Secure firmware transfer from a server to a primary platform
Abstract
A device can (i) operate a primary platform (PP) within a tamper resistant element (TRE) and (ii) receive encrypted firmware images for operating within the primary platform. The TRE can store in nonvolatile memory of the TRE (i) a PP static private key (SK-static.PP), (ii) a server public key (PK.IDS1), and (iii) a set of cryptographic parameters. The TRE can generate a one-time PM key pair of SK-OT1.PP and PK-OT1.PP and send the public key PK-OT1.PP to a server. The TRE can receive a one-time public key from the server comprising PK-OT1.IDS1. The TRE can derive a ciphering key using an elliptic curve Diffie Hellman key exchange and the SK-static.PP, SK-OT1.PP, PK.IDS1, and PK-OT1.IDS1 keys. The TRE can decrypt the encrypted firmware using the derived ciphering key. The primary platform can comprise a smart secure platform (SSP) and the decrypted firmware can comprise a virtualized image for the primary platform.
Claims
exact text as granted — not AI-modified1 . A method for a primary platform to securely receive a firmware, the method comprising the primary platform (PP):
recording a server static public key and a PP private key; deriving a one-time PKI key pair comprising a PP one-time private key and a corresponding PP one-time public key, wherein the PP records the server static public key before deriving the PP one-time public key; sending the PP one-time public key and a random number; receiving (i) a secure hash value of the server static public key and (ii) a server one-time public key; conducting an elliptic curve Diffie Hellman (ECDH) key exchange using the server static public key, the server one-time public key, the PP private key, and the PP one-time private key in order to derive a symmetric ciphering key; receiving a bound image comprising a ciphertext; decrypting the ciphertext into the firmware and the random number, wherein the PP verifies that the decrypted random number equals the sent random number; loading the firmware into a memory; and operating an application using the firmware.
2 . The method of claim 1 , further comprising conducting the elliptic curve Diffie Hellman (ECDH) key exchange with an elliptic curve point addition for the server static public key and the server one-time public key.
3 . The method of claim 1 , further comprising conducting the elliptic curve Diffie Hellman (ECDH) key exchange with (i) a sum of the PP private key and the PP one-time private key and (ii) a modulus of the sum.
4 . The method of claim 1 , wherein the PP (i) does not store a certificate for the server static public key and (ii) does not receive the certificate for the server static public key.
5 . The method of claim 1 , wherein a tamper resistant element (TRE) in a computing device operates the PP, and wherein the computing device uses an agent as a device driver to transfer the ciphertext from an image delivery server to the PP.
6 . The method of claim 1 , further comprising selecting the server static public key using the secure hash value of the server static public key:
7 . A method for a server to encrypt and transfer a symmetric ciphering key, the method performed by the server, the method comprising:
recording a server static private key, wherein a device stores a corresponding server static public key; deriving a one-time PKI key pair comprising a server one-time private key and a corresponding server one-time public key, wherein the server records the server static private key before deriving the server one-time public key; receiving a device static public key and a device one-time public key; conducting an elliptic curve point addition operation with the device static public key and the device one-time public key in order to derive a first point; calculating a modulus for a sum of the server static private key and the server one-time private key; conducting an elliptic curve point multiplication operation with the first point and the modulus in order to derive a second point; conducting a key derivation function with the second point in order to derive an encryption key; encrypting the symmetric ciphering key with the encryption key; and sending the encrypted symmetric ciphering key to the device.
8 . The method of claim 7 , wherein the server receives the device static public key from a secure session before the server receives the device one-time public key from the device.
9 . The method of claim 7 , further comprising recording, by the server, a set of cryptographic parameters for (i) the server static public key and the one-time PKI key pair and (ii) the key derivation function, wherein the cryptographic parameters specify at least a named elliptic curve and a secure hash algorithm.
10 . The method of claim 7 , further comprising deriving, by the device, the encryption key using (i) a device one-time private key corresponding to the device one-time public key, (ii) a device static private key corresponding to the device static public key, (iii) a server static public key corresponding to the server static private key, and (iv) the server one-time public key.
11 . The method of claim 7 , wherein the device includes a tamper resistant element (TRE) and an agent, wherein the TRE reads the encrypted symmetric ciphering key using the agent, and wherein the TRE derives the encryption key and decrypts the encrypted symmetric ciphering key using the encryption key.
12 . The method of claim 7 , further comprising sending, by the server, a ciphertext to the device, wherein the ciphertext is encrypted with the symmetric ciphering key.
13 . The method of claim 7 , further comprising:
receiving, by the server, a random number from the device; and encrypting, by the server, the symmetric ciphering key and the random number with the encryption key
14 . The method of claim 7 , further comprising sending, by the server, a ciphertext to the device, wherein the ciphertext is encrypted with the symmetric ciphering key.Join the waitlist — get patent alerts
Track US2020162247A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.