IP Library Granted Patent US 12,506,621
Granted Patent B2
US 12,506,621 · App. 18/270,936 · Granted Dec 23, 2025

Securing cryptographic keys

Inventor: Silvio Micali (Brookline, MA)
H04L9/3263H04L9/3247H04L9/3278
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,506,621
App. No.
18/270,936
Granted
Dec 23, 2025
Kind
B2
Abstract

A security device includes a covering device that, in response to an input signal, consistently provides a same random output signal that varies according to the microstructure of the covering device, where altering the microstructure of the covering device alters the random output signal, a key generation component that generates a secret key based on the random output signal, and a digital signature component that produces a digital signature of a message received by the security device using the secret key. The covering device surrounds at least a portion of the key generation component and the digital signature component to prevent access thereto and where accessing any of the components alters the microstructure of the covering device to alter the random output signal. The security device may be attached to an object and detaching the security device from the object may alter the microstructure of the covering device.

Claims (36)

1 . A security device, comprising:

a covering device that, in response to an input signal, consistently provides a random output signal that varies according to a microstructure of the covering device, wherein altering the microstructure of the covering device alters the random output signal and wherein modifying the covering device or detaching the security device from an object alters the microstructure of the covering device, the object being at least one of: a banknote, a consumer item, a manufactured component, a pharmaceutical product, an alimentary product, and a packet with content;

a key generation component that generates a secret key based on the random output signal; and

a digital signature component that produces a digital signature of a message received by the security device using the secret key, wherein the covering device surrounds at least a portion of the key generation component and the digital signature component to prevent access thereto and wherein accessing any of the components alters the microstructure of the covering device to alter the random output signal, wherein the secret key exists only long enough to sign the message.

2 . A security device according to claim 1 , further comprising:

a protective layer disposed on one or more outer surfaces of the security device to prevent the microstructure of the covering device from being altered under normal use of the security device.

3 . A security device according to claim 2 , wherein the protective layer is used to attach the security device to an object and wherein detaching the security device from the object alters the microstructure of the covering device.

4 . A security device according to claim 1 , wherein an entity digitally signs a public key corresponding to the secret key together with additional information that specifies at least one of: the input signal to the covering device and information about the object.

5 . A security device according to claim 1 , wherein additional security devices are attached to the object.

6 . A security device according to claim 1 , wherein an entity digitally signs a public key corresponding to the secret key together with some information and wherein a digital signature of the entity together with the security device constitute a given monetary value.

7 . A security device, according to claim 1 , wherein the input signal is authenticated by an entity.

8 . A security device according to claim 1 , further comprising:

a Faraday cage disposed about the security device.

9 . A security device according to claim 1 , wherein the key generation component also generates a public key corresponding to the secret key.

10 . A security device according to claim 9 , wherein the security device outputs the public key.

11 . A security device according to claim 1 , wherein the input signal is one of a plurality of challenge values stored in the security device.

12 . A security device according to claim 11 , wherein one of the input signals is chosen according to an internal counter of the security device.

13 . A security device according to claim 1 , further comprising:

a transformation component disposed between the covering device and the key generation component.

14 . A security device according to claim 13 , wherein the transformation component uses one of: a cryptographic hash function or an identity function to transform the random value signal.

15 . A security device according to claim 1 , wherein the security device runs unrelated computations when digitally signing a message.

16 . A method of digitally signing a message, comprising:

providing the message to a security device having a covering device that, in response to an input signal, consistently provides a random output signal that varies according to a microstructure of the covering device, wherein altering the microstructure of the covering device alters the random output signal and wherein modifying the covering device or detaching the security device from an object alters the microstructure of the covering device, the object being at least one of: a banknote, a consumer item, a manufactured component, a pharmaceutical product, an alimentary product, and a packet with content, the security device also having a key generation component that generates a secret key based on the random output signal and a digital signature component that produces a digital signature of a message received by the security device using the secret key, wherein the covering device surrounds at least a portion of the key generation component and the digital signature component to prevent access thereto and wherein accessing any of the components alters the microstructure of the covering device to alter the random output signal and the secret key exists only long enough to sign the message;

providing a challenge value to the security device; and

obtaining a digital signature from the security device.

17 . A method of digitally signing a message, according to claim 16 , further comprising:

an entity digitally signing a public key corresponding to the secret key.

18 . A method of digitally signing a message, according to claim 17 , wherein a digital signature of the entity together with the security device constitute a given monetary value.

19 . A method of digitally signing a message, according to claim 16 , wherein the input signal is authenticated by an entity.

20 . A method of digitally signing a message, according to claim 16 , further comprising:

the key generation component also generating a public key corresponding to the secret key.

21 . A method of digitally signing a message, according to claim 20 , further comprising:

the security device outputting the public key.

22 . A method of digitally signing a message, according to claim 16 , further comprising: the wherein a transformation component, disposed between the covering device and the key generation component, uses using one of: a cryptographic hash function or an identity function to transform the random value signal.

23 . A method of digitally signing a message, according to claim 16 , further comprising:

the security device running unrelated computations while digitally signing a message.

Continuity (1)
Related Publication 20240089120A1 · Mar 14, 2024
References Cited (60)
US 5478990A · Montanari et al. · 1995 [cited by applicant]
US 7681103B2 · Devadas et al. · 2010 [cited by applicant]
US 8029320B1 · Lustig et al. · 2011 [cited by applicant]
US 9116491B2 · Murakata · 2015 [cited by applicant]
US 9246686B1 · Holland et al. · 2016 [cited by applicant]
US 10523443B1 · Kleinman · 2019 [cited by examiner]
US 10607234B2 · Micali · 2020 [cited by applicant]
US 10803374B2 · Micali · 2020 [cited by examiner]
US 20080282206A1 · Anderson et al. · 2008 [cited by applicant]
US 20090008924A1 · Ophey et al. · 2009 [cited by applicant]
US 20090282259A1 · Skoric et al. · 2009 [cited by applicant]
US 20100073147A1 · Guajardo Merchan et al. · 2010 [cited by applicant]
US 20100250936A1 · Kusakawa et al. · 2010 [cited by applicant]
US 20110099117A1 · Schepers et al. · 2011 [cited by applicant]
US 20120033810A1 · Devadas et al. · 2012 [cited by applicant]
US 20130047209A1 · Satoh et al. · 2013 [cited by applicant]
US 20130127442A1 · Satoh et al. · 2013 [cited by applicant]
US 20130147511A1 · Koeberl et al. · 2013 [cited by applicant]
US 20130246809A1 · Beckmann et al. · 2013 [cited by applicant]
US 20130246881A1 · Goettfert et al. · 2013 [cited by applicant]
US 20140091832A1 · Gotze et al. · 2014 [cited by applicant]
US 20140108786A1 · Kreft · 2014 [cited by applicant]
US 20140266296A1 · Wang et al. · 2014 [cited by applicant]
US 20140334622A1 · Smyth et al. · 2014 [cited by applicant]
US 20150161415A1 · Kreft · 2015 [cited by applicant]
US 20150183257A1 · Glendenning et al. · 2015 [cited by applicant]
US 20170330200A1 · Micali et al. · 2017 [cited by applicant]
US 20180167211A1 · Falk et al. · 2018 [cited by applicant]
US 20180211264A1 · Micali · 2018 [cited by applicant]
US 20190026724A1 · Wade et al. · 2019 [cited by applicant]
US 20190236427A1 · Micali · 2019 [cited by applicant]
US 20190325171A1 · Obermaier et al. · 2019 [cited by applicant]
US 20200076624A1 · Cambou · 2020 [cited by applicant]
US 20200104101A1 · Satpathy et al. · 2020 [cited by applicant]
US 20200195447A1 · Shin · 2020 [cited by applicant]
CN 101422015A · 2009 [cited by applicant]
CN 101847296A · 2010 [cited by applicant]
CN 102077205A · 2011 [cited by applicant]
CN 102812472A · 2012 [cited by applicant]
CN 103345690A · 2013 [cited by applicant]
EP 2230793A2 · 2010 [cited by applicant]
JP 2004516706A · 2004 [cited by applicant]
JP 2008541260A · 2008 [cited by applicant]
JP 2011526113A · 2011 [cited by applicant]
JP 2011198317A · 2011 [cited by applicant]
JP 2014026227A · 2014 [cited by applicant]
JP 20130147511A · 2015 [cited by applicant]
JP 2015023301A · 2015 [cited by applicant]
JP 2019530271 · 2019 [cited by applicant]
WO WO2009156904A1 · 2009 [cited by applicant]
WO WO2016073041A1 · 2016 [cited by applicant]
WO WO2017023831A1 · 2017 [cited by applicant]
WO WO2018031437A1 · 2018 [cited by applicant]
Japanese Office Action Dated Nov. 21, 2024. [cited by applicant]
Vincent Immler, et al., “Secure Physical Enclosures from Covers with Tamper-Resistance”, https://doi.org/10.13154/tches.v2019.11.51-96, vol. 2019, Issue 1, Nov. 9, 2018. [cited by applicant]
International Preliminary Report on Patentability Dated Aug. 3, 2023. [cited by applicant]
Srinivas Devadas, et al., “Design and Implementation of PUF-Based “Unclonable” RFID ICs for Anti-Counterfeiting and Security Applications,” 2008 IEEE International Conference on RFID, Apr. 16-17, 2008. [cited by applicant]
Chiraag S. Juvekar, et al., “A Keccak-Based Wireless Authentication Tag with per-Query Key Update and Power-Glitch Attack Countermeasures,” 16.2, ISSCC 2016 / Session 16 / Innovations in Circuits and Systems Enabled by … [cited by applicant]
Saloomeh Shariati, “Image-based Physical Unclonable Functions for Anti-counterfeiting,” PhD thesis, Feb. 1, 2013, pp. 93-103, URL:https://dial.uclouvain.be/pr/boreal/object/boreal:124681/datastream/PDF_01/view. [cited by applicant]
Japanese Office Action Dated Jul. 30, 2025. [cited by applicant]