usable to perform cryptographic operations, and run the executable code to perform the cryptographic operations. The first secret may be a one-time pad.

Claims (46)

1. A computer-implemented method, comprising:

generating a hash output using a secret and executable code of an update that causes previously installed executable codes of a hardware device to be updated and to be applied by a hardware device that securely stores a one-time pad, wherein the update has not been previously installed on the hardware device and wherein the hash output is a hash of the secret and the executable code of the update together;

using a one-time pad to encrypt the hash output, thereby generating an encrypted hash output; and

providing the encrypted hash output to the hardware device to cause the hardware device to run the executable code to apply the update to enable the hardware device to perform cryptographic operations using the secret.

2. The computer-implemented method of claim 1 , wherein the executable code comprises code that, if applied by the hardware device, causes firmware of the hardware device to be updated.

3. The computer-implemented method of claim 1 , wherein the encrypted hash output is decryptable to verify the executable code applying the update.

4. The computer-implemented method of claim 1 , further comprising:

identifying a cryptographic algorithm; and

generating the executable code, wherein the executable code, if applied by the hardware device, enables the hardware device to perform the cryptographic operations according to the cryptographic algorithm.

5. A system, comprising memory storing instructions that, as a result of execution by one or more processors, cause the system to:

generate a hash output using a first secret and executable code of an update that causes previously installed executable codes of a hardware device to be updated, wherein the update has not been previously installed on the hardware device;

obtain, by encrypting the hash output, encrypted data that can be decrypted by a second secret to obtain data, wherein the second secret is securely stored by the system;

determine that the data encodes a second the first secret and the update usable to perform operations; and

apply the update to enable the system to perform the operations.

6. The system of claim 5 , wherein the instructions further cause the system to:

decrypt the encrypted data using the second secret to obtain the data;

generate an output based on the first secret and the update; and

apply the update in response to verifying that the data and the output match.

7. The system of claim 6 , wherein the instructions to generate the output cause the system to:

concatenate the update and the first secret to generate concatenated data; and

use at least the concatenated data as an input to a cryptographic hash function to generate the output.

8. The system of claim 5 , wherein the executable code of the update, if executed, causes the system to generate, based on the first secret, a trust anchor.

9. The system of claim 8 , wherein the instructions that cause the system to generate the trust anchor include instructions to generate a root certificate.

10. The system of claim 5 , wherein:

the instructions further comprise instructions that cause the system to receive the update from a second computing entity different from a first computing entity associated with the encrypted data.

11. The system of claim 5 , further comprising one or more fuses, wherein:

the second secret is securely stored in the one or more fuses; and

physical destruction of the one or more fuses is caused in response to detecting an attempt to physically access the one or more fuses.

12. The system of claim 5 , wherein the instructions to enable the system to perform the operations enable the system to perform cryptographic operations.

13. A non-transitory computer-readable storage medium storing thereon instructions that, if executed by one or more processors, cause a system to:

generate a hash output using a first secret and executable code of an update that causes previously installed executable codes of a hardware device to be updated, wherein the update has not been previously installed on the hardware device;

obtain, by encrypting the hash output, encrypted data that can be decrypted by a second secret to obtain data, wherein the second secret is securely stored by the system;

detect that the data comprises first secret and the update usable to perform operations; and

apply the update to enable the system to perform the operations.

14. The non-transitory computer-readable storage medium of claim 13 , wherein the instructions further cause the system to:

decrypt the encrypted data using the second secret to obtain the data;

generate an output based on the first secret; and

apply the update if the data and the output match.

15. The non-transitory computer-readable storage medium of claim 14 , wherein the instructions to generate the output cause the system to:

combine the update and the first secret to generate combined data; and

use at least the combined data as an input to a hash function to generate the output.

16. The non-transitory computer-readable storage medium of claim 13 , wherein the executable code of the update, if executed, causes the system to generate, based on the first secret, cryptographic material.

17. The non-transitory computer-readable storage medium of claim 16 , wherein the cryptographic material corresponds to a digital certificate.

18. The non-transitory computer-readable storage medium of claim 13 , wherein the instructions further comprise instructions that cause the system to receive the update from a second computing entity, wherein a first computing entity associated with the encrypted data and the second computing entity are different.

19. The non-transitory computer-readable storage medium of claim 13 , wherein the second secret is comprised in one or more fuses of the system.

20. The non-transitory computer-readable storage medium of claim 13 , wherein the operations comprise cryptographic operations.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 30, 2021
From: NIKITAS, DALTON JAMES; NORUM, STEVE PRESTON LIGHTNER; RAMBHIA, AVNI HARILAL
To: AMAZON TECHNOLOGIES, INC.
Reel/Frame 057657/0692 →
Continuity (1)
Division 16011230 · Jun 18, 2018
References Cited (56)
US 1310719A · Vernam · 1919 [cited by applicant]
US 6889324B1 · Kanai · 2005 [cited by examiner]
US 8214653B1 · Marr · 2012 [cited by examiner]
US 8363834B1 · Singhal · 2013 [cited by applicant]
US 9483647B2 · Shah et al. · 2016 [cited by applicant]
US 11153074B1 · Nikitas et al. · 2021 [cited by applicant]
US 20020004784A1 · Forbes et al. · 2002 [cited by applicant]
US 20060005046A1 · Hars · 2006 [cited by examiner]
US 20060143600A1 · Cottrell · 2006 [cited by examiner]
US 20070074037A1 · Eckleder · 2007 [cited by applicant]
US 20080256363A1 · Balacheff et al. · 2008 [cited by applicant]
US 20100085075A1 · Luzzi · 2010 [cited by examiner]
US 20100246811A1 · Sadler · 2010 [cited by examiner]
US 20100246817A1 · Sadler · 2010 [cited by examiner]
US 20100265617A1 · Isuyama · 2010 [cited by applicant]
US 20110055585A1 · Lee · 2011 [cited by applicant]
US 20120144204A1 · Litz · 2012 [cited by examiner]
US 20120331308A1 · Fernandez Gutierrez · 2012 [cited by applicant]
US 20130036314A1 · Glew · 2013 [cited by examiner]
US 20140201518A1 · Yao · 2014 [cited by examiner]
US 20150106616A1 · Nix · 2015 [cited by applicant]
US 20160306977A1 · Zarakas · 2016 [cited by examiner]
US 20160315777A1 · Lloyd · 2016 [cited by examiner]
US 20170180137A1 · Spanier · 2017 [cited by examiner]
US 20180060561A1 · Pedersen · 2018 [cited by examiner]
US 20180082065A1 · Liu et al. · 2018 [cited by applicant]
US 20180275979A1 · Shepherd · 2018 [cited by applicant]
US 20200076591A1 · Baker · 2020 [cited by examiner]
US 20200134185A1 · Cho · 2020 [cited by examiner]
US 20210367781A1 · Wu · 2021 [cited by examiner]
CN 102105883A · 2011 [cited by examiner]
CN 102823195A · 2012 [cited by examiner]
CN 106155725A · 2016 [cited by examiner]
EP 1973052A1 · 2008 [cited by examiner]
JP 2007041694A · 2007 [cited by examiner]
WO WO2004021719A1 · 2004 [cited by examiner]
WO WO2009062965A2 · 2009 [cited by examiner]
WO WO2010095703A1 · 2010 [cited by examiner]
WO WO2017066409A1 · 2017 [cited by examiner]
Falas et al., “A Hardware-based Framework for Secure Firmware Updates on Embedded Systems,” 2019 IFIP/IEEE 27th International Conference on Very Large Scale Integration (VLSI-SoC), 2019, pp. 198-203, doi: 10.1109/VLSI-S… [cited by examiner]
Zandberg et al., “Secure Firmware Updates for Constrained IoT Devices Using Open Standards: A Reality Check,” in IEEE Access, vol. 7, pp. 71907-71920, 2019, doi: 10.1109/ACCESS.2019.2919760. (Year: 2019). [cited by examiner]
Falas et al., “A Modular End-to-End Framework for Secure Firmware Updates on Embedded Systems,” arXiv:2007.09071v4, Oct. 1, 2021. (Year: 2021). [cited by examiner]
Mtetwa et al., “Secure Firmware Updates in the Internet of Things: A survey,” 2019 International Multidisciplinary Information Technology and Engineering Conference (IMITEC), Vanderbijlpark, South Africa, 2019, pp. 1-7,… [cited by examiner]
Wu et al., “Work-in-Progress: Measuring Security Protection in Real-time Embedded Firmware,” 2022 IEEE Real-Time Systems Symposium (RTSS), Houston, TX, USA, 2022, pp. 495-498, doi: 10.1109/RTSS55097.2022.00050. (Year: 2… [cited by examiner]
Li et al., “Towards Fine-grained Fingerprinting of Firmware in Online Embedded Devices,” IEEE INFOCOM 2018—IEEE Conference on Computer Communications, Honolulu, HI, USA, 2018, pp. 2537-2545, doi: 10.1109/INFOCOM.2018.84… [cited by examiner]
Falas et al., “A Hardware-based Framework for Secure Firmware Updates on Embedded Systems,” 2019 IFIP/IEEE 27th International Conference on Very Large Scale Integration (VLSI-SoC), Cuzco, Peru, 2019, pp. 198-203, doi: 1… [cited by examiner]
Ramachandran et al., “A remote attestation infrastructure for verifying the application of software updates,” 2017 IFIP/IEEE Symposium on Integrated Network and Service Management (IM), Lisbon, Portugal, 2017, pp. 317-3… [cited by examiner]
Keleman et al., “Secure firmware update in embedded systems,” 2019 IEEE 9th International Conference on Consumer Electronics (ICCE-Berlin), Berlin, Germany, 2019, pp. 16-19, doi: 10.1109/ICCE-Berlin47944.2019.8966174. (… [cited by examiner]
Choi et al., “Secure firmware validation and update for consumer devices in home networking,” in IEEE Transactions on Consumer Electronics, vol. 62, No. 1, pp. 39-44, Feb. 2016, doi: 10.1109/TCE.2016.7448561. (Year: 201… [cited by examiner]
Prada-Delgado et al., A. Vázquez-Reyes and I. Baturone, “Trustworthy firmware update for Internet-of-Thing Devices using physical unclonable functions,” 2017 Global Internet of Things Summit (GIoTS), Geneva, Switzerland… [cited by examiner]
IBM, “One Time Pad Digital Signature Technique”, NN78081316, IBM Technical Disclosure Bulletin, Aug. 1978, 4 pages. [cited by applicant]
IBM , “Methods for Thwarting Corrupt Implementation of Data Encryption”, NN9509345, IBM Technical Disclosure Bulletin , Sep. 1995, 3 pages. [cited by applicant]
Chen et al., “Public-Key Quantum Digital Signature Scheme with One-Time Pad Private-Key”, Springer Science + Business Media, 10.1007/S11128-017-1778-5, Dec. 2017, pp. 1-14. [cited by applicant]
Shannon, “Communication Theory Secrecy Systems,” The material in this paper appeared in a confidential report ,A Mathematical Theory of Cryptography, dated Sep. 1, 1946, which has now been declassified, 60 pages. [cited by applicant]
Cooper et al., “Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile,” Request for Comments: 5280, Standards Track, May 2008, 141 pages. [cited by applicant]
Dang, “Recommendation for Applications Using Approved Hash Algorithms”, NIST Special Publication 800-107 , Revision 1 , National Institute of Standards and Technology ( NIST ) , Aug. 2012 , retrieved on Nov. 24, 2015 , … [cited by applicant]