IP Library › Granted Patent US 12,463,831
Granted Patent B2
US 12,463,831 · App. 18/469,470 · Granted Nov 4, 2025

Device signing model

Inventors: Arvind Mukund (San Diego, CA); Phalguni Bumhyavarapu (San Diego, CA); Arun Menon (San Diego, CA)
Assignee: QUALCOMM Incorporated
H04L9/3265G06F21/10H04L9/30
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,463,831
App. No.
18/469,470
Granted
Nov 4, 2025
Kind
B2
Abstract

Systems and techniques are provided for secure processing. For instance, a process can include generating a model signing key, wherein the device is associated with a device model, and wherein the model signing key is shared by apparatuses of the device model; obtaining a certificate for a device-unique public key of the apparatus; signing the device-unique public key based on the model signing key; and transmitting the signed device-unique public key for authentication.

Claims (62)

1 . An apparatus for secure processing, comprising:

a memory system comprising instructions; and

a processor system coupled to the memory system, wherein the processor system is configured to:

generate a model signing key, wherein the apparatus is associated with a device model, and wherein the model signing key is shared by apparatuses of the device model;

obtain a certificate for a device-unique public key of the apparatus;

sign the device-unique public key based on the model signing key;

transmit the signed device-unique public key to a digital rights management service for authentication;

receive, in response to the transmitted signed device-unique public key, a certificate for authentication from the digital rights management service;

transmit the certificate for authentication to the digital rights management service; and

receive, from the digital rights management service, a digital rights management certificate for accessing content.

2 . The apparatus of claim 1 , wherein a public key associated with the model signing key was transmitted to the digital rights management service as a part of manufacturing the apparatus.

3 . The apparatus of claim 1 , wherein the processor system is further configured to:

obtain a boot certificate chain of the apparatus; and

transmit the boot certificate chain for authentication.

4 . The apparatus of claim 1 , wherein the processor system is further configured to:

receive an authentication request in response to a request for media access, wherein the model signing key is generated based on the authentication request; and

receive, in response to the transmitted signed device-unique public key, a certificate for authentication.

5 . The apparatus of claim 1 , wherein the memory system includes a set of fuses, and wherein the model signing key is generated based on values blown into the set of fuses.

6 . The apparatus of claim 5 , wherein the values blown into the set of fuses is set during a manufacturing process.

7 . The apparatus of claim 5 , wherein the values blown into the set of fuses is shared by apparatuses of the device model.

8 . The apparatus of claim 1 , wherein the model signing key is generated by a secure element of the processor system.

9 . The apparatus of claim 1 , wherein the processor system is further configured to discard the model signing key after the model signing key is used for signing the device-unique public key.

10 . A method for secure processing by a device, comprising:

generating a model signing key, wherein the device is associated with a device model, and wherein the model signing key is shared by apparatuses of the device model;

obtaining a certificate for a device-unique public key of the device;

signing the device-unique public key based on the model signing key;

transmitting the signed device-unique public key to a digital rights management service for authentication;

receiving, in response to the transmitted signed device-unique public key, a certificate for authentication from the digital rights management service;

transmitting the certificate for authentication to the digital rights management service; and

receiving, from the digital rights management service, a digital rights management certificate for accessing content.

11 . The method of claim 10 , wherein a public key associated with the model signing key was transmitted to the digital rights management service as a part of manufacturing the device.

12 . The method of claim 10 , further comprising:

obtaining a boot certificate chain of the device; and

transmitting the boot certificate chain for authentication.

13 . The method of claim 10 , further comprising:

receiving an authentication request in response to a request for media access, wherein the model signing key is generated based on the authentication request; and

receiving, in response to the transmitted signed device-unique public key, a certificate for authentication.

14 . The method of claim 10 , wherein a memory of the device includes a set of fuses, and wherein the model signing key is generated based on values blown into the set of fuses.

15 . The method of claim 14 , wherein the values blown into the set of fuses is set during a manufacturing process of the device.

16 . The method of claim 14 , wherein the values blown into the set of fuses is shared by apparatuses of a device model.

17 . The method of claim 10 , wherein the model signing key is generated by a secure element of a processor system of the device.

18 . The method of claim 10 , further comprising discarding the model signing key after the model signing key is used for signing the device-unique public key.

19 . A non-transitory computer-readable medium having stored thereon instructions that, when executed by a processor system of a device, cause the processor system to:

generate a model signing key, wherein the device is associated with a device model, and wherein the model signing key is shared by apparatuses of the device model;

obtain a certificate for a device-unique public key of the device;

sign the device-unique public key based on the model signing key;

transmit the signed device-unique public key to a digital rights management service for authentication;

receive, in response to the transmitted signed device-unique public key, a certificate for authentication from the digital rights management service;

transmit the certificate for authentication to the digital rights management service; and

receive, from the digital rights management service, a digital rights management certificate for accessing content.

20 . The non-transitory computer-readable medium of claim 19 , wherein a public key associated with the model signing key was transmitted to the digital rights management service as a part of manufacturing.

21 . The non-transitory computer-readable medium of claim 19 , wherein the instructions further cause the processor system to:

obtain a boot certificate chain of the device; and

transmit the boot certificate chain for authentication.

22 . The non-transitory computer-readable medium of claim 19 , wherein the instructions further cause the processor system to:

receive an authentication request in response to a request for media access, wherein the model signing key is generated based on the authentication request; and

receive, in response to the transmitted signed device-unique public key, a certificate for authentication.

23 . The non-transitory computer-readable medium of claim 19 , wherein a memory of the device includes a set of fuses, and wherein the model signing key is generated based on values blown into the set of fuses.

24 . The non-transitory computer-readable medium of claim 23 , wherein the values blown into the set of fuses is set during a manufacturing process.

25 . The non-transitory computer-readable medium of claim 23 , wherein the values blown into the set of fuses is shared by apparatuses of the device model.

26 . The non-transitory computer-readable medium of claim 19 , wherein the model signing key is generated by a secure element of a processor system of the device.

27 . The non-transitory computer-readable medium of claim 19 , wherein the instructions cause the processor system to discard the model signing key after the model signing key is used for signing the device-unique public key.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 3, 2023
From: MUKUND, ARVIND; BUMHYAVARAPU, PHALGUNI; MENON, ARUN
To: QUALCOMM INCORPORATED
Reel/Frame 065112/0211 →
Continuity (1)
Related Publication 20250097053A1 · Mar 20, 2025
References Cited (21)
US 9281949B2 · Nair et al. · 2016 [cited by applicant]
US 11018871B2 · Sood · 2021 [cited by examiner]
US 11283626B2 · Lian · 2022 [cited by examiner]
US 20090158028A1 · Jung et al. · 2009 [cited by applicant]
US 20100189265A1 · Ito · 2010 [cited by examiner]
US 20110258426A1 · Mujtaba · 2011 [cited by examiner]
US 20130019110A1 · Lee · 2013 [cited by examiner]
US 20140047558A1 · Veerubhotla · 2014 [cited by examiner]
US 20140064480A1 · Hartley · 2014 [cited by examiner]
US 20150086019A1 · Tamminen · 2015 [cited by examiner]
US 20150113627A1 · Curtis · 2015 [cited by examiner]
US 20180007033A1 · Ajitomi · 2018 [cited by examiner]
US 20190363894A1 · Kumar Ujjwal · 2019 [cited by examiner]
US 20190372780A1 · Messerges · 2019 [cited by examiner]
US 20200004933A1 · Cocchi · 2020 [cited by examiner]
US 20200389326A1 · Teglas · 2020 [cited by examiner]
US 20210028933A1 · Medvinsky · 2021 [cited by examiner]
US 20220237333A1 · Peng · 2022 [cited by examiner]
US 20220284100A1 · Simon · 2022 [cited by examiner]
US 20230394129A1 · Boyapalle · 2023 [cited by examiner]
International Search Report and Written Opinion—PCT/US2024/046249—ISA/EPO—Nov. 19, 2024. [cited by applicant]