US2010122076A1PendingUtilityA1

Security method

Assignee: ARISTOCRAT TECHNOLOGIES AUPriority: Sep 30, 2008Filed: Sep 29, 2009Published: May 13, 2010
Est. expirySep 30, 2028(~2.2 yrs left)· nominal 20-yr term from priority
G06F 9/4401G06F 21/645G06F 21/575
36
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A security method for verifying a client device comprising: loading and executing a boot loader at the client device which establishes a connection to a boot compliance server; sending a first cryptographic element from the boot compliance server to the client device; generating a first cryptographic response with the first cryptographic element based on at least part of the boot loader and sending the first cryptographic response to the boot compliance server for verification; and continuing the boot process upon successful verification of the first cryptographic response.

Claims

exact text as granted — not AI-modified
1 . A security method for verifying a client device comprising:
 loading and executing a boot loader at the client device which establishes a connection to a boot compliance server;   sending a first cryptographic element from the boot compliance server to the client device;   generating a first cryptographic response with the first cryptographic element based on at least part of the boot loader and sending the first cryptographic response to the boot compliance server for verification; and   continuing the boot process upon successful verification of the first cryptographic response.   
   
   
       2 . A method as claimed in  claim 1 , comprising:
 sending at least a second cryptographic element to the client device subsequent to the successful verification of the first cryptographic response;   generating a second cryptographic response with the second cryptographic element based on at least part of the operating system; and   loading the operating system upon successful verification of the second cryptographic response.   
   
   
       3 . A method as claimed in  claim 1 , wherein the client device takes at least one protective action upon unsuccessful verification of the first cryptographic response. 
   
   
       4 . A method as claimed in  claim 1 , wherein the first cryptographic element is a first hash key and generating the cryptographic response comprises applying a corresponding hash function to the boot loader using the first hash key. 
   
   
       5 . A method as claimed in  claim 2 , wherein sending at least a second cryptographic element comprises sending a valid second cryptographic response to the client device whereby the client device can verify the operating system without further reference to the boot compliance server. 
   
   
       6 . A method as claimed in  claim 2 , comprising sending a plurality of second cryptographic elements corresponding to respective ones of a plurality of possible operating versions to the client device and determining at the client device a relevant one of the second cryptographic elements to apply. 
   
   
       7 . A method as claimed in  claim 1 , wherein establishing a connection comprises establishing an encrypted connection. 
   
   
       8 . A verification system comprising:
 a boot compliance server; and   a client device arranged to load and execute a boot loader at the client device to establish a connection to a boot compliance server, whereafter:   the boot compliance server sends a first cryptographic element from the boot compliance server to the client device;   the client device generates a first cryptographic response with the first cryptographic element based on at least part of the boot loader and sends the first cryptographic response to the boot compliance server for verification; and   the client device continues the boot process upon successful verification of the first cryptographic response.   
   
   
       9 . A verification system as claimed in  claim 8 , wherein:
 the boot compliance server sending at least a second cryptographic element to the client device subsequent to the successful verification of the first cryptographic response;   the client device generates a second cryptographic response with the second cryptographic element based on at least part of the operating system; and   the client device loads the operating system upon successful verification of the second cryptographic response.   
   
   
       10 . A verification system as claimed in  claim 8 , wherein the client device takes at least one protective action upon unsuccessful verification of the first cryptographic response. 
   
   
       11 . A verification system as claimed in  claim 8 , wherein the first cryptographic element is a first hash key and the client device generates the cryptographic response by applying a corresponding hash function to the boot loader using the first hash key. 
   
   
       12 . A verification system as claimed in  claim 9 , wherein the boot compliance server sends a valid second cryptographic response to the client device whereby the client device can verify the operating system without further reference to the boot compliance server. 
   
   
       13 . A verification system as claimed in  claim 9 , wherein the boot compliance server sends a plurality of second cryptographic elements corresponding to respective ones of a plurality of possible operating versions to the client device and the client device determines a relevant one of the second cryptographic elements to apply. 
   
   
       14 . A verification system as claimed in  claim 8 , wherein establishing a connection comprises establishing an encrypted connection. 
   
   
       15 . A verification system as claimed in  claim 8 , wherein the client device is a gaming device. 
   
   
       16 . A verification system as claimed in  claim 15 , wherein the gaming device is a player tracking module. 
   
   
       17 . A verification system as claimed in  claim 8 , further comprising a boot loader update server adapted to communicate an updated boot loader to the client device, whereafter the client device replaces the current boot loader with the updated boot loader. 
   
   
       18 . A verification system as claimed in  claim 8 , further comprising an operating system update server adapted to communicate an updated operating system to the client device, whereafter the client device replaces the current operating system with the updated operating system. 
   
   
       19 . A client device arranged to:
 load and execute a boot loader at the client device to establish a connection to a boot compliance server;   receive a first cryptographic element sent from a boot compliance server to the client device;   generate a first cryptographic response with the first cryptographic element based on at least part of the boot loader and send the first cryptographic response to the boot compliance server for verification; and   continue the boot process upon successful verification of the first cryptographic response.   
   
   
       20 . A client device as claimed in  claim 19 , arranged to:
 receive a second cryptographic element to the client device subsequent to the successful verification of the first cryptographic response;   generate a second cryptographic response with the second cryptographic element based on at least part of the operating system; and   load the operating system upon successful verification of the second cryptographic response.   
   
   
       21 . A client device as claimed in  claim 19 , arranged to take at least one protective action upon unsuccessful verification of the first cryptographic response. 
   
   
       22 . A client device as claimed in  claim 19 , wherein the first cryptographic element is a first hash key and the client device generates the cryptographic response by applying a corresponding hash function to the boot loader using the first hash key. 
   
   
       23 . A client device as claimed in  claim 20 , arranged to receive a valid second cryptographic response to the client device whereby the client device can verify the operating system without further reference to the boot compliance server. 
   
   
       24 . A client device as claimed in  claim 20 , arranged to receive a plurality of second cryptographic elements corresponding to respective ones of a plurality of possible operating versions and determine a relevant one of the second cryptographic elements to apply. 
   
   
       25 . A client device as claimed in  claim 19 , wherein establishing a connection comprises establishing a encrypted connection. 
   
   
       26 . A client device as claimed in  claim 19 , which is a gaming device. 
   
   
       27 . A client device as claimed in  claim 26 , wherein the gaming device is a player tracking module. 
   
   
       28 . A security method for verifying a client device comprising:
 loading and executing a boot loader at the client device to establish a connection to a boot compliance server;   receiving a first cryptographic element sent from a boot compliance server to the client device;   generating a first cryptographic response with the first cryptographic element based on at least part of the boot loader and sending the first cryptographic response to the boot compliance server for verification; and   continuing the boot process upon successful verification of the first cryptographic response.

Join the waitlist — get patent alerts

Track US2010122076A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.