EP2178259A2

System and method for supporting multiple identities for a secure identity device

Abstract

A multiple-identity secure device (MISD) persistently stores a single identification code (a "seed identity"). The seed identity need not be a network address, and may be stored in an integral memory of the device, or on an interchangeable card received in a physical interface of the MISD. The MISD is provided with a transformation engine, in hardware or software form, that is subsequently used to generate one or more unique identities (e.g., network addresses) from the stored seed identity using predefined logic. The generated identities may be dynamically generated, e.g., in real-time as needed after deployment of a device into possession of a subscriber/customer/user, etc., or may be securely stored in the MISD for subsequent retrieval. The transformation engine may generate a unique identity in accordance with an addressing scheme identified as a default setting, a global/network setting, or as determined from a received data transmission.

EP2178259A2, drawing sheet 1
Sheet 1 of 5

Term

3 yearsto projected expiry

Projected expiry 9 October 2029, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

15 claims: 5 independent, 10 dependent

  1. 1
    A computer program product comprising a computer-readable medium storing computer-readable instructions configured to cause a computer system to:receive as input a seed identity comprising an identification code;generate as output at least one unique identity as a function of predefined logic, said unique identity being a unique network address.
  2. 4
    A multiple-identity secure device comprising:a microprocessor;a memory operatively connected to the microprocessor, the memory storing: a seed identity, said seed identity being an identification code;and a transformation engine comprising instructions executable by said microprocessor to: receive as input said seed identity;and generate as output at least one unique identity as a function of predefined logic accessible to said transformation engine, said unique identity being a code uniquely identifying said multiple-identity secure device.
  3. 9
    The multiple-identity secure device of any one of claims 4 to 8, wherein said transformation further comprises computer-readable instructions executable by said microprocessor to:store said unique identity in a secure area of said memory;and optionally wherein said identification code is assigned to be unique among a plurality of assigned identification codes, said identification code comprises a network address;and optionally wherein said predefined logic used to generate said unique identity requires application of a predefined bit mask to said seed identity, and optionally wherein said predefined logic used to generate said unique identity requires adding of a predefined offset to the seed identity;and optionally wherein said predefined logic used to generate said unique identity includes conditional logic requiring generation of said unique identity by a first method if a first condition exists, and generation of said unique identity by a second method if a second condition exists.
  4. 10
    A method for supporting multiple identities for a secure identity device, the method comprising:providing a transformation engine in the network device, the transformation engine comprising computer-readable instructions executable by the microprocessor to: receive as input the seed identity from the secure memory;and generate as output at least one unique identity as a function of predefined logic accessible to the transformation engine, the unique identity being a code uniquely identifying the network device;and causing the transformation engine to run to generate a unique identity as a function of the stored seed identity.
  5. 13
    A method for processing data using a multiple-identity secure device (MISD), the MISD comprising a microprocessor, a memory operatively connected to the microprocessor, a seed identity stored in the memory, and a transformation engine stored in the memory, the transformation engine comprising computer- readable instructions executable by said microprocessor to receive the seed identity as input and to generate as output at least one unique identity as a function of predefined logic, the method comprising:deploying an MISD for use in an information network: transmitting via the information network a data transmission intended for delivery to a network device, said data transmission comprising recipient identity data;receiving, at the MISD, the data transmission;extracting, at the MISD, the recipient identity data from the data transmission;obtaining, at the MISD, a unique identity for the MISD;comparing, at the MISD, the unique identity to the recipient identity data;discarding the data transmission, at the MISD, if the unique identity does not correspond to the recipient identity data;and processing the data transmission, at the MISD, if the unique identity corresponds to the recipient identity data.