The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jul. 13, 2021

Filed:

Mar. 20, 2019
Applicant:

Arris Enterprises Llc, Suwanee, GA (US);

Inventors:

Alexander Medvinsky, San Diego, CA (US);

Jinsong Zheng, San Diego, CA (US);

Jason A. Pasion, San Diego, CA (US);

Xin Qiu, San Diego, CA (US);

Tat Keung Chan, San Diego, CA (US);

Eric Eugene Berry, El Cajon, CA (US);

Michael Ryan Pilquist, Souderton, PA (US);

Douglas M. Petty, San Diego, CA (US);

Assignee:

ARRIS Enterprises LLC, Suwanee, GA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 29/06 (2006.01); H04L 9/08 (2006.01); H04L 9/32 (2006.01); G06F 21/60 (2013.01);
U.S. Cl.
CPC ...
H04L 9/0844 (2013.01); G06F 21/602 (2013.01); H04L 9/0894 (2013.01); H04L 9/3234 (2013.01); H04L 9/3236 (2013.01); H04L 9/3247 (2013.01); H04L 9/3263 (2013.01); H04L 63/0884 (2013.01);
Abstract

A system is provided for distribution of device key sets over a network in a protected software environment (PSE). In the system, a client device includes a connection interface for receiving a crypto hardware (CH) token belonging to a user, untrusted software, a quoting enclave, and a PSE for generating a provisioning request for a device key set. An attestation proxy server (APS) receives the provisioning message using a first network connection, and transmits the provisioning message to an online provisioning server (OPS) using a second network connection. The OPS constructs a provisioning response and an encrypted device key set, and delivers the provisioning response to the untrusted software using the first and second network connections. The PSE decrypts the encrypted device key set to obtain the device key set, re-encrypts the device key set with a local chip-specific key, and stores the re-encrypted device key set.


Find Patent Forward Citations

Loading…