IP Library Granted Patent US 12,367,288
Granted Patent B2
US 12,367,288 · App. 17/970,198 · Granted Jul 22, 2025

Securely provisioning secrets in authentication devices

Inventor: Vidya Satyamsetti (Bothell, WA)
Assignee: Google LLC
G06F21/572G06F21/44G06F21/575G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,367,288
App. No.
17/970,198
Granted
Jul 22, 2025
Kind
B2
Abstract

The present disclosure provides for increased security of root of trust (RoT) chips by preventing malicious provisioning. Unique device secrets (UDS) can only be provisioned securely by trustworthy hardware or trustworthy firmware. Entities other than the trustworthy hardware and trustworthy firmware do not have access to a composite device identifier (CDI) generated using the UDS and firmware measurements.

Claims (30)

1. A method of ensuring secure provisioning of a root-of-trust device, comprising:

verifying, using hardware on the root-of-trust device, firmware to be used for provisioning during a boot process;

if the firmware is verified, allowing firmware to write unique device secrets; and

if the firmware is not verified, taking, by the hardware, one or more security measures, wherein taking one or more security measures comprises refusing to boot.

2. The method of claim 1 , wherein if the firmware is verified, the method further comprises:

obtaining, by a device identifier composition engine, firmware measurements; and

generating a composite device identifier based on the firmware measurements and the unique device secrets.

3. The method of claim 1 , wherein taking one or more security measures comprises locking access to storage areas.

4. The method of claim 1 , wherein taking one or more security measures comprises refusing to run the firmware.

5. The method of claim 1 , wherein the root-of-trust device is a root-of-trust chip.

6. The method of claim 1 , further comprising preventing access to a composite device identifier or unique device secrets by any firmware that they were not intended for.

7. A method of ensuring secure provisioning of a root-of-trust device, comprising:

writing, by hardware on the root-of-trust device, unique device secrets;

detecting, by the hardware on the root-of-trust device, a request from firmware for provisioning; and

performing, by at least one of the hardware or a device identifier composition engine, one or more security measures preventing the firmware from reading provisioned unique device secrets or any composite device identifier that is not meant to be accessed by the loaded firmware, wherein the one or more security measures comprises having the device identifier composition engine on the device be locked by the hardware when unique device secret is not provisioned.

8. The method of claim 7 , wherein the hardware on the root-of-trust device comprises a boot read only memory.

9. The method of claim 7 , wherein the one or more security measures comprises resetting the root-of-trust device after the unique device secrets are provisioned.

10. The method of claim 7 , wherein the one or more security measures comprises allowing unique device secrets provisioning only when a secure boot mechanism is enabled and enforced by the hardware before the firmware boots.

11. The method of claim 7 , wherein the one or more security measures comprises the device identifier composition engine automatically taking the measurements made at the time of boot, and automatically creating a composite device identifier corresponding to the firmware that booted.

12. The method of claim 11 , wherein the firmware is not validated by the hardware.

13. The method of claim 11 , wherein the firmware is validated by the hardware.

14. A system for ensuring secure provisioning of a root-of-trust device, comprising:

memory;

one or more processors in communication with the memory, the one or more processors configured to:

write unique device secrets or verify firmware to be used for writing unique device secrets during a boot process; and

prevent unintended or unverified firmware from provisioning, wherein preventing unverified firmware from provisioning comprises refusing to boot.

15. The system of claim 14 , wherein if the firmware is verified, the one or more processors allow the firmware to write the unique device secrets.

16. The system of claim 14 , wherein preventing unverified firmware from provisioning comprises locking access to storage areas.

17. The system of claim 14 , wherein preventing unintended firmware from provisioning comprises resetting the root-of-trust device after the unique device secrets are provisioned.

18. The system of claim 14 , wherein preventing unintended firmware from provisioning comprises allowing unique device secrets provisioning only when a secure boot mechanism is enabled and enforced by the one or more processors before the firmware boots.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 24, 2022
From: SATYAMSETTI, VIDYA
To: GOOGLE LLC
Reel/Frame 061509/0875 →
Continuity (2)
Related Publication 20240134986A1 · Apr 25, 2024
Related Publication 20240232361A9 · Jul 11, 2024
References Cited (9)
US 20200193065A1 · Smith · 2020 [cited by applicant]
US 20200322134A1 · Duval · 2020 [cited by examiner]
US 20220038272A1 · Hershman et al. · 2022 [cited by applicant]
US 20220067162A1 · Jeansonne · 2022 [cited by examiner]
US 20220198070A1 · Hunt · 2022 [cited by examiner]
US 20220382863A1 · Weizman · 2022 [cited by examiner]
DICE Layering Architecture, Mar. 9, 2020, Trust Computing Group, pp. 1-30 (Year: 2020). [cited by examiner]
Extended European search report for European Appl. No. 23174793.2 dated Feb. 23, 2024. 10 pages. [cited by applicant]
Tao, Z., et al., “DICE: A Formally Verified Implementation of DICE Measured Boot”, USENIX, The Advanced Computing Systems Association, Apr. 2021. pp. 1-17. [cited by applicant]