IP Library Granted Patent US 10,419,407
Granted Patent B2
US 10,419,407 · App. 15/987,978 · Granted Sep 17, 2019

System and method for controlling features on a device

Inventors: Michael Daskalopoulos (San Francisco, CA); Ashok Vadekar (Rockwood, CA); David Wong (Mississauga, CA); William Lattin (Los Altos, CA); Daniel O'Loughlin (Aptos, CA); David R. Sequino (Lansdowne, VA)
Assignee: Certicom Corp.
H04L63/0428G06F21/10G06F21/57H04L63/061H04L67/125G06F2221/0742G06F2221/2135
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,419,407
App. No.
15/987,978
Granted
Sep 17, 2019
Kind
B2
Abstract

Trust between entities participating in an upgrade or enablement/disablement process is established and, to facilitate this remotely and securely, a highly tamper resistant point of trust in the system that is being produced is used. This point of trust enables a more efficient distribution system to be used. Through either a provisioning process or at later stages, i.e. subsequent to installation, manufacture, assembly, sale, etc.; the point of trust embodied as a feature controller on the device or system being modified is given a feature set (or updated feature set) that, when validated, is used to enable or disable entire features or to activate portions of the feature.

Claims (41)

1. A method performed at a remote server, the method comprising:

participating in a public key based key agreement with a feature controller in a device, by performing cryptographic operations using a connection that enables transfer of data between the remote server and the feature controller, to establish a shared key between the remote server and the feature controller;

storing the shared key and an identifier associated with the device in a memory of the remote server, the identifier being derived from at least a portion of a public key of a static key pair stored in a secure memory in the feature controller;

encrypting, using a symmetric cipher and the shared key, a control instruction for the feature controller to control features in the device;

generating a signature using the control instruction and information provided by the feature controller in the device during the public key based key agreement, the information comprising the identifier associated with the device;

generating a message comprising the encrypted control instruction and the signature; and

sending the message to the feature controller of the device to thereby securely control features in the device.

2. The method of claim 1 , wherein the information provided by the feature controller in the device comprises an ephemeral public key received by the remote server during the key agreement, and the signature is generated using at least the control instruction, the ephemeral public key, and the identifier associated with the device.

3. The method of claim 1 , wherein the public key based key agreement comprises an elliptic curve based key agreement.

4. The method of claim 1 , wherein the public key based key agreement comprises an elliptic curve Menezes-Qu-Vanstone (ECMQV) key agreement.

5. The method of claim 1 , wherein the identifier associated with the device is generated using a static key pair.

6. The method of claim 1 , wherein the control instruction comprises feature control programming.

7. The method of claim 1 , wherein the control instruction comprises at least one command.

8. The method of claim 1 , wherein the identifier is unique to the device.

9. The method of claim 1 , wherein the identifier is unique to a group comprising a plurality of devices.

10. The method of claim 1 , wherein the message is generated by concatenating the encrypted control instruction with the signature.

11. The method of claim 1 , wherein the device is a digital television system-on-chip device.

12. The method of claim 1 , wherein the device is an integrated circuit device.

13. A control server comprising:

a processor; and

at least one memory, the memory comprising computer executable instructions that when executed by the processor operate the control server to perform the following method:

participating in a public key based key agreement with a feature controller in a device, by performing cryptographic operations using a connection that enables transfer of data between the control server and the feature controller to establish a shared key between the control server and the feature controller;

storing the shared key and an identifier associated with the device in a memory of the control server, the identifier being derived from at least a portion of a public key of a static key pair stored in a secure memory in the feature controller;

encrypting, using a symmetric cipher and the shared key, a control instruction for the feature controller to control features in the device;

generating a signature using the control instruction and information provided by the feature controller in the device during the public key based key agreement, the information comprising the identifier associated with the device; and

generating a message comprising the encrypted control instruction and the signature; and

sending the message to the feature controller of the device to thereby securely control features in the device.

14. A non-transitory computer readable storage medium comprising computer executable instructions for performing operations at a remote server for provisioning features in a device, the operations comprising:

participating in a public key based key agreement with a feature controller in a device, by performing cryptographic operations using a connection that enables transfer of data between the remote server and the feature controller, to establish a shared key between the remote server and the feature controller;

storing the shared key and an identifier associated with the device in a memory of the remote server, the identifier being derived from at least a portion of a public key of a static key pair stored in a secure memory in the feature controller;

encrypting, using a symmetric cipher and the shared key, a control instruction for the feature controller to provision features in the device;

generating a signature using the control instruction and information provided by the feature controller in the device during the public key based key agreement, the information comprising the identifier associated with the device;

generating a message comprising the encrypted control instruction and the signature; and

sending the message to the feature controller of the device to thereby securely provision features in the device.

15. The computer readable storage medium of claim 14 ,

wherein the information provided by the feature controller in the device comprises an ephemeral public key received by the remote server during the key agreement, and the signature is generated using at least the control instruction, the ephemeral public key, and the identifier associated with the device.

16. The computer readable storage medium of claim 14 ,

wherein the public key based key agreement comprises an elliptic curve based key agreement.

17. The computer readable storage medium of claim 14 ,

wherein the public key based key agreement comprises an elliptic curve Menezes-Qu-Vanstone (ECMQV) key agreement.

18. The computer readable storage medium of claim 14 , wherein the identifier associated with the device is generated using a static key pair.

Assignments (4)
NUNC PRO TUNC ASSIGNMENT Recorded Jun 19, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064270/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064104/0103 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 2, 2019
From: CERTICOM CORP.
To: BLACKBERRY LIMITED
Reel/Frame 050610/0937 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 17, 2018
From: DASKALOPOULOS, MICHAEL; VADEKAR, ASHOK; WONG, DAVID; LATTIN, BILL; O'LOUGHLIN, DANIEL; SEQUINO, DAVID R.
To: CERTICOM CORP.
Reel/Frame 047798/0720 →
Continuity (4)
Division 13615311 · Sep 13, 2012
Continuation 12314610 · Dec 12, 2008
Provisional Application 60996976 · Dec 13, 2007
Related Publication 20180278587A1 · Sep 27, 2018
Cited By (1)
US 12,417,138