IP Library › Granted Patent US 12,739,103
Granted Patent B2
US 12,739,103 · App. 18/612,117 · Granted Sep 15, 2026

Cryptographic agility

Inventors: Melissa Azouaoui (Norderstedt, DE); Christoph Baumann (Graz, AT); Florian Boehl (Leuven, BE); Joppe Willem Bos (Wijgmaal, BE); Gareth Thomas Davies (Leuven, BE); Sarah Esmann (Hamburg, DE)
Assignee: NXP B.V.
H04L9/0825H04L9/085
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,739,103
App. No.
18/612,117
Granted
Sep 15, 2026
Kind
B2
Abstract

A method for updating a device, including: receiving, by the device, a public one-time signature key; receiving, by the device, a secret encryption key; receiving an encrypted update package and signature from an update provider; verifying the signature using the public one-time signature key; decrypting the encrypted update package using the secret encryption key; and updating the device using the decrypted update package.

Claims (91)

1 . A method for updating a device, the method comprising:

during a provisioning process:

receiving, by the device, a public one-time signature (OTS) key;

receiving, by the device, a secret encryption key; and

provisioning code to run a one-time signature verification in the device; and

during an update process:

receiving at least one signed message including an encrypted update package and a command to enable a critical update mode from an update provider;

verifying the signature using the public OTS key;

when the signature is verified, enabling the critical update mode;

decrypting the encrypted update package using the secret encryption key; and

updating the device using the decrypted update package.

2 . The method of claim 1 , wherein, during the provisioning process, the method further comprising;

provisioning the device with a secret seed; and

reserving code space in the device for key generation using the secret seed.

3 . A method for updating a device by an update provider, the method comprising:

sending, by the update provider to the device, a critical update mode command signed using a first public one-time signature (OTS) key;

encrypting an update package using a secret encryption key;

signing a message including the encrypted update package using a second secret one-time signature key; and

sending the signed message including the encrypted update package to the device to update or replace code stored on the device to perform one or more cryptographic operations, the one or more cryptographic operations including a one-time signature verification operation.

4 . A method for updating a device, the method comprising:

during a provisioning process:

receiving, by the device, a first public one-time signature key and a second public one-time signature key;

receiving, by the device, a secret encryption key;

receiving, by the device, code to perform one or more cryptographic operations on the device, the one or more cryptographic operations including a one-time signature verification;

during a critical update process:

receiving, by the device, an update mode message and a first signature;

verifying, by the device, the first signature using the first public one-time signature key;

in response to verifying the first signature, entering, by the device, a critical update mode;

receiving, by the device, an encrypted update package and a second signature from an update provider;

verifying, by the device, the second signature using the second public one-time signature key;

in response to verifying the second signature, decrypting, by the device, the encrypted update package using the secret encryption key; and

updating, by the device, the code on the device using the decrypted update package.

5 . A method for updating a device by an update provider, the method comprising:

during a provisioning process:

sending a first public one-time signature key and a second public one-time signature key to the device;

sending a secret encryption key; and

sending code to the device, the code configured to cause the device to perform one or more cryptographic operations, the one or more cryptographic operations including a one-time signature verification operation;

during a critical update process:

producing a first signature of an update mode message using a first secret one-time signature key corresponding to the first public one-time signature key;

sending the update mode message and the first signature to the device to cause the device to enter a critical update mode;

encrypting an update package using the secret encryption key, the update package including update code to update or replace the code on the device;

producing a second signature of the encrypted update package using a second secret one-time signature key corresponding to the second public one-time signature key; and

sending the encrypted update package and second signature to the device.

6 . A method for requesting a certificate by an updated device, the method comprising:

receiving, by the updated device, a public certification authority signature key;

receiving, by the updated device, a secret one-time signature key;

generating a new updated device secret key and public key;

producing a signature request for the new updated device public key;

producing a first signature of the signature request using the secret one-time signature key;

sending the signature request and the first signature to a certification authority; and

receiving a certificate including a signature of the certificate from the certification authority.

7 . The method of claim 6 , further comprising:

provisioning the updated device with a secret seed; and

reserving code space in the updated device for key generation using the secret seed.

8 . The method of claim 6 , further comprising:

provisioning code to run a one-time signature verification in the updated device.

9 . The method of claim 6 , wherein the first signature is based on a secret certification authority signature key.

10 . A method for generating a certificate for an updated device, the method comprising:

sending a public certification authority signature key to the updated device;

sending a secret one-time signature key to the updated device;

receiving a certificate request for a new updated device public key and a first signature for the certificate request from the updated device, wherein the first signature is based on the secret one-time signature key;

verifying the first signature and the certificate request;

producing a certificate for the new updated device public key including a second signature of the certificate using a secret certification authority signature key corresponding to the public certification authority signature key; and

sending the certificate and second signature to the updated device.

11 . The method of claim 1 , wherein, during the provisioning process, receiving, by the device, the public OTS key, comprises:

receiving, by the device, a first public OTS key and a second public OTS key.

12 . The method of claim 11 , wherein the at least one signed message includes a first message signed by a first OTS key and including the command and a second message signed by a second OTS key and including the encrypted update package.

13 . The method of claim 12 , further comprising:

receiving, by the device, the first message;

verifying the first message using the first public OTS key;

in response to verifying the first message:

enabling the critical update mode based on the command of the first message; and

disabling any updates that utilize current cryptographic schemes;

receiving, by the device, the second message;

verifying the second message using the second public OTS key; and

in response to verifying the second message, decrypting the encrypted update package using the secret encryption key; and

updating the device using the decrypted update package.

14 . The method of claim 1 , further comprising:

provisioning the device with a secret seed; and

reserving code space in the device for key generation using the secret seed.

15 . The method of claim 3 , wherein, during a provisioning process that is performed before sending the critical update mode command, the method comprises:

provisioning the device with the first public OTS key and the second public OTS key;

provisioning the device with the secret encryption key; and

provisioning code to perform one or more cryptographic operations on the device, the one or more operations including a one-time signature verification operation.

16 . The method of claim 3 , further comprising:

provisioning the device with a secret seed; and

reserving code space in the device for key generation using the secret seed.

17 . The method of claim 4 , wherein in response to verifying the first signature, the method further comprises disabling any updates that utilize the code to perform the one or more cryptographic operations.

18 . The method of claim 4 , further comprising:

provisioning the device with a secret seed; and

reserving code space in the device for key generation using the secret seed.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 20, 2024
From: AZOUAOUI, MELISSA; BAUMANN, CHRISTOPHER; BOEHL, FLORIAN; BOS, JOPPE WILLEM; DAVIES, GARETH THOMAS; ESMANN, SARAH
To: NXP B.V.
Reel/Frame 069653/0840 →
Continuity (1)
Related Publication 20250300812A1 · Sep 25, 2025
References Cited (31)
US 11593488B2 · Wentz · 2023 [cited by applicant]
US 12177338B2 · Van Vredendaal · 2024 [cited by examiner]
US 20130318357A1 · Abraham · 2013 [cited by examiner]
US 20170214662A1 · Chu · 2017 [cited by examiner]
US 20180217828A1 · Madrid · 2018 [cited by examiner]
US 20220069984A1 · Ahn · 2022 [cited by examiner]
US 20230098090A1 · Barui · 2023 [cited by examiner]
US 20230246826A1 · Van Vredendaal · 2023 [cited by applicant]
EP 4160980A1 · 2021 [cited by applicant]
EP 4020435A1 · 2022 [cited by applicant]
EP 4160982A1 · 2022 [cited by applicant]
EP 4068686A1 · 2022 [cited by applicant]
WO 2022211899A1 · 2022 [cited by applicant]
Fabio Campos et al., “LMS vs XMSS: Comparison of Stateful Hash-Based Signature Schemes on ARM Cortex-M4,” AFRICACRYPT 2020, LNCS 12174, pp. 258-277, 2020. [cited by applicant]
Hans Georg Shaathun, et al., “A Trellis-Based Bound on (2,1)-Separating Codes,” Conference Paper in Lecture Notes in Computer Science, Dec. 2005. [cited by applicant]
Sanotsh Ghosh, et al., “Lightweight Post-Quantum-Secure Digital Signature Approach for IoT Motes,” Security and Privacy Research, Intel Labs, Intel Corporation. [cited by applicant]
David McGrew, et al., “State Management for Hash-Based Signatures”. [cited by applicant]
Roberto Roman, et al., “A Lightweight Remote Attestation Using PUFs and Hash-Based Signatures for Low-End IoT Devices,” Future Generation Computer Systems 148, 2023, pp. 425-435, Jun. 8, 2023. [cited by applicant]
Santosh Ghosh, et al., “Intelligent IoT Motes: Preventing Their Abuse at the Weakest Entry Point,” Mar./Apr. 2019, IEEE 2168-2356/19. [cited by applicant]
Jean-Philippe Aumasson, et al., “SPHINCS+ submission to the NIST post-quantum project, v.3”, 2020. [cited by applicant]
Roberto Avanzi, et al., “CRYSTALS-kyber algorithm specifications and supporting documentation (version 3.02)”, 2021. [cited by applicant]
Ward Beullens, “Breaking Rainbow takes a weekend on a laptop”, Advances in Cryptology—CRYPTO 2022—42nd Annual International Cryptology Conference, CRYPTO2022, Santa Barbara, CA, USA, Aug. 15-18, 2022, Proceedings, Part … [cited by applicant]
Wouter Castryck and Thomas Decru, “An efficient key recovery attack on SIDH,” Advances in Cryptology—EUROCRYPT 2023—42nd Annual International Conference on the Theory and Applications of Cryptographic Techniques, Lyon, … [cited by applicant]
David A. Cooper, et al., “NIST Special Publication 800-208: Recommendation for stateful hash-based signature schemes,” 2020. [cited by applicant]
C. Dods, et al.,, “Hash based digital signature schemes,” Cryptography and Coding, 10th IMA International Conference, Cirencester, UK, Dec. 19-21, 2005, Proceedings (Nigel P. Smart, ed.), Lecture Notes in Computer Scien… [cited by applicant]
Léo Ducas, et al., “CRYSTALS-Dilithium algorithm specification and supporting documentation (version 3.1)”, 2021. [cited by applicant]
Pierre-Alain Fouque, et al., “Falcon: Fast-fourier lattice-based compact signatures over NTRU specification v1.2” Jan. 10, 2020, 2020. [cited by applicant]
Andreas Huelsing, et al., “XMSS: extended Merkle Signature Scheme,” RFC 8391, May 2018. [cited by applicant]
David McGrew, Michael Curcio, and Scott Fluhrer, Leighton-Micali Hash-BasedSignatures, RFC 8554, Apr. 2019. [cited by applicant]
National Institute of Standards and Technology, Post-quantum cryptography: Digital signature schemes, https://csrc.nist.gov/Projects/pqc-dig-sig/signaturesround-1-additional. [cited by applicant]
Post-quantum cryptography standardization, https://csrc.nist.gov/Projects/Post-Quantum-Cryptography/Standardization.Post-Quantum-Cryptography. [cited by applicant]