IP Library › Granted Patent US 12,657,279
Granted Patent B2
US 12,657,279 · App. 18/724,878 · Granted Jun 16, 2026

Firmware authentication

Inventors: Jeffrey Kevin Jeansonne (Spring, TX); Mason Andrew Gunyuzlu (Spring, TX)
Assignee: Hewlett-Packard Development Company, L.P.
G06F21/44G06F21/572G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,657,279
App. No.
18/724,878
Granted
Jun 16, 2026
Kind
B2
Abstract

An example computing device comprises a memory to store control instructions, and a processor to: perform a first authentication of the control instructions using a first key; and in response to receipt of a command to enable a second authentication of the control instructions, add a second key to a one-time programmable portion of the memory, wherein the command is signed using the first key, the second key to perform a second authentication of the control instructions with the first key to perform the first authentication of the control instructions.

Claims (62)

1 . A computing device, comprising:

a memory comprising:

a read-only memory (ROM) bootloader portion to store control instructions and a first key; and

a one-time programmable portion; and

a processor to:

perform a first authentication of the control instructions using the first key;

in response to receipt of a command to enable a second authentication of the control instructions, add a second key to the one-time programmable portion of the memory, wherein the command is signed using the first key; and

use the second key to perform a second authentication of the control instructions.

2 . The computing device of claim 1 , wherein the processor is to receive the control instructions from an external memory.

3 . The computing device of claim 1 , wherein the processor is to:

when an update flag of the one-time programmable portion of the memory is set to a first value, perform the first authentication of the control instructions using the first key;

in response to verifying the second authentication using the first key, set the update flag to a second value;

enable receipt of the command to enable the second authentication of the control instructions in response to the update flag set to the second value; and

add the second key to the one-time programmable portion of the memory.

4 . The computing device of claim 3 , wherein the processor is to:

when the update flag of the one-time programmable portion of the memory is set to the first value, block write access to the memory; and

in response to verifying the second authentication, allow write access to the memory to allow the second key to be added to the one-time programmable portion of the memory.

5 . The computing device of claim 1 , wherein the second key is a one-time signing key selected from a plurality of possible one-time signing keys of a hash-based signature scheme.

6 . The computing device of claim 1 , wherein the second key is associated with a quantum-safe cryptographic protocol.

7 . The computing device of claim 6 , wherein the quantum-safe cryptographic protocol comprises a Leighton-Micali Signature (LMS) scheme or an extended Merkle Signature Scheme (XMSS).

8 . A computing device, comprising:

a memory comprising:

a read-only memory (ROM) bootloader portion to store control instructions and a first key; and

a one-time programmable portion; and

a processor to:

perform a first authentication of the control instructions using the first key;

after performing the first authentication of the control instructions, execute the control instructions to enable the computing device to obtain a second key; wherein

store the second key in the one-time programmable portion of the memory; and

perform a second authentication of the control instructions using the second key.

9 . The computing device of claim 8 , wherein the processor is to:

execute the control instructions to enable the computing device to obtain a second authentication code;

store the second authentication code in the memory; and

use the second authentication code to perform the second authentication.

10 . The computing device of claim 9 , wherein:

the second authentication code comprises a header, the header comprising:

the second key;

a first checking key; and

a second checking key; and

prior to enabling the computing device to obtain the second key, the processor is to verify the second authentication code by:

verifying a first key checking signature of the second authentication code using the first checking key; and

verifying a second key checking signature of the second authentication code using the second checking key.

11 . The computing device of claim 10 , wherein;

the first checking key is to verify the second authentication code using a first verification protocol of the first key; and

the second checking key is to verify the second authentication code using a second verification protocol of the second key.

12 . The computing device of claim 11 , wherein the processor is to:

sign the second authentication code using a first signature generated using the first checking key; and

sign the second authentication code using a second signature generated using the second checking key; and

use the first signature and the second signature to verify validity of the second authentication code prior to enabling the computing device to obtain the second key.

13 . The computing device of claim 8 , wherein the second key is associated with a quantum-safe cryptographic protocol.

14 . The computing device of claim 8 , wherein the second key is associated with a Leighton-Micali Signature (LMS) scheme or an extended Merkle Signature Scheme (XMSS).

15 . A non-transitory computer-readable medium comprising instructions that, when executed by a processor of a computing device, cause the computing device to:

perform a first authentication of control instructions received from an external memory using a first key stored in a read-only memory (ROM) bootloader portion of a memory of the computing device and using a first cryptographic protocol;

receive, from a trusted source, a second key;

store the second key in a one-time programmable portion of the memory; and

perform a second authentication of the control instructions using the second key and using a second cryptographic protocol.

16 . The non-transitory computer-readable medium of claim 15 , wherein the instructions, when executed by the processor, cause the computing device to:

allow write access to the memory, to allow the second key to be stored in the one-time programmable portion of the memory, in response to receipt of an authentication indicator indicating that the trusted source has verified the second cryptographic protocol.

17 . The non-transitory computer-readable medium of claim 16 , wherein the instructions, when executed by the processor, cause the computing device to:

disable write access to the memory after storing the second key in the one-time programmable portion of the memory.

18 . The non-transitory computer-readable medium of claim 15 , wherein the second key is a quantum-safe public cryptography key.

19 . The non-transitory computer-readable medium of claim 18 , wherein the second cryptographic protocol comprises a quantum-safe cryptographic protocol.

20 . The non-transitory computer-readable medium of claim 18 , wherein the second cryptographic protocol comprises a Leighton-Micali Signature (LMS) scheme or an extended Merkle Signature Scheme (XMSS).

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 28, 2024
From: JEANSONNE, JEFFREY KEVIN; GUNYUZLU, MASON ANDREW
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 067871/0468 →
Continuity (1)
Related Publication 20250068715A1 · Feb 27, 2025
References Cited (54)
US 7069452B1 · Hind · 2006 [cited by examiner]
US 10630478B1 · Yavuz · 2020 [cited by applicant]
US 20030026427A1 · Couillard · 2003 [cited by examiner]
US 20050125652A1 · Singer · 2005 [cited by examiner]
US 20060291265A1 · Schrom · 2006 [cited by examiner]
US 20070043948A1 · Bugbee · 2007 [cited by examiner]
US 20070113102A1 · Glen · 2007 [cited by applicant]
US 20100189262A1 · Ducharme et al. · 2010 [cited by applicant]
US 20110066787A1 · Markey et al. · 2011 [cited by applicant]
US 20110142242A1 · Tanaka · 2011 [cited by applicant]
US 20120137137A1 · Brickell · 2012 [cited by examiner]
US 20120210115A1 · Park · 2012 [cited by examiner]
US 20130111203A1 · Baltes · 2013 [cited by examiner]
US 20140033305A1 · Nelson · 2014 [cited by examiner]
US 20140359268A1 · Jauhiainen · 2014 [cited by examiner]
US 20150058979A1 · Peeters · 2015 [cited by examiner]
US 20150186651A1 · Kim · 2015 [cited by examiner]
US 20160154744A1 · Zheng · 2016 [cited by examiner]
US 20160162669A1 · Mikhailov · 2016 [cited by examiner]
US 20160182238A1 · Dewan · 2016 [cited by examiner]
US 20170090909A1 · Guo et al. · 2017 [cited by applicant]
US 20170177373A1 · Jeansonne · 2017 [cited by examiner]
US 20170180139A1 · Jeansonne · 2017 [cited by examiner]
US 20170244568A1 · Brickell · 2017 [cited by examiner]
US 20170272250A1 · Kaliski, Jr. · 2017 [cited by applicant]
US 20180088927A1 · Zhao · 2018 [cited by examiner]
US 20180109377A1 · Fu · 2018 [cited by applicant]
US 20190065750A1 · Bolan · 2019 [cited by examiner]
US 20190166117A1 · Kumar · 2019 [cited by examiner]
US 20190207756A1 · Vass et al. · 2019 [cited by applicant]
US 20190213359A1 · Kepa · 2019 [cited by examiner]
US 20200097658A1 · Samuel · 2020 [cited by examiner]
US 20200104221A1 · Kost · 2020 [cited by examiner]
US 20200177757A1 · Ono · 2020 [cited by examiner]
US 20200184077A1 · Venkataraman · 2020 [cited by examiner]
US 20200374130A1 · Strong · 2020 [cited by examiner]
US 20210240567A1 · Hsu · 2021 [cited by examiner]
US 20210377049A1 · Nix · 2021 [cited by examiner]
US 20210389958A1 · Choi · 2021 [cited by examiner]
US 20220067166A1 · Kwon · 2022 [cited by examiner]
US 20220198018A1 · Wentz · 2022 [cited by examiner]
US 20220353061A1 · Pala · 2022 [cited by examiner]
US 20220382872A1 · Sakib · 2022 [cited by examiner]
US 20220405392A1 · Nix · 2022 [cited by examiner]
US 20230122962A1 · Liu · 2023 [cited by examiner]
US 20230327885A1 · Griffin · 2023 [cited by examiner]
US 20240152284A1 · Lee · 2024 [cited by examiner]
US 20240267211A1 · Shingala · 2024 [cited by examiner]
CN 109214168A · 2019 [cited by examiner]
CN 110795126A · 2020 [cited by examiner]
CN 114003915A · 2022 [cited by examiner]
JP 2021092848A · 2021 [cited by examiner]
WO WO2021262161A1 · 2021 [cited by examiner]
Kumar, Vinay BY, et al. “Post-quantum secure boot.” 2020 Design, Automation & Test in Europe Conference & Exhibition (Date). IEEE, 2020. (Year: 2020). [cited by examiner]