Per-Device Authentication
Abstract
Systems and techniques are provided for per-device authentication. A hardware serial number associated with a hardware component of a computing device may be received. The hardware serial number may be converted to a hardware key check. A hardware key associated with a certificate from the computing device may be received. The hardware key may be compared to the hardware check key to obtain a verification of the certificate. The certificate may be verified when the hardware key check matches the hardware key and the certificate may not be verified when the hardware key check does not match the hardware key. A signature associated with the certificate may be verified. Access to the data processing apparatus by the computing device may be permitted when the certificate is verified and the signature is determined to be authentic.
Claims
exact text as granted — not AI-modified1 . A computer-implemented method performed by a data processing apparatus, the method comprising:
receiving a hardware serial number associated with a hardware component of a computing device; converting the hardware serial number to a hardware key; storing the hardware key as part of a certificate, wherein the certificate further comprises a signature; and sending the certificate to the computing device.
2 . The computer-implemented method of claim 1 , further comprising:
receiving a second hardware serial number associated with second hardware component of a second computing device, wherein the second hardware component is of the same type as the hardware component; converting the second hardware serial number to a second hardware key; storing the second hardware key as part of a second certificate, wherein the second certificate further comprises a second signature equivalent to the signature; and sending the second certificate to the second computing device.
3 . The computer-implemented method of claim 2 , wherein converting the hardware serial number to a hardware key further comprises:
hashing the hardware serial number to obtain a hash.
4 . The computer-implemented method of claim 3 , further comprising:
discarding a portion of the hash.
5 . The computer-implemented method of claim 1 , wherein the hardware component is a USB chip or network interface card.
6 . The computer-implemented method of claim 2 , wherein the signature is generated for use with SSL.
7 . A computer-implemented method performed by a data processing apparatus, the method comprising:
receiving a hardware serial number associated with a hardware component of a computing device; converting the hardware serial number to a hardware key check; receiving a hardware key associated with a certificate from the computing device; comparing the hardware key to the hardware check key to obtain a verification of the certificate; and verifying the certificate when the hardware key check matches the hardware key and not verifying the certificate when the hardware key check does not match the hardware key.
8 . The computer-implemented method of claim 7 , further comprising:
authenticating a signature associated with the certificate.
9 . The computer-implemented method of claim 8 , further comprising permitting access to the data processing apparatus by the computing device when the certificate is verified and the signature is determined to be authentic.
10 . The computer-implemented method of claim 8 , further comprising:
receiving a second hardware serial number associated with a second hardware component of a second computing device, wherein the second hardware component is of the same type as the hardware component of the first computing device; converting the second hardware serial number to a second hardware key check; receiving a second hardware key associated with a second certificate from the second computing device; comparing the second hardware key to the second hardware key check to obtain a verification of the second certificate; and verifying the second certificate when the second hardware key check matches the second hardware key and not verifying the second certificate when the second hardware key check does not match the second hardware key, and wherein a second signature equivalent to the signature is associated with the second certificate.
11 . The computer-implemented method of claim 10 , further comprising:
authenticating the second signature; and permitting access to the data processing apparatus by the second computing device when the second certificate is verified and the second signature is determined to be authentic.
12 . The computer-implemented method of claim 7 , wherein converting the hardware serial number to a hardware key check further comprises:
hashing the hardware serial number to obtain a hash.
13 . The computer-implemented method of claim 12 , further comprising:
discarding a portion of the hash.
14 . The computer-implemented method of claim 7 , wherein converting the hardware serial number to a hardware key check is performed based on a manner in which the hardware key was generated from the hardware serial number when the certificate was issued to the computing device.
15 . The computer-implemented method of claim 7 , wherein the hardware component is a USB chip or network interface card.
16 . The computer-implemented method of claim 7 , wherein the data processing apparatus comprises a vehicle computing device and the computing device comprises a mobile computing device.
17 . A computer-implemented system for per-device authentication comprising:
a storage, the storage comprising two certificates, each certificate comprising a signature and a hardware key, the hardware key of a first certificate being different from the hardware key of a second certificate, and the signature of the first certificate being the same as the signature of the second certificate; a certificate generator adapted to generate the hardware key of the first certificate from a hardware serial number associated with a hardware component of a first computing device, generate the hardware key of the second certificate from a hardware serial number associated with a hardware component of the second computing device, store the hardware key of the first certificate with the first certificate, store the hardware key of the second with the second certificate, send the first certificate to the first computing device, and send the second certificate to the second computing device.
18 . The computer implemented system of claim 17 , wherein the hardware component of the first computing device and the hardware component of the second computing device are of the same type.
19 . The computer-implemented system of claim 17 , wherein sending the first certificate to the first computing device comprises issuing the first certificate to the first computing device.
20 . The computer-implemented system of claim 17 , wherein the certificate generator is further adapted to generate the hardware key of the first certificate by hashing the hardware serial number of the hardware component of the first computing device.
21 . A computer-implemented system for per-device authentication comprising:
a certificate authenticator adapted to receive hardware serial number associated with a hardware component of a computing device, receive a hardware key from a certificate of the computing device, generate a hardware key check from the hardware serial number, match the hardware key check with the hardware key to verify the certificate, receive a signature from the certificate, authenticate the signature, permit access by the computing device when the certificate is verified and the signature is authenticated, and deny access by the computing device when the certificate is not verified or the signature is not authenticated.
22 . The computer-implemented system of claim 21 , wherein the certificate authenticator is adapted to generate the hardware key check based on the manner in which the hardware key was generated from the hardware serial number when the certificate was issued to the computing device.
23 . The computer-implemented system of claim 21 , wherein the certificate authenticator is further adapted generate the hardware key check by hashing the hardware serial number.
24 . The computer-implemented system of claim 21 , wherein certificate authenticator is further adapted to receive a second hardware serial number associated with a second hardware component of a second computing device, receive a second hardware key from a second certificate of the second computing device, generate a second hardware key check from the second hardware serial number, match the second hardware key check with the second hardware key to verify the second certificate, receive a second signature from the second certificate wherein the second signature is equivalent to the signature from the certificate, authenticate the second signature, permit access by the second computing device when the second certificate is verified and the second signature is authenticated, and deny access by the second computing device when the second certificate is not verified or the second signature is not authenticated.
25 . A system comprising: one or more computers and one or more storage devices storing instructions which are operable, when executed by the one or more computers, to cause the one or more computers to perform operations comprising:
receiving a hardware serial number associated with a hardware component of a computing device; converting the hardware serial number to a hardware key; storing the hardware key as part of a certificate, wherein the certificate further comprises a signature; and sending the certificate to the computing device.
26 . The system of claim 25 , wherein the instructions further cause the one or more computers to perform operations further comprising:
receiving a second hardware serial number associated with second hardware component of a second computing device, wherein the second hardware component is of the same type as the hardware component; converting the second hardware serial number to a second hardware key; storing the second hardware key as part of a second certificate, wherein the second certificate further comprises a second signature equivalent to the signature; and sending the second certificate to the second computing device.
27 . A system comprising: one or more computers and one or more storage devices storing instructions which are operable, when executed by the one or more computers, to cause the one or more computers to perform operations comprising:
receiving a hardware serial number associated with a hardware component of a computing device; converting the hardware serial number to a hardware key check; receiving a hardware key associated with a certificate from the computing device; comparing the hardware key to the hardware check key to obtain a verification of the certificate; and verifying the certificate when the hardware key check matches the hardware key and not verifying the certificate when the hardware key check does not match the hardware key.
28 . The system of claim 27 , wherein the instructions further cause the one or more computers to perform operations further comprising:
authenticating a signature associated with the certificate; receiving a second hardware serial number associated with a second hardware component of a second computing device, wherein the second hardware component is of the same type as the hardware component of the first computing device; converting the second hardware serial number to a second hardware key check; receiving a second hardware key associated with a second certificate from the second computing device; comparing the second hardware key to the second hardware key check to obtain a verification of the second certificate; and verifying the second certificate when the second hardware key check matches the second hardware key and not verifying the second certificate when the second hardware key check does not match the second hardware key, and wherein a second signature equivalent to the signature is associated with the second certificate.Join the waitlist — get patent alerts
Track US2015372825A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.