EP2350910B1

System and method for hardware based security

Abstract

This record has no abstract on file.

EP2350910B1, drawing sheet 1
Sheet 1 of 73

Term

3.2 yearsleft in the term

Expires 24 November 2029.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

5 claims: 1 independent, 4 dependent

  1. 1
    A method of performing hardware based control of features to be applied to a device (14), the method comprising:providing a hardware module (ACC, 12) on said device, said hardware module comprising: non-volatile memory 'NVM' (34,62) for storing feature activation information, at least a portion of said NVM being protected by the hardware module from unauthorized access by agents (20) through which said device communicates;a random number generator, RNG, (58) for generating one or more statistically random numbers used as a private key;and an arithmetic unit (56) for generating a respective public key based on the generated private key;said hardware module receiving a first command for establishing a secure communication session between said hardware module and an available appliance of a redundant pair of appliances and establishing the secure communication session through the agent (20) connected to said hardware module, the agent being a software component running on a separate device adapted to communicate with the available appliance of the redundant pair of appliances and the hardware module;said hardware module generating one or more public keys using said random number generator and said arithmetic unit, and providing said one or more public keys to said agent;said agent providing said one or more public keys to the available appliance (18) of the redundant pair of appliances, wherein each appliance of the redundant pair comprises sets of features to be provided to devices and unique serial numbers to be provided to devices, the serial numbers not overlapping with serial numbers of the respective other appliance of the pair;said available appliance generating a shared secret key (kij) based on said one or more public keys;said hardware module also generating the shared secret key (kij);said hardware module obtaining a set of features and a serial number from said available appliance via said agent through the secure communications session (29) based on said secret key (kij);said hardware module using said shared secret key (kij) to decrypt said set of features and the serial number;injecting said serial number into the hardware module;and said hardware module storing one or more features within the protected portion of said NVM of said device according to said decrypted set of features, wherein the decrypted set of features indicates whether one or more features are enabled or disabled for said device.
  2. 5
    The method according to any one of claims 1 to 4 wherein said hardware module is incorporated into a wafer, chip (40), printed circuit board (44) or electronic device.