Secure unlock systems for locked devices
Abstract
Technologies disclosed herein provide an apparatus comprising a fuse controller coupled to an aggregator. The fuse controller includes a plurality of fuses for storing a unique identifier of a device and a first secured value of a first password associated with the unique identifier. The aggregator is to receive the unique identifier and the first secured value from the fuse controller, send the unique identifier to an unlock host, receive a second password from the unlock host, compute a second secured value of the second password using a security function, and unlock one or more privileged features on the device based on the first secured value corresponding to the second secured value. In a specific embodiment, the first secured value corresponds to the second secured value if the first password is equivalent to the second password.
Claims
exact text as granted — not AI-modified1 - 20 . (canceled)
21 . A system-on-a-chip (SoC) comprising:
debug circuitry; and a security engine coupled with the debug circuitry, the security engine to determine whether to enable or disable external access to the debug circuitry, including to:
generate a nonce;
send the nonce to a host;
receive a signed token from the host;
perform a plurality of verifications, including to:
verify the signed token; and
determine whether a device identifier received from a host matches an expected device identifier;
enable the external access to the debug circuitry if the plurality of verifications succeed.
22 . The SoC of claim 21 , wherein the security engine is to generate the signed token based, at least in part, on the nonce.
23 . The SoC of claim 21 , wherein the security engine, to receive the signed token, is to receive the signed token including a unique identifier for the SoC.
24 . The SoC of claim 21 , wherein the security engine, to verify the signed token, is to verify authenticity of the signed token.
25 . The SoC of claim 21 , wherein the signed token is to have been signed with a signing key
26 . The SoC of claim 21 , wherein the host has access to a private key used to generate the signed token.
27 . The SoC of claim 21 , wherein the nonce is a random number.
28 . The SoC of claim 27 , further comprising a true random number generator to generate the nonce.
29 . The SoC of claim 21 , wherein the nonce is a random number, wherein the security engine is to generate the signed token based, at least in part, on the nonce, and wherein the security engine, to receive the signed token, is to receive the signed token including a unique identifier for the SoC.
30 . A system comprising:
a dynamic random access memory (DRAM); and a system-on-a-chip (SoC) coupled with the DRAM, the SoC comprising:
debug circuitry; and
a security engine coupled with the debug circuitry, the security engine to determine whether to enable or disable external access to the debug circuitry, including to:
generate a nonce;
send the nonce to a host;
receive a signed token from the host;
perform a plurality of verifications, including to:
verify the signed token; and
determine whether a device identifier received from a host matches an expected device identifier;
enable the external access to the debug circuitry if the plurality of verifications succeed.
31 . The system of claim 30 , wherein the host has access to a private key used to generate the signed token.
32 . The system of claim 30 , wherein the signed token is to have been signed with a signing key
33 . The system of claim 30 , wherein the nonce is a random number.
34 . The system of claim 33 , wherein the SoC comprises a true random number generator to generate the nonce.
35 . The system of claim 30 , wherein the security engine, to receive the signed token, is to receive the signed token including a unique identifier for the SoC.
36 . The system of claim 30 , wherein the security engine is to generate the signed token based, at least in part, on the nonce.
37 . The system of claim 30 , wherein the security engine, to verify the signed token, is to verify authenticity of the signed token.
38 . The SoC of claim 30 , wherein the nonce is a random number, wherein the security engine is to generate the signed token based, at least in part, on the nonce, and wherein the security engine, to receive the signed token, is to receive the signed token including a unique identifier for the SoC.
39 . A method comprising:
determining to enable external access to debug circuitry, including:
generating a nonce;
sending the nonce to a host;
receiving a signed token from the host;
verifying that the signed token is authentic; and
determining that a device identifier received from a host matches an expected device identifier; and
enabling the external access to debug circuitry.
40 . The method of claim 39 , wherein generating the signed token includes generating the signed token based, at least in part, on the nonce, and wherein the signed token includes a unique identifier for the SoC.Join the waitlist — get patent alerts
Track US2024031158A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.