US2024031158A1PendingUtilityA1

Secure unlock systems for locked devices

Assignee: INTEL CORPPriority: Jun 30, 2017Filed: May 26, 2023Published: Jan 25, 2024
Est. expiryJun 30, 2037(~10.9 yrs left)· nominal 20-yr term from priority
H04L 9/3228G06F 21/335G06F 21/6218G06F 21/85G06F 21/72H04L 9/3213H04L 9/3247H04L 9/3226H04L 9/3297H04L 9/0643G06F 21/53G06F 2221/2149
66
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Technologies disclosed herein provide an apparatus comprising a fuse controller coupled to an aggregator. The fuse controller includes a plurality of fuses for storing a unique identifier of a device and a first secured value of a first password associated with the unique identifier. The aggregator is to receive the unique identifier and the first secured value from the fuse controller, send the unique identifier to an unlock host, receive a second password from the unlock host, compute a second secured value of the second password using a security function, and unlock one or more privileged features on the device based on the first secured value corresponding to the second secured value. In a specific embodiment, the first secured value corresponds to the second secured value if the first password is equivalent to the second password.

Claims

exact text as granted — not AI-modified
1 - 20 . (canceled) 
     
     
         21 . A system-on-a-chip (SoC) comprising:
 debug circuitry; and   a security engine coupled with the debug circuitry, the security engine to determine whether to enable or disable external access to the debug circuitry, including to:
 generate a nonce; 
 send the nonce to a host; 
 receive a signed token from the host; 
 perform a plurality of verifications, including to:
 verify the signed token; and 
 determine whether a device identifier received from a host matches an expected device identifier; 
 
 enable the external access to the debug circuitry if the plurality of verifications succeed. 
   
     
     
         22 . The SoC of  claim 21 , wherein the security engine is to generate the signed token based, at least in part, on the nonce. 
     
     
         23 . The SoC of  claim 21 , wherein the security engine, to receive the signed token, is to receive the signed token including a unique identifier for the SoC. 
     
     
         24 . The SoC of  claim 21 , wherein the security engine, to verify the signed token, is to verify authenticity of the signed token. 
     
     
         25 . The SoC of  claim 21 , wherein the signed token is to have been signed with a signing key 
     
     
         26 . The SoC of  claim 21 , wherein the host has access to a private key used to generate the signed token. 
     
     
         27 . The SoC of  claim 21 , wherein the nonce is a random number. 
     
     
         28 . The SoC of  claim 27 , further comprising a true random number generator to generate the nonce. 
     
     
         29 . The SoC of  claim 21 , wherein the nonce is a random number, wherein the security engine is to generate the signed token based, at least in part, on the nonce, and wherein the security engine, to receive the signed token, is to receive the signed token including a unique identifier for the SoC. 
     
     
         30 . A system comprising:
 a dynamic random access memory (DRAM); and   a system-on-a-chip (SoC) coupled with the DRAM, the SoC comprising:
 debug circuitry; and 
 a security engine coupled with the debug circuitry, the security engine to determine whether to enable or disable external access to the debug circuitry, including to:
 generate a nonce; 
 send the nonce to a host; 
 receive a signed token from the host; 
 perform a plurality of verifications, including to:
 verify the signed token; and 
 determine whether a device identifier received from a host matches an expected device identifier; 
 
 enable the external access to the debug circuitry if the plurality of verifications succeed. 
 
   
     
     
         31 . The system of  claim 30 , wherein the host has access to a private key used to generate the signed token. 
     
     
         32 . The system of  claim 30 , wherein the signed token is to have been signed with a signing key 
     
     
         33 . The system of  claim 30 , wherein the nonce is a random number. 
     
     
         34 . The system of  claim 33 , wherein the SoC comprises a true random number generator to generate the nonce. 
     
     
         35 . The system of  claim 30 , wherein the security engine, to receive the signed token, is to receive the signed token including a unique identifier for the SoC. 
     
     
         36 . The system of  claim 30 , wherein the security engine is to generate the signed token based, at least in part, on the nonce. 
     
     
         37 . The system of  claim 30 , wherein the security engine, to verify the signed token, is to verify authenticity of the signed token. 
     
     
         38 . The SoC of  claim 30 , wherein the nonce is a random number, wherein the security engine is to generate the signed token based, at least in part, on the nonce, and wherein the security engine, to receive the signed token, is to receive the signed token including a unique identifier for the SoC. 
     
     
         39 . A method comprising:
 determining to enable external access to debug circuitry, including:
 generating a nonce; 
 sending the nonce to a host; 
 receiving a signed token from the host; 
 verifying that the signed token is authentic; and 
 determining that a device identifier received from a host matches an expected device identifier; and 
   enabling the external access to debug circuitry.   
     
     
         40 . The method of  claim 39 , wherein generating the signed token includes generating the signed token based, at least in part, on the nonce, and wherein the signed token includes a unique identifier for the SoC.

Join the waitlist — get patent alerts

Track US2024031158A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.