Patent · US Active

Extending measured boot for secure link establishment

US11709941B1 · kind B1 · utility

1Cited by
1References
21Claims
0Family size

Assignee

Inventors

Key dates

Filing dateJun 30, 2021
Grant dateJul 25, 2023
Priority date
Expiry dateJun 30, 2041

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/1466
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

A modified measured boot approach is utilized for establishing a secure communication link between two devices. Each device may execute a respective boot process until the device reaches the stage responsible for establishing the communication link with the other device. Each device may exchange its respective self-signed certificate and extend its certificate chain with the self-signed certificate received from the other device. Each device can then generate a new pair of keys based on its extended certificate chain that includes the identity of the other device, and exchange the public key of the new key pair with the other device. A secure link can be established using the public key of the other device as a based key for a key exchange protocol. A central management entity can attest the measurements of the boot stages for each device using the corresponding public key.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.