Secure unlock systems for locked devices
Abstract
Technologies disclosed herein provide an apparatus comprising a fuse controller coupled to an aggregator. The fuse controller includes a plurality of fuses for storing a unique identifier of a device and a first secured value of a first password associated with the unique identifier. The aggregator is to receive the unique identifier and the first secured value from the fuse controller, send the unique identifier to an unlock host, receive a second password from the unlock host, compute a second secured value of the second password using a security function, and unlock one or more privileged features on the device based on the first secured value corresponding to the second secured value. In a specific embodiment, the first secured value corresponds to the second secured value if the first password is equivalent to the second password.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . An apparatus, comprising:
a fuse controller including a plurality of fuses for storing a unique identifier of a device and a first secured value of a first password associated with the unique identifier; an aggregator coupled to the fuse controller to:
receive the unique identifier and the first secured value from the fuse controller;
send the unique identifier to an unlock host;
receive a second password from the unlock host;
compute a second secured value of the second password using a security function; and
unlock one or more privileged features on the device based on the first secured value corresponding to the second secured value.
2 . The apparatus of claim 1 , wherein the first secured value corresponds to the second secured value if the first password is equivalent to the second password.
3 . The apparatus of claim 1 , wherein the first password is randomly generated for the device and stored in a database.
4 . The apparatus of claim 1 , wherein the aggregator is further to:
receive a request from the unlock host to unlock the device, wherein the unique identifier is sent to the unlock host in response to receiving the request at the aggregator.
5 . The apparatus of claim 4 , wherein the aggregator is further to:
block the request to unlock the device, wherein the request is blocked based on the first secured value not corresponding to the second secured value.
6 . The apparatus of claim 1 , wherein the security function is equivalent to another security function used by a fusing device to compute the first secured value of the first password.
7 . The apparatus of claim 6 , wherein the security function is Secure Hash Algorithm 3 (SHA-3).
8 . The apparatus of claim 6 , wherein the first password is associated with an unlock mode of a plurality of unlock modes for the device, wherein the unlock mode specifies the one or more privileged features on the device to be unlocked.
9 . A system, comprising:
a fuse controller for storing a unique identifier of a device and a first secured value computed from a first password associated with the unique identifier; and an aggregator coupled to the fuse controller to:
receive the unique identifier and the first secured value from the fuse controller;
send the unique identifier to an unlock host;
receive a second password from the unlock host;
compute a second secured value of the second password using a security function; and
unlock one or more privileged features on the device based on the first secured value corresponding to the second secured value.
10 . The system of claim 9 , wherein the first secured value corresponds to the second secured value if the first password is equivalent to the second password.
11 . The system of claim 9 , wherein the first password is randomly generated for the device and stored in a database.
12 . The system of claim 9 , further comprising:
a fusing device to:
receive the first password and the unique identifier from a database in which the first password and the unique identifier are stored;
compute the first secured value of the first password using the security function; and
store the first secured value and the unique identifier in the fuse controller of the device.
13 . The system of claim 9 , further comprising:
an unlock host to:
authenticate one or more credentials of a user;
request the unique identifier from the aggregator based, at least in part, on the one or more credentials being authenticated;
receive the unique identifier from the aggregator;
query a database based on the unique identifier;
receive the second password from the database;
send the second password to the aggregator; and
receive an indication that the one or more privileged features of the device are unlocked based on the aggregator determining the first secured value corresponds to the second secured value.
14 . At least one machine readable medium having instructions stored thereon, the instructions when executed by at least one processor cause the at least one processor to:
receive, from a fuse controller, a unique identifier of the device and a first secured value of a first password associated with the unique identifier, wherein the unique identifier and the first secured value are stored in fuses of the fuse controller; send the unique identifier to an unlock host; receive a second password from the unlock host; compute a second secured value of the second password using a security function; and unlock one or more privileged features on the device based on the first secured value corresponding to the second secured value.
15 . The at least one machine readable medium of claim 14 , wherein the first secured value corresponds to the second secured value if the first password is equivalent to the second password.
16 . The at least one machine readable medium of claim 14 , wherein the first password is randomly generated for the device and stored in a database.
17 . The at least one machine readable medium of claim 14 , wherein the security function is equivalent to another security function used by a fusing device to compute the first secured value of the first password.
18 . A method, the method comprising:
receiving, from a fuse controller, a unique identifier of a device and a first secured value of a first password associated with the unique identifier, wherein the unique identifier and the first secured value are stored in fuses of the fuse controller; sending the unique identifier to an unlock host; receiving a second password from the unlock host; computing a second secured value of the second password using a security function; and unlocking one or more privileged features on the device based on the first secured value corresponding to the second secured value.
19 . The method of claim 18 , wherein the first secured value corresponds to the second secured value if the first password is equivalent to the second password.
20 . The method of claim 20 , wherein the first password is associated with an unlock mode of a plurality of unlock modes for the device, wherein the unlock mode specifies the one or more privileged features on the device to be unlocked.
22 . An apparatus, comprising:
a security engine in a device to:
receive a signed token from an unlock host;
store the signed token in a boot partition of the device;
subsequent to a boot process initiating, attempt to verify the signed token;
send a request to unlock the device based, at least in part, on the attempt to verify the signed token being successful; and
an aggregator coupled to the security engine to:
receive the request from the security engine to unlock the device; and
unlock one or more privileged features on the device based on unlock data in the token.
22 . The apparatus of claim 21 , wherein the signed token is based, at least in part, on a device identifier (ID) of the device and a nonce generated by the security engine.
23 . The apparatus of claim 21 , wherein the signed token includes a timestamp and an expiration parameter, wherein the timestamp and the expiration parameter define a time period during which the signed token is valid.
24 . The apparatus of claim 21 , wherein at least one privileged feature is unlocked by disabling code of a computing block on the device.
25 . The apparatus of claim 21 , wherein at least one privileged feature is unlocked by permitting one or more messages associated with a computing block of the device to be outputted.
26 . The apparatus of claim 21 , wherein at least one privileged feature is unlocked by enabling a type of access for a computing block on the device.
27 . The apparatus of claim 26 , wherein the type of access is selected from a group of access types including debugging, testing, provisioning, prototyping, validating, and analyzing.
28 . The apparatus of claim 21 , wherein the security engine is further to:
receive, from an unlock host, a request for a device identifier (ID) of the device; generate a nonce; and send the device ID and the nonce to the unlock host.
29 . The apparatus of claim 21 , wherein the attempt to verify the signed token is successful based, at least in part, on:
verifying integrity of the signed token; and verifying authenticity of the signed token.
30 . The apparatus of claim 29 , wherein a token header of the signed token includes a public key associated with a private key used to create a signature of the signed token, wherein the public key is used to verify the integrity of the signed token and to verify the authenticity of the signed token.
31 . The apparatus of claim 21 , wherein the signed token includes a plurality of device IDs and a plurality of nonces.
32 . The apparatus of claim 31 , wherein the attempt to verify the token is successful based, at least in part, on:
determining a device ID stored in the device corresponds to one of the plurality of device IDs in the signed token; and determining a nonce stored in the device corresponds to one of the plurality of nonces associated with the one of the plurality of device IDs.
33 . An apparatus, comprising:
a fuse controller comprising circuitry for storing, in a plurality of fuses, a unique identifier of the device and a first secured value of a first password associated with the unique identifier; an aggregator comprising circuitry, the aggregator coupled to the fuse controller to:
receive the unique identifier and the first secured value from the fuse controller;
send the unique identifier to an unlock host; and
receive an error message from the unlock host indicating a second password was not retrieved; and
a security engine comprising circuitry, the security engine coupled to the aggregator to:
retrieve a signed token from a boot partition of the device;
attempt to verify the signed token; and
send a request to unlock the device based, at least in part, on the attempt to verify the signed token being successful, wherein the aggregator is further to:
receive the request from the security engine to unlock the device; and
unlock one or more privileged features on the device based on unlock data in the token.Join the waitlist — get patent alerts
Track US2019007212A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.