MÉTODO E APARELHO PARA ESTABELECIMENTO DE CHAVE, E, MEIO NÃO TRANSITÓRIO LEGÍVEL POR COMPUTADOR

BR112025019903A2Pending Publication Date: 2026-08-04QUALCOMM INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
BR112025019903
Authority / Receiving Office
BR · BR
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-03-30
Filing Date
2024-03-12
Publication Date
2026-08-04

Smart Images

  • Figure 00000081_0000
    Figure 00000081_0000
  • Figure 00000082_0000
    Figure 00000082_0000
  • Figure 00000083_0000
    Figure 00000083_0000
Patent Text Reader

Abstract

Systems and techniques are described for key establishment. For instance, a process can, during a first cryptographic key derivation, store a first trusted measurement value of a first entity in a first storage location, store an expected measurement value of a second entity in a second storage location, and generate a first instance of a cryptographic key using the first trusted measurement value, the expected measurement value, and a key derivation function (KDF). The process can, during a second cryptographic key derivation, obtain the expected measurement value as a second trusted measurement value of the second entity and store it in the second storage location, obtain the first trusted measurement value as a second expected measurement value and store it in the first storage location, and generate a second instance of the cryptographic key using the second expected measurement value, the second trusted measurement value, and the key derivation function.
Need to check novelty before this filing date? Find Prior Art

Description

1 / 73 “METHOD AND APPARATUS FOR ESTABLISHING A KEY, AND, NON-TRANSIENTIAL COMPUTER-READABLE MEANS” FIELD

[0001] This disclosure relates generally to the establishment of keys for use by device entities in performing cryptographic operations. For example, aspects of this disclosure relate to obtaining and providing inputs for a key derivation function. BACKGROUND

[0002] Devices frequently use cryptographic keys to perform cryptographic operations (e.g., encryption and / or decryption) on data. In some cases, multiple entities (e.g., different software image versions, different components, different devices, etc.) may require access to such data (e.g., being able to decrypt encrypted data). However, in certain scenarios, the cryptographic key used to perform cryptographic operations may be derived based on one or more data items that differ between the multiple entities. Therefore, the entities may be unable to derive common cryptographic keys to use the data. Consequently, systems and techniques are needed to allow different entities to derive the same cryptographic keys in order to enable the entities to access the data. SUMMARY

[0003] The present invention describes systems and techniques for establishing keys in pairs. Petition 870250083986, dated 09 / 18 / 2025, page 7 / 170 2 / 73 between two entities to allow the derivation of a common cryptographic key using a key derivation function.

[0004] According to at least one example, a process for key establishment is provided. The process includes: during a first cryptographic key derivation: storing a first reliable measurement value associated with a first entity in a first secure storage location; storing an expected measurement value associated with a second entity in a second secure storage location; and generating a first instance of a cryptographic key using the first reliable measurement value, the expected measurement value, and a key derivation function; and during a second cryptographic key derivation: obtaining, after generating the first instance of the cryptographic key during the first cryptographic key derivation, the expected measurement value as a second reliable measurement value associated with the second entity; storing the second reliable measurement value in the second secure storage location;Obtain the first reliable measurement value as a second expected measurement value; store the second expected measurement value in the first secure storage location; and generate a second instance of the cryptographic key using the second expected measurement value, the second reliable measurement value, and the key derivation function.

[0005] In another illustrative example, a key establishment device is provided. The device includes at least one memory and at least one processor coupled to at least one memory and configured to: during a first cryptographic key derivation: cause that Petition 870250083986, dated 09 / 18 / 2025, page 8 / 170 3 / 73 a first reliable measurement value associated with a first entity is stored in a first secure storage location; an expected measurement value associated with a second entity is stored in a second secure storage location; and a first instance of a cryptographic key is generated using the first reliable measurement value, the expected measurement value, and a key derivation function; and during a second cryptographic key derivation: after generating the first instance of the cryptographic key during the first cryptographic key derivation, the expected measurement value is obtained as a second reliable measurement value associated with the second entity; the second reliable measurement value is stored in the second secure storage location; the first reliable measurement value is obtained as a second expected measurement value;Cause the second expected measurement value to be stored in the first secure storage location; and generate a second instance of the cryptographic key using the second expected measurement value, the second reliable measurement value, and the key derivation function.

[0006] In another illustrative example, a non-transient, computer-readable medium is provided that has instructions stored therein which, when executed by at least one processor, cause the at least one processor to: during a first cryptographic key derivation: cause a first reliable measurement value associated with a first entity to be stored in a first secure storage location; cause an expected measurement value associated with a second entity to be stored in a second secure storage location; Petition 870250083986, dated 09 / 18 / 2025, page 9 / 170 4 / 73 and generate a first instance of a cryptographic key using the first reliable measurement value, the expected measurement value, and a key derivation function; and during a second cryptographic key derivation: obtain, after generating the first instance of the cryptographic key during the first cryptographic key derivation, the expected measurement value as a second reliable measurement value associated with the second entity; cause the second reliable measurement value to be stored in the second secure storage location; obtain the first reliable measurement value as a second expected measurement value; cause the second expected measurement value to be stored in the first secure storage location; and generate a second instance of the cryptographic key using the second expected measurement value, the second reliable measurement value, and the key derivation function.

[0007] In another illustrative example, a key establishment apparatus is provided. The apparatus includes: during a first cryptographic key derivation: means for storing a first reliable measurement value associated with a first entity in a first secure storage location; means for storing an expected measurement value associated with a second entity in a second secure storage location; and means for generating a first instance of a cryptographic key using the first reliable measurement value, the expected measurement value, and a key derivation function; and during a second cryptographic key derivation: means for obtaining, after generating the first instance of the cryptographic key during the first Petition 870250083986, dated 09 / 18 / 2025, page 10 / 170 5 / 73 cryptographic key derivation, the expected measurement value as a second reliable measurement value associated with the second entity; means to store the second reliable measurement value in the second secure storage location; means to obtain the first reliable measurement value as a second expected measurement value; means to store the second expected measurement value in the first secure storage location; and means to generate a second instance of the cryptographic key using the second expected measurement value, the second reliable measurement value, and the key derivation function.

[0008] In some respects, one or more of the devices described in the present invention are, form part of, and / or include a mobile or wireless communication device (for example, a mobile phone or other mobile device), an extended reality (XR) device or system (for example, a virtual reality (VR) device, an augmented reality (AR) device, or a mixed reality (MR) device), a wearable device (for example, a network-connected wristwatch or other wearable device), a vehicle or a computing device or component of a vehicle, a camera, a personal computer, a laptop computer, a server computer or server device (for example, an edge or cloud-based server, a personal computer acting as a server device, a mobile device, such as a mobile phone, acting as a server device,an XR device acting as a server device, a vehicle acting as a server device, a router, Petition 870250083986, dated 09 / 18 / 2025, page 11 / 170 6 / 73 network or other device acting as a server device), a system-on-a-chip (SoC), any combination thereof and / or other type of device. In some aspects, the device(s) include a display to show one or more images, notifications and / or other viewable data. In some aspects, the device(s) may include one or more sensors (for example, one or more RF sensors), such as one or more gyroscopes, one or more gyrometers, one or more accelerometers, any combination thereof and / or other sensor(s).

[0009] This summary is not intended to identify key or essential attributes of the claimed subject matter, nor is it intended to be used in isolation to determine the scope of the claimed subject matter. Subject matter should be understood by reference to the appropriate portions of the entire descriptive report of this patent, to any or all of the drawings and to each claim.

[0010] The above, along with other attributes and examples, will become more evident by reference to this descriptive report, the claims, and the attached drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0011] Illustrative examples of this application are described in detail below with reference to the following figures:

[0012] Figure 1 is a block diagram illustrating certain components of a computing device, according to one or more examples described in this invention.

[0013] Figure 2A is a block diagram that Petition 870250083986, dated 09 / 18 / 2025, page 12 / 170 Figure 7 / 73 illustrates an environment for deriving a cryptographic key during a first measurement state, according to one or more examples described in the present invention.

[0014] Figure 2B is a block diagram illustrating an environment for deriving a cryptographic key during a second measurement state, according to one or more examples described in the present invention.

[0015] Figure 3 is a flow diagram illustrating an example of a process for establishing paired switches between different measurement states, according to one or more examples described in the present invention.

[0016] Figure 4 is a diagram illustrating an example of a computing system for implementing certain aspects described in the present invention. DETAILED DESCRIPTION

[0017] Certain aspects and examples of this disclosure are provided below. Some of these aspects and examples can be applied independently, and some can be applied in combination, as would be evident to those skilled in the art. In the following description, specific details are set forth for explanatory purposes to provide a complete understanding of examples of the application. However, it will become evident that several aspects can be practiced without these specific details. The figures and description are not intended to be restrictive. Additionally, certain details known to those skilled in the art may be omitted to avoid obscuring the description.

[0018] In the description of the figures below, any component described in relation to a figure, in Petition 870250083986, dated 09 / 18 / 2025, page 13 / 170 8 / 73 Several examples described in the present invention may be equivalent to one or more components with similar names (or numbers) described in relation to any other figure. For the sake of brevity, the descriptions of these components may not be entirely repeated in relation to each figure. Thus, each and every example of the components in each figure is incorporated by reference and considered as optionally present in all other figures with one or more components with similar names. Additionally, according to several examples described in the present invention, any description of the components in a figure should be interpreted as an optional example, which may be implemented in addition to, in conjunction with, or in place of the examples described in relation to a component with the same corresponding name in any other figure.

[0019] The following description provides illustrative examples only and is not intended to limit the scope, applicability, or configuration of this disclosure. Instead, the following description of the illustrative examples will provide those skilled in the art with a description that will enable the implementation of an exemplary embodiment. It should be understood that various changes may be made to the function and arrangement of the elements without departing from the spirit and scope of the application as set forth in the appended claims.

[0020] As used in the present invention, the expression operationally connected, or operational connection (or any variation thereof), means that there exists between elements / components / devices etc., a direct or indirect connection that allows the elements to interact with each other in some way. For example, Petition 870250083986, dated 09 / 18 / 2025, p. 14 / 170 9 / 73 The expression "operationally connected" can refer to any direct connection (e.g., wired directly between two devices or components) or indirect connection (e.g., wired and / or wireless connections between multiple devices or components that connect the operationally connected devices). Thus, any path through which information can travel can be considered an operational connection. Furthermore, operationally connected devices and / or components can exchange things and / or inadvertently share things besides information, such as electrical current, radio frequency signals, power supply interference, interference due to proximity, interference due to reuse of the same wire and / or physical medium, interference due to reuse of the same register and / or other logical medium, etc.

[0021] The present invention describes systems and techniques for establishing a common cryptographic key for different entities. In other words, the systems and techniques described in the present invention allow a common cryptographic key to be generated by a key derivation function for at least two separate entities that require the cryptographic key to perform cryptographic operations on data that can be used and / or shared by the entities. A key derivation function can be any algorithm (e.g., at least partially implemented in hardware) that performs a function to produce an output based on one or more inputs (e.g., a platform key, etc.). The output may include, at least in part, a derived cryptographic key. Petition 870250083986, dated 09 / 18 / 2025, page 15 / 170 10 / 73

[0022] In some examples, an aggregated software image may be initialized on a device. As used in the present invention, an aggregated software image may be a set of any one or more software images loaded during the initialization of a computing device. In some examples, when this aggregated software image is initialized on a computing device, a reliable measurement value may be obtained using the image. In some examples, a measurement value is any value (which may also be called a parameter) obtained during a device initialization process.In some instances, this measurement value may be called a reliable value when the measurement is obtained during a device initialization and stored in a location that cannot be rewritten during subsequent device operation (e.g., in write-only memory, some form of immutable storage, read-only memory, etc.). As an example, the reliable measurement value might include a cryptographic hash of the aggregated software image obtained by executing a hash function using the aggregated software images as input. In some instances, the hash might be combined with any other items of information (e.g., computing device state information, measured physical properties, etc.) to obtain the reliable measurement value.This reliable measurement value, along with a secure platform key, can be used with a key derivation function to obtain a cryptographic key to be used for performing cryptographic operations on data to be accessed and / or otherwise used by the aggregated software image. In some cases... Petition 870250083986, dated 09 / 18 / 2025, page 16 / 170 11 / 73 examples, as used in the present invention, a platform key refers to any cryptographic key available to (at least) two entities that is a protected secret known only to one or more devices comprising the two entities, such that the platform key is made available as an input to a key derivation function performed by and / or on behalf of the two entities. In some examples, the use of a platform key in combination with a unique measurement value for a software image prevents a classical signature forgery (e.g., performed using a quantum computer) from granting access to device secrets to an unauthorized aggregate image. For example, if the previous aggregate image does not authorize the new or updated image, the new image will not have access to secrets linked to the device state.Authentication of the new or updated image can be performed using the previously measured image and cryptographic primitives that are quantum-safe. Quantum protection can thus be provided by the mutable component and does not need to be added to the immutable software of the device.

[0023] In some examples, the reliable measurement value, obtained at startup, is stored in a secure storage location. In some examples, the secure storage location is any storage location that can only be written to during a secure startup process and cannot be subsequently rewritten (e.g., a write-only storage location). A computing device can be configured with multiple secure storage locations without departing from the scope of the examples described herein. Petition 870250083986, dated 09 / 18 / 2025, page 17 / 170 12 / 73 invention. In some examples, the particular secure storage location to which the reliable measurement value is recorded is determined based, at least in part, on one or more parameters and / or information associated with the aggregated software image. As one example, the secure storage location may be selected based on a version number of the aggregated software image. As another example, the aggregated software image may include instruction(s) indicating a particular secure storage location to which the reliable measurement value should be recorded.

[0024] In some instances, an aggregated software image may require an update (for example, to fix a security issue). This update may require an update to one or more portions of the aggregated software image. An update may alter the contents of the aggregated software image such that a hash of the aggregated software image changes, as hashes of different information result in different hash values. Therefore, if an updated aggregated software image attempts to obtain a cryptographic key using a key derivation function (for example, using a hash of the updated aggregated image instead of a hash of the original image), the cryptographic key may differ from the cryptographic key obtained by the aggregated software image before the update. Obtaining a different cryptographic key may render the information protected by the original cryptographic key unobtainable by the updated aggregated software image.Thus, a technique is needed to allow the aggregated software image and the updated aggregated software image to provide the same inputs to a key derivation function, so that... Petition 870250083986, dated 09 / 18 / 2025, page 18 / 170 The generated cryptographic key 13 / 73 must be the same, allowing the updated aggregated software image to access data previously protected by the non-updated aggregated software image.

[0025] As another example, a particular component may need to share data with another component, where such data is subjected to cryptographic operations by the particular component. The components may be portions of the same computing device, or they may be portions of separate computing devices (e.g., components of separate mobile computing devices). In such a scenario, the two components may again require the ability to generate the same cryptographic key to access the same data. Thus, again, a technique is needed to enable the components to generate the same cryptographic key.

[0026] In some examples, issues such as those described above can be addressed, at least in part, via a technique that uses at least two inputs to a key derivation function, along with a common platform key, to derive a cryptographic key. The two inputs can remain the same between two versions of an aggregated software image and / or between two components, by manipulating the secure storage location of the measurement values. Specifically, during an initialization process, a first secure storage location can be used to store a reliable measurement value (e.g., from an initial aggregated software image or a first component), and a second secure storage location can be used to store an expected measurement value (e.g., from an initial aggregated software image or a first component). Petition 870250083986, dated 09 / 18 / 2025, page 19 / 170 14 / 73 example, of an updated aggregate software image or a second component). In some examples, during a subsequent initialization (e.g., of the same device, of a separate component, etc.), the expected measurement value may be a second trusted measurement value obtained during the initialization process (e.g., a hash, a serial number, etc.) and stored in the second secure storage location, and the first trusted measurement value may be obtained and stored in the first secure storage location. Thus, a key derivation function configured to use a common platform key and the values ​​in the first and second secure storage locations may have equal inputs and thus output the same derived cryptographic key. Because secure resources are finite and populated by an immutable trusted party, a system with the platform secret but in a different state will not be able to derive the same group secret.

[0027] In some examples, a computing device is configured with at least one first secure storage location and a second secure storage location (e.g., two separate platform control registers). In some examples, the first secure storage location may be configured so that it can only be written to once, during a computing device initialization. The first secure storage location may thus be immutable during the runtime of the computing device. The first secure storage location may be written to a first reliable measurement value obtained (e.g., measured) during a device initialization, and which can only be written to once. Petition 870250083986, dated 09 / 18 / 2025, page 20 / 170 15 / 73 times, during initialization, by a component configured to obtain the measurement and record the measurement in the first secure storage location. In some examples, the first reliable measurement value is a hash value of a first aggregated software image being loaded during the initialization process. In some examples, the first storage location may be recorded with a serial number of a component being initialized during the initialization process. In both cases, the first reliable measurement value may be a combination of information items (e.g., image hash, component serial number, etc.) with any other information of any type. As an example, an image hash or a component serial number may be combined with a value representing the state of the computing device to obtain the first reliable measurement value.Examples of state information may include, but are not limited to, values ​​from one or more read-only registers of the computing device, measurements related to the operation of the computing device, etc. In some examples, the first reliable measurement value may be called a startup-time measurement.

[0028] In some examples, an expected measurement value is obtained. The expected measurement value can be any value chosen by the first aggregated software image, or by a first component, to represent an expected measurement value for an updated aggregated software image or a second component, respectively. As an example, a second reliable measurement value can be obtained, at least in part, by obtaining a hash value associated with an aggregated software image. Petition 870250083986, dated 09 / 18 / 2025, page 21 / 170 16 / 73 updated. As another example, the second reliable measurement value can be obtained, at least in part, using a serial number associated with a second component. In some examples, the expected measurement value may be a value that, if measured during a subsequent initialization of a device (or any component on it), becomes a reliable measurement value. As an example, a known hash of an updated software image, or a known serial number (or other identifying information) of another component, can be obtained as at least part of an expected measurement value, and may or may not be combined with some other information (e.g., a device register state) to generate the expected measurement value.In this example, during a subsequent device initialization (e.g., for different software versions), or during device operation (e.g., for separate device components), the expected measurement value obtained may become a reliable measurement value.

[0029] In some examples, the second reliable measurement value is stored in a second secure storage location (e.g., a second platform control register) that is writable after the first secure storage location has been made immutable (e.g., read-only). In some examples, the second reliable measurement value (e.g., the expected measurement value) is obtained using any suitable information-gathering technique. As an example, an aggregated software image, running on a computing device, may obtain an expected hash of an updated software image to be loaded (e.g., obtained Petition 870250083986, dated 09 / 18 / 2025, p. 22 / 170 17 / 73 via a network connection). As another example, a serial number for a separate component can be obtained, directly or indirectly, from the other component. In some examples, the expected measurement value is stored in the second storage location based, at least in part, on information associated with the first entity (e.g., an aggregated software image, a device component, etc.) and / or a second entity (e.g., an updated software image, a second device component, etc.). For example, a version number of an updated software image can determine the second secure storage location.As another example, the key derivation process contemplated in the present invention can determine the first secure storage location based on the version number of an aggregated software image, and the second secure storage location can be determined by virtue of being the other secure storage location to be used in the key derivation process (for example, when only two entries plus a platform key are used to perform the key derivation function).

[0030] In some examples, the first reliable measurement value and the expected measurement value are used as input to a key derivation function, along with the common platform key. In some examples, the common platform key is any cryptographic key available to two separate entities. As an example, a platform key might be stored in a particular read-only storage location of a hardware component (e.g., configured during a manufacturing process), and is accessible to images. Petition 870250083986, dated 09 / 18 / 2025, page 23 / 170 18 / 73 of software running on devices that include the hardware component (e.g., indirectly accessible to the software, such as via a key derivation function or via immutable software at initialization, after which the key is locked). As another example, the platform key may be stored in a read-only hardware component of a device, and be accessible only to certain other hardware components of that device. As another example, two separate devices made by the same manufacturer may each include a read-only hardware component that includes the common platform key.

[0031] In some examples, the first reliable measurement value, the expected measurement value, and the platform key are used as inputs to a key derivation function in order to derive a cryptographic key to be used to perform cryptographic operations (e.g., data encryption and / or decryption) by the first entity (e.g., an initial aggregated software image, a first component, etc.).

[0032] However, for other entities to access and / or use the same data, the same cryptographic key may be required. Therefore, during a subsequent cryptographic key derivation, using the same key derivation function, the same inputs need to be used. To achieve the same inputs, the contents of the secure storage locations providing the input measurement values ​​need to be the same. To this end, in some examples, the secure storage locations of the expected measurement value and the first reliable measurement value may be reversed between initializations. Petition 870250083986, dated 09 / 18 / 2025, page 24 / 170 19 / 73 subsequent of a computing device or during initializations of separate components.

[0033] In some examples, when the first trusted measurement value includes a hash of an initial aggregated software image, as discussed above, the first trusted measurement value is stored in a first secure storage location based on information associated with the initial aggregated software image (e.g., an image version number). An expected measurement value from an updated aggregated software image can then be stored in a second secure storage location, and the two measurement values ​​can be used, along with a common platform key, to obtain a derived cryptographic key.

[0034] In some examples, when an updated aggregate software image is initialized, the updated image has different associated information (e.g., a new version number) that determines that the second secure storage location is used to store a reliable measurement value during the initialization process, with the first secure storage location being writable by the updated aggregate software image. The first storage location may be written with the reliable measurement value from the previous aggregate software image (e.g., an expected measurement value from the initial aggregate software image obtained by the updated aggregate software image). Thus, the first secure storage location still includes the reliable measurement value associated with the initial aggregate software image, while the second secure storage location includes the reliable measurement value associated with the image. Petition 870250083986, dated 09 / 18 / 2025, page 25 / 170 The updated aggregate software image (which was previously the expected measurement value associated with the updated aggregate software image) and the platform key remain the same. As a result, in some examples, the inputs to the key derivation function (e.g., the platform key, the reliable measurement value associated with the initial aggregate software image, and the measurement value associated with the updated aggregate software image) remain the same, leading to the same derived cryptographic key. Therefore, the updated aggregate software image can access the same data (e.g., via cryptographic operations) as the initial aggregate software image.

[0035] In some examples, when the first reliable measurement value includes a serial number of a first component, as discussed above, the first reliable measurement value is stored in a first secure storage location during a computing device initialization. The expected value in this scenario is information (e.g., another serial number) associated with a second component, and is stored in a second secure storage location during or after the initialization process. In some examples, the reliable measurement value of the first component and the expected measurement value of the second component are used with the platform key as inputs to a key derivation function in order to obtain a derived cryptographic key to be used to perform cryptographic operations (e.g., encryption / decryption) on data to be commonly used by the two components.In some examples, the second component can be configured to store its own. Petition 870250083986, dated 09 / 18 / 2025, page 26 / 170 21 / 73 reliable measurement value (e.g., its own serial number) in a secure storage location during an initialization process, obtain an expected measurement value associated with the first component (e.g., the serial number of the first component) and store the expected measurement value in another secure storage location, so that when used as inputs, along with a common platform key, to a key derivation function, an output of the same cryptographic key is obtained, thus allowing both components to have a shared derived cryptographic key for use in performing cryptographic operations on data shared by the two components.

[0036] Examples described in the present invention may address the need to securely establish commonly derived pairwise cryptographic keys between two entities when the entities, or the whole or any portion of one or more devices comprising the entities, may be in different states (e.g., measurement states). In some examples, the examples described in the present invention provide consistent inputs to a key derivation function when entities change state (e.g., during and / or after software updates) and / or separate components require common cryptographic capabilities (e.g., the components will be operating on at least partially common data sets).

[0037] Several aspects of the techniques described in the present invention will be discussed below in relation to the figures. Figure 1 is a block diagram illustrating an example of a computing device 100. As shown, the computing device 100 includes a Petition 870250083986, dated 09 / 18 / 2025, page 27 / 170 22 / 73 processor 102, a universal flash storage (UFS) device 104, a memory device 108, an additional storage device 110, and a trusted environment 112. The trusted environment 112 may include several secure storage locations for measurement values ​​(e.g., secure storage location A for measurement values ​​114, secure storage location B for measurement values ​​116), a platform key storage 118, a key derivation component 120, and several security components (e.g., security component A 122, security component B 124). Each of these components is described below.

[0038] A computing device 100 is any device, portion of a device, or any set of devices capable of processing instructions electronically and may include, but is not limited to, any of the following: one or more processors (e.g., components including integrated circuit sets, memory, input / output device(s) (not shown), non-volatile storage hardware, one or more physical interfaces (e.g., input / output (I / O input / output) interfaces), various other hardware components (not shown), and / or any combination thereof.Examples of computing devices include, but are not limited to, a mobile device (e.g., laptop computer, smartphone, personal digital assistant, tablet computer, automotive computing system, and / or any other mobile computing device), an Internet of Things (IoT) device, a server (e.g., a blade server in a blade server chassis, a... Petition 870250083986, dated 09 / 18 / 2025, page 28 / 170 23 / 73 rack server in a rack, etc.), a desktop computer, a storage device (e.g., a disk drive array, a fiber channel storage device, an internet small computer systems interface (iSCSI) storage device, a tape storage device, a flash storage array, a network-attached storage device, etc.), a network device (e.g., switch, router, multilayer switch, etc.), a wearable device (e.g., a network-attached wristwatch or smartwatch or other wearable device), a robotic device, a smart television, a smart home appliance, an extended reality (XR) device (e.g., augmented reality, virtual reality, etc.).(a device that includes one or more SoCs and / or any other type of computing device with the aforementioned requirements. In one or more examples, any or all of the aforementioned examples may be combined to create a system of such devices, which may collectively be referred to as a computing device. Other types of computing devices may be used without departing from the scope of the examples described in the present invention.)

[0039] In some examples, the processor 102 is any component that includes a set of circuits to execute instructions (for example, from a computer program). As an example, such a set of circuits may be a set of integrated circuits implemented, at least in part, using transistors implementing components such as Petition 870250083986, dated 09 / 18 / 2025, page 29 / 170 24 / 73 arithmetic logic units, control units, logic gates, registers, first-in, first-out (FIFO) buffers, data and control buffers, etc. In some instances, the processor may include additional components, such as cache memory. In some instances, a processor retrieves and decodes instructions, which are then executed. Instruction execution may include data operations, which may include reading and / or writing data. In some instances, the instructions and data used by a processor are stored in the memory (e.g., in memory device 108) of the computing device 100. A processor may perform various operations to run software, such as operating systems, applications, etc.Processor 102 can write data from memory to the storage of computing device 100 and / or read data from storage via memory. Examples of processors include, but are not limited to, central processing units (CPUs), graphics processing units (GPUs), neural processing units, tensor processing units, display processing units, digital signal processors (DSPs), finite state machines, etc. Processor 102 can be operationally connected to memory device 108, to any storage (e.g., UFS device 104, additional storage device 110) of computing device 100, and / or to all or any portion of the trusted environment 112. Although Figure 1 shows computing device 100 with... Petition 870250083986, dated 09 / 18 / 2025, p. 30 / 170 25 / 73 a single processor 102, the computing device may include any number of processors without departing from the scope of the examples described in this invention.

[0040] In some examples, the computing device 100 includes a universal flash storage (UFS) device 104. In some examples, the UFS device 104 is a flash storage device conforming to the UFS specification. The UFS device 104 can be used to store data of any type. Data can be written to and / or read from the UFS device 104. For example, the UFS device can store operating system images, software images, application data, etc. The UFS device 104 can store any other type of data without departing from the scope of the examples described in the present invention. In some examples, the UFS device 104 includes NAND flash storage. The UFS device 104 can use any other type of storage technology without departing from the scope of the examples described in the present invention.In some examples, the UFS 104 device is capable of data rates that are relatively faster than other storage devices (e.g., additional storage device 110) of the computing device 100. The UFS 104 device can be operationally connected to the processor 102, the memory device 108, the additional storage device 110, and / or to all or any portion of the trusted environment. Although Figure 1 shows the computing device 100 with a single UFS 104 device, the computing device can include any number of UFS devices without this being the case. Petition 870250083986, dated 09 / 18 / 2025, page 31 / 170 26 / 73 is outside the scope of the examples described in the present invention. Additionally, although Figure 1 shows the UFS device 104, the computing device 100 may include any other type of flash storage device without departing from the scope of the examples described in the present invention.

[0041] In some examples, computing device 100 includes an additional storage device 110. In some examples, the additional storage device is any one or more non-volatile storage devices. The additional storage device 110 may, for example, be a persistent memory device. In some examples, the additional storage device 110 may be computer storage of any type. Examples of computer storage types include, but are not limited to, hard disks, solid-state drives, flash storage, tape drives, removable disk drives, Universal Serial Bus (USB) storage devices, Secure Digital (SD) cards, optical storage devices, read-only memory devices, etc.Although Figure 1 shows the additional storage device 110 as part of the computing device 100, the additional storage device may be separate from, and operationally connected to, the computing device 100 (e.g., an external hard drive array, cloud storage, etc.). In some instances, the additional storage device 110 operates at a data rate that is relatively slower than the UFS device 104. In some instances, the... Petition 870250083986, dated 09 / 18 / 2025, page 32 / 170 27 / 73 additional storage device 110 is also a UFS storage device. In some examples, the additional storage device 110 is operationally connected to the processor 102, the UFS device 104, the memory device 108, and / or all or any portion of the trusted environment 112. Although Figure 1 shows the computing device 100 with a single additional storage device 110, the computing device 100 may have any number of additional storage devices without departing from the scope of the examples described in the present invention.

[0042] In some instances, computing device 100 includes a memory device 108. The memory device can be any type of computer memory. In some instances, memory device 108 is a volatile storage device. For example, memory device 108 might be random access memory (RAM). In one or more instances, the data stored in memory device 108 is located at memory addresses and is therefore accessible to processor 102 using those memory addresses. Similarly, processor 102 can write data to, and read data from, memory device 108 using those memory addresses. Memory device 108 can be used to store any type of data, such as computer programs, computation results, etc.In some examples, memory device 108 is operationally connected to processor 102, to UFS device 104, to additional storage device 110, and / or to all or any of them. Petition 870250083986, dated 09 / 18 / 2025, p. 33 / 170 28 / 73 portion of the reliable environment 112. Although Figure 1 shows the computing device 100 with a single memory device 108, the computing device 100 may have any number of memory devices without departing from the scope of the examples described in the present invention.

[0043] In some instances, computing device 100 includes trusted environment 112. Trusted environment 112 can be any hardware (e.g., circuit assembly), software, firmware, or any combination thereof configured to perform various services that can protect computing device 100. Examples of such services may include, but are not limited to, performing various operations to execute various types of cryptographic services, providing secure boot functionality, managing cryptographic keys, cryptographic key derivation, etc. Examples of trusted environment 112 include, but are not limited to, secure execution environments, trusted management environments, trusted execution environments, trust zones, trusted platform modules, secure elements, etc.The trusted environment 112 may be operationally connected to the processor 102, the UFS device 104, the additional storage device 110, and / or the memory device 108. Although Figure 1 shows the computing device 100 as having a single trusted environment 112, the computing device 100 may have multiple trusted environments without departing from the scope of the examples described in the present invention. Furthermore, although Figure 1 shows several components (described below) as being included in a single trusted environment 112, the whole or any portion thereof. Petition 870250083986, dated 09 / 18 / 2025, page 34 / 170 29 / 73 of the components shown within the trusted environment 112 may be in different secure execution environments (not shown) of the computing device 100, and / or not in a secure execution environment (e.g., being part of a rich execution environment).

[0044] In some examples, the trusted environment includes multiple secure storage locations for measurement values ​​(e.g., secure storage location A for measurement value 114, secure storage location B for measurement value 116). In some examples, a secure storage location for measurement values ​​is any hardware (e.g., circuit assembly), software, firmware, or any combination thereof configured to securely store information of any type. Such information may be or include a measurement value.

[0045] In some examples, a secure measurement value storage location is any location or medium for data storage to which writing is somehow restricted. As an example, a secure measurement value storage location (e.g., 114, 116) might be a register (e.g., a platform control register) configured to be written to only once (e.g., a single-write storage device) during a secure initialization process, which is subsequently immutable for all or any portion of the time that the computing device 100 operates continuously (e.g., remains powered on). A different register (e.g., a second platform control register) might be configured to be written to during a secure initialization process by an entity associated with Petition 870250083986, dated 09 / 18 / 2025, page 35 / 170 30 / 73 generation of inputs for a key derivation function, and may include any information (e.g., an expected measurement value based on a hash obtained from an updated software image, a serial number of another component, etc.). Other examples of secure measurement value storage locations may be used without departing from the scope of the examples described in the present invention (e.g., immutable memory devices, one-time programmable devices, fuse-based devices, registers, other volatile or non-volatile storage, etc.). Although Figure 1 shows computing device 100 as having two secure measurement value storage locations, computing device 100 may have multiple such storage locations without departing from the scope of the embodiments described in the present invention.

[0046] In some examples, platform key storage 118 is any location and / or medium suitable for storing data of any type. As an example, platform key storage 118 may be any type of storage discussed above in relation to secure measurement storage locations (114, 116). As another example, platform key storage 118 may be a hardware component configured during a manufacturing process to include certain immutable secret data. In some examples, this data may be referred to as a platform key. As used in the present invention, the term platform key may refer to any cryptographic key that may be somehow incorporated into one or more devices (which may be identical or similar devices), such as computing device 100, so as Petition 870250083986, dated 09 / 18 / 2025, page 36 / 170 31 / 73 that the platform key can be obtained by entities (e.g., hardware components, software components, etc.) of a given device, but not by other devices (e.g., the platform key is not a shared secret). Although Figure 1 shows the computing device 100 as having a platform key storage 118, the computing device 100 may include multiple such storage locations to store multiple platform keys without departing from the scope of the embodiments described in the present invention.

[0047] In some examples, the secure storage locations of measurement value (e.g., 114, 116) and the platform key storage 118 are each operationally connected to a key derivation component 120. In some examples, the key derivation component 120 is any hardware, software, firmware, or any combination thereof, configured to perform a key derivation function to generate various derived cryptographic keys. In some examples, a key derivation function is any algorithm, which may be at least partially implemented in hardware, that takes one or more inputs, performs a function to produce an output based on the one or more inputs, where the output is, at least in part, a derived cryptographic key.The entries may include, but are not limited to, a platform key (e.g., stored in platform key storage 118) and various other entries (e.g., the contents of secure measurement value storage locations).

[0048] As used in the present invention, a measurement value can be any item of information based Petition 870250083986, dated 09 / 18 / 2025, page 37 / 170 32 / 73 in, associated with, derived from, or otherwise corresponding to any other one or more items of information. Measurement values ​​may be, include, or otherwise relate to any item of information of a computing device 100. Examples include, but are not limited to, hash values ​​associated with aggregated software images, serial numbers or other identifying information items associated with device components, physical values ​​measured during the operation of a computing device, state information of a computing device at a given time (e.g., the contents of one or more registers), etc. In some examples, a measurement value is a combination of any one or more of the examples mentioned above and / or any other type of measurement value.For example, a measurement value could be a hash of a software image being loaded during a secure boot process combined with a measured state value from a computing device register at a certain point during the boot process. [004 9] A measurement value may be called a reliable measurement value or an expected measurement value. In some examples, a reliable measurement value is a measurement value obtained during a secure boot process. As an example, during a secure boot process, the trusted environment 112 may be configured to validate one or more software images to be loaded by obtaining a hash of the one or more software images (e.g., an aggregated software image) and obtaining a certain value from a particular register, and combining the two pieces of information to form a value. Petition 870250083986, dated 09 / 18 / 2025, page 38 / 170 33 / 73 of reliable measurement. An expected measurement value can be a data item of any type obtained in any way. As an example, an expected measurement value might be based on, or otherwise include, a hash value of an updated aggregate software image obtained by the trusted environment 112 during a secure boot process from a repository of such information available to the trusted environment (e.g., via a network). The expected measurement value might be a combination of such a value obtained and another measured value from the computing device 100 (e.g., a state information item).

[0050] Thus, in some examples, a reliable measurement value is reliable when one or more items of information used for the reliable measurement value are measured during a secure initialization of a device. The expected measurement value, in some examples, is based, at least in part, on an item of information (e.g., the hash of a software image update that has not yet been applied, a serial number of another component, etc.) that is obtained rather than measured. In some examples, this difference in measurement values ​​can be used to generate cryptographic keys for different entities in various scenarios that are secure between different measurement states of a computing device (e.g., 100).

[0051] As an example, a reliable measurement value can be used as an input to a key derivation function (discussed above), an expected measurement value can be used as a second input to the key derivation function, and a platform key (discussed above) can be used as a third input. Petition 870250083986, dated 09 / 18 / 2025, page 39 / 170 34 / 73 for the key derivation function. The key derivation function can then be executed (for example, by the key derivation component 120) to produce, as an output, a derived cryptographic key. If the key is used by two separate entities (for example, an early version of an aggregated software image and an updated version, between two components of a device, etc.), then the same cryptographic key must be generated for each entity. Derivation of the same key can be achieved, in some instances, by providing the same inputs to the key derivation function.Assuming the platform key remains common, making the measured value inputs equal may require configuring one or more elements of the trusted environment 112 and / or any component within it to ensure that the values ​​of secure storage locations of measured value (e.g., 114, 116) remain the same between different measurement states of a computing device and / or component within it.

[0052] As an example, the trusted environment can be configured to determine a secure measurement value location (e.g., 114) to be the storage location for the trusted measurement value during a secure boot process. Such a determination can be made, for example, based on any piece of information (e.g., software version number) associated with an aggregated software image to be loaded. The trusted environment 112 can be further configured to obtain an expected measurement value (described above) and store the expected measurement value in a second secure measurement value storage location (e.g., 116). While the image of Petition 870250083986, dated 09 / 18 / 2025, page 40 / 170 35 / 73 aggregate software is running (e.g., during a secure boot process before a reboot after a software update), the two values ​​of the secure storage location of the measurement value, and the platform key, can be provided to a key derivation function (discussed below) to derive one or more cryptographic keys for use by the software in the aggregate software image in order to perform various cryptographic operations (e.g., encrypting and / or decrypting data). The data on which cryptographic operations are performed (e.g., decrypted data) may be required during the operation of the computing device 100 after a software update has been performed.

[0053] As an example, during a boot process, a first aggregated software image can be loaded, and a reliable measurement value can be obtained and stored in a configured write-only secure storage location. The aggregated software image can be configured to check for software updates, which can then be obtained. The trusted environment 112 can be configured to obtain a hash value as at least part of an expected measurement value of the planned updated version of the aggregated software image. The expected measurement value can be stored in a second secure measurement value storage location (which can also be pre-configured or determined based on any information) and used as part of the key derivation process. After reboot, a secure boot process continues with the execution of the updated aggregated software image. During this boot, Petition 870250083986, dated 09 / 18 / 2025, page 41 / 170 36 / 73 The updated aggregate software image is used to obtain the reliable measurement value, which is stored in the second secure measurement storage location during the current initialization based on the updated aggregate software image having a different version number than the previous aggregate software image. The reliable environment 112 can be configured to obtain information associated with the previous aggregate software image, generate an expected measurement value for the previous aggregate software image, and store the value in the first secure measurement value storage location, as configured.

[0054] This configuration can cause the values ​​of the two secure measurement value storage locations to remain the same between subsequent initializations (as the locations of the reliable and expected values ​​are switched, but remain the same values ​​based on the information used to obtain the values ​​remaining the same). Thus, when there is a match between the reliable measurement value generated during the first initialization and the one obtained as an expected measurement value during the second initialization, and vice versa for the updated aggregate software image, and the storage locations for each are as described above, the inputs to the key derivation function remain the same.Therefore, since the inputs to the key derivation function can remain the same, one or more common cryptographic keys can be derived for the updated aggregate software image that corresponds to the one or more cryptographic keys previously derived for the previous aggregate software image during the previous initialization. Therefore, the software image... Petition 870250083986, dated 09 / 18 / 2025, page 42 / 170 The updated aggregated software image 37 / 73 may be able to access or otherwise use data previously used by the earlier aggregated software image that may have been protected by cryptographic keys derived during the previous initialization. In other words, the aggregated software image and the updated aggregated software image may be able to have common cryptographic keys derived for use in performing cryptographic operations on common data, based on matches between reliable measurement values ​​and expected measurement values ​​between different measurement states (e.g., different initializations during a secure initialization process) of a computing device.

[0055] As another example, two components (not shown in Figure 1) of computing device 100 may require access to common data (e.g., an input / output component and a display generation component). In some examples, this data may be subjected to cryptographic operations. Therefore, similar to the example described above, each component may generate a reliable measurement value based, at least in part, on information (e.g., a serial number) associated with itself, and obtain an expected measurement value (e.g., a serial number) associated with the other component. The first component may be configured so that the two measurement values ​​are stored in a certain order in secure measurement value storage locations being provided as inputs to a key derivation function instance.The second component can be configured to do the same, but in reverse order, providing the same inputs to the same key derivation function instance, or to one. Petition 870250083986, dated 09 / 18 / 2025, page 43 / 170 38 / 73 separate instance of the key derivation function. Thus, when the reliable and expected measurement values ​​associated with the first component values ​​are the same for the second component, and a shared secret (e.g., a platform key) is commonly available to both components, the same cryptographic keys can be derived for both components between different measurement states (e.g., due to being performed by different components, at different points in time, etc.). Such components can be separated from, or included in, any one or more reliable environments (e.g., 112) of the computing device 100.

[0056] In some examples, as discussed above, the determination of which secure measurement value storage location (e.g., 114, 116) is configured to store a reliable measurement value or an expected measurement value can be accomplished using any technique for determining where data is stored. As an example, a reliable environment (e.g., 112) can be configured to determine a location for a reliable measurement value based on an information item (e.g., version number, component identification information, etc.) and configured to use a separate location for the expected measurement value. In some examples, after a state change (e.g., software update followed by reboot, during the initialization of separate components, etc.), the reliable environment can be configured to reverse the locations where measurement values ​​are stored, at least relative to the configuration of the inputs. Petition 870250083986, dated 09 / 18 / 2025, page 44 / 170 39 / 73 for a key derivation function. This inversion causes the inputs to remain the same between measurement states, thus allowing the previously mentioned common cryptographic key derivation(s).

[0057] In some examples, the computing device 100 includes several security components (for example, security component 122, security component 124). Security components 122 and 124 can be any component capable of performing various cryptographic services and can thus be any hardware (e.g., circuit assembly), software, firmware, or any combination thereof. In some examples, the security components are subchip hardware components of a system-on-a-chip (SoC), which may include other components shown in Figure 1, such as, for example, the processor 102. Any other components of the computing device 100 may also be included as part of an SoC without departing from the scope of the examples described in the present invention.In some examples, the security components exist on a data path between storage devices (e.g., UFS storage device 104, additional storage device 110) and memory device 108, and / or data paths between processor 102 and memory device 108 or any of the storage devices (e.g., 104, 110). In some examples, all or any portion of the security components may be considered as inline cryptographic mechanisms. In some examples, the security components (e.g., 122, 124) are configured to perform. Petition 870250083986, dated 09 / 18 / 2025, page 45 / 170 40 / 73 various types of cryptographic services on data being read from, or written to, a storage device (e.g., UFS device 104, additional storage device 110) and / or a memory device 108 of the computing device 100. In some examples, all or any portion of the data passing from memory to storage, from storage to memory, or to or from the processor 102 of the computing device 100 passes through a security component (e.g., 122, 124). In some examples, the security components (122, 124) are configured to use cryptographic keys derived as described in the present invention by key derivation functions in order to perform various cryptographic operations (e.g., encryption, decryption, authentication, validation, etc.).Although Figure 1 shows the trusted environment as having two security components (122, 124), the trusted environment 112 and / or the computing device 100 may include multiple security components without departing from the scope of the examples described in the present invention.

[0058] Although Figure 1 shows a certain number of components in a particular configuration, a person skilled in the art will recognize that the computing device 100 may include more or fewer components and / or components arranged in any number of alternative configurations, without departing from the scope of the examples described in the present invention. Additionally, some or all of the components shown may be part of a single component, and any single component shown may be implemented in the form of multiple components. Petition 870250083986, dated 09 / 18 / 2025, page 46 / 170 41 / 73 distinct. As an example, although Figure 1 shows several components as being included in computing device 100, all or any portion of such components may be separated from, and operationally connected to, computing device 100 without departing from the scope of the examples described in the present invention. Additionally, although not shown in Figure 1, a person skilled in the art will recognize that computing device 100 may run any amount or type of software or firmware (e.g., boot loaders, operating systems, hypervisors, virtual machines, computer applications, mobile device applications, etc.). Consequently, the examples disclosed in the present invention should not be limited to the configuration of the components shown in Figure 1.

[0059] Figures 2A and 2B are diagrams illustrating an environment 200 according to one or more examples described in the present invention. In an illustrative example, environment 200 is an example of the reliable environment 112 of Figure 1. Certain aspects of examples described in the present invention are set forth below in relation to Figures 2A and 2B. The following examples are for illustrative purposes only and are not intended to limit the scope of the examples described in the present invention. Furthermore, although the example shows certain aspects of the examples described in the present invention, all possible aspects of such examples may not be illustrated in this particular example. In certain respects, obscuring details are omitted, such as certain components and devices discussed above in the description of Figure 1, in order to provide clarity to certain aspects. Petition 870250083986, dated 09 / 18 / 2025, page 47 / 170 42 / 73 described in the present invention.

[0060] Figures 2A and 2B are block diagrams illustrating an example environment 200 according to one or more examples described in the present invention. As shown in Figure 2A and Figure 2B, environment 200 includes a first secure storage location 202 and a second secure storage location 204, which may be the same as or similar to the secure measurement value storage locations 114 and 116 discussed above in the description of Figure 1. As shown in Figure 2A and Figure 2B, environment 200 also includes a platform key 206, which may, for example, be the same as or similar to a platform key discussed above in the description of Figure 1 and stored in a platform key storage (for example, platform key storage 118 of Figure 1).

[0061] Figure 2A and Figure 2B also show environment 200 as including a key derivation function 208. As an example, the key derivation function 208 can be executed, at least in part, using the key derivation component 120 discussed above in the description of Figure 1. Although not shown in Figure 2A or Figure 2B, all or any portions of the components of environment 200 can be included in, or otherwise operationally connected to, one or more trusted environments (for example, trusted environment 112 of Figure 1).

[0062] In some examples, the first secure storage location 202, the second secure storage location 204, and the platform key 206 can each be configured as inputs to the derivation function. Petition 870250083986, dated 09 / 18 / 2025, page 48 / 170 43 / 73 key 208. In some examples, the key derivation function 208 processes the values ​​provided as inputs to obtain as output a derived cryptographic key 210. In some examples, as long as the inputs remain the same, the derived cryptographic key 210 may remain the same.

[0063] Environment 200, as shown in Figure 2A shows an initial measurement state, such as a boot environment during a secure boot process after initializing an initial aggregate software image. The initial aggregate software image was used to calculate (i.e., measure) a hash value, and the hash value is combined with another measurement (a register value) to produce a reliable measurement value of 0xabba. This reliable measurement value is stored in a write-only platform control register configured to store a reliable measurement value and then not be rewritten (at least until a subsequent boot). The determination to store the reliable measurement value is based, at least in part, on a version number associated with the initial aggregate software image.In this scenario, the secure boot process includes performing an update of the initial aggregate software image and rebooting to run an updated aggregate software image. Therefore, a trusted environment (not shown) from environment 200 obtains an expected measurement value corresponding to the updated aggregate software image, which includes a hash value associated with the updated aggregate software image. The expected value, 0xdbac, is configured to be stored in the second secure storage location 204. The trusted measurement value, the expected measurement value, and the platform key. Petition 870250083986, dated 09 / 18 / 2025, page 49 / 170 44 / 73 6 are used as input for the key derivation function 208 in order to derive the derived cryptographic key 210, which is used during the operation of the initial aggregate software image to perform cryptographic operations on data.

[0064] However, the updated aggregate software image will need to use the data on which cryptographic operations may have been performed. Thus, after a reboot, when the updated aggregate software image is running, the updated aggregate software image requires the same cryptographic keys previously used on the data by the initial aggregate software image. To achieve such a common derived cryptographic key, a similar process is performed to obtain reliable and expected measurement values ​​as described above, resulting in environment 200 as shown in Figure 2B.

[0065] In Figure 2B, the values ​​stored in the secure storage locations remain the same, but derived in a manner opposite to that described above during the previous initialization. Specifically, in some examples, the reliable measurement value calculated during initialization for the updated aggregate software image again uses the hash of the updated aggregate software image and is therefore calculated to be equal to the expected measurement value in the previous initialization. Due to a different version number associated with the updated aggregate software image, the reliable measurement value is now stored in the second secure storage location 204. An expected measurement value associated with the initial aggregate software image is obtained, and configured to be stored, during this initialization. Petition 870250083986, dated 09 / 18 / 2025, page 50 / 170 45 / 73 subsequent, in the first secure storage location 202.

[0066] Consequently, the inputs to the key derivation function 208 remain the same between subsequent initializations (e.g., two different measurement states), allowing the same derived cryptographic key 210 to be obtained for use by both the initial aggregated software image and the updated aggregated software image.

[0067] Although the previously mentioned example contemplates the derivation of common cryptographic keys for separate software images during a secure initialization process by reversing the order in which reliable and expected measurement values ​​are stored in secure storage locations, a person skilled in the art, and benefiting from this Detailed Description, will recognize that the technique can be applied to any other scenario where two entities require a common cryptographic key to be derived using a key derivation function.

[0068] As a simple example, 0xabba could be a serial number of a first component of a computing device, and 0xdbac could be a serial number of a second component of the computing device. The components may require the ability to operate commonly on the same data, some of which may be subject to a cryptographic operation (e.g., encrypted, requiring subsequent decryption). When the components are being initialized, a reliable measurement value of the first component that includes the serial number 0xabba can be obtained for the first component, along with an expected measurement value including the Petition 870250083986, dated 09 / 18 / 2025, page 51 / 170 46 / 73 Oxdbac serial number of the second component. The computing device can be configured so that, when deriving a cryptographic key for the first component, the reliable measurement value is provided as a first input to a key derivation function, and the expected measurement value can be provided as a second input. These inputs can be combined with a platform key input to generate a derived cryptographic key.

[0069] Separately, a reliable measurement value of the second component that includes the serial number 0xdbac can be obtained for the second component, along with an expected measurement value including the serial number 0xabba of the first component. The computing device can be configured so that, when deriving a cryptographic key for the second component, the expected measurement value is provided as a first input to a key derivation function, and the reliable measurement value can be provided as a second input. These inputs can be combined with a platform key input to generate a derived cryptographic key. Thus, in each case, the inputs to the key derivation, and therefore the output cryptographic key, remain the same. Therefore, each of the two components can have a common derived cryptographic key to perform cryptographic operations.

[0070] Figure 3 is a flow diagram illustrating an example of a process 300 for key establishment (e.g., key establishment in pairs between measurement states) according to one or more examples described in the present invention. The process 300 can be carried out, at least in part, for example, by a computing device. Petition 870250083986, dated 09 / 18 / 2025, page 52 / 170 47 / 73 or a component (e.g., a chipset, etc.) of the computing device. In an illustrative example, process 300 can be performed, at least in part, by the computing device 100 shown in Figure 1 and described above (or any one or more components or elements therein).

[0071] In block 302, the computing device (or component thereof) may, during a first (or initial) cryptographic key derivation, store a first trusted measure value associated with a first entity (e.g., a first software image, a first component, etc.) in a first secure storage location (e.g., secure storage location A of measure value 114). With reference to Figure 2A as an illustrative example, the first trusted measure value may be the trusted measure value 0xabba stored in the first secure storage location 202. In an illustrative example, the first trusted measure value includes a hash (e.g., a cryptographic hash) of the first software image.

[0072] In block 304, the computing device (or component thereof) may, during the first cryptographic key derivation, store an expected measurement value associated with a second entity (e.g., a second software image, a second component, etc.) in a second secure storage location (e.g., secure storage location B of measurement value 116). With reference to Figure 2A as an illustrative example, the expected measurement value may be the expected measurement value 0xdbac stored in the second location of Petition 870250083986, dated 09 / 18 / 2025, page 53 / 170 48 / 73 Secure Storage 204. In an illustrative example, the expected measurement value includes a hash (e.g., a cryptographic hash) of the second software image.

[0073] In some respects, when the first entity is a first component and the second entity is a second component, the first reliable measurement value may include a first item of identifying information (e.g., a first serial number) associated with the first component and the expected measurement value may include a second item of identifying information (e.g., a second serial number) associated with the second component.

[0074] In block 306, the computing device (or component thereof) may, during the first cryptographic key derivation, generate a first instance of a cryptographic key (for example, the cryptographic key derived 206 of Figure 2A) using the first reliable measurement value, the expected measurement value, and a key derivation function (for example, the key derivation component 120 of Figure 1, the key derivation function 208 of Figure 2A and / or 2B and / or another key derivation function).

[0075] In block 308, the computing device (or component thereof) may, during a second cryptographic key derivation, obtain, after generating the first instance of the cryptographic key during the first cryptographic key derivation, the expected measurement value as a second trusted measurement value associated with the second entity. In block 310, the computing device (or component thereof) may, during the second cryptographic key derivation, store the second trusted measurement value in the second secure storage location. With Petition 870250083986, dated 09 / 18 / 2025, page 54 / 170 49 / 73 Referring to Figure 2B as an illustrative example, the expected measurement value 0xdbac from Figure 2A is stored as the second reliable measurement value in the second secure storage location 204 in Figure 2B.

[0076] In block 312, the computing device (or component thereof) may, during the second cryptographic key derivation, obtain the first reliable measurement value as a second expected measurement value. In block 314, the computing device (or component thereof) may, during the second cryptographic key derivation, store the second expected measurement value in the first secure storage location. With reference to Figure 2B as an illustrative example, the reliable measurement value 0xabba from Figure 2A is stored as the second expected measurement value in the first secure storage location 202 in Figure 2B.

[0077] In block 314, the computing device (or component thereof) can, during the second cryptographic key derivation, generate a second instance of the cryptographic key (for example, the cryptographic key derived 206 of Figure 2B) using the second expected measurement value, the second reliable measurement value, and the key derivation function. In some cases, the computing device (or component thereof) can generate the first instance of the cryptographic key and the second instance of the cryptographic key using the key derivation function and using a platform key common to the first entity and the second entity. As noted in the present invention, a platform key can be a cryptographic key available to at least two entities. Petition 870250083986, dated 09 / 18 / 2025, page 55 / 170 50 / 73 (for example, the first entity and the second entity) is a protected secret known only to one or more devices that include both entities. The platform key can be made available as an input to the key derivation function performed by, and / or on behalf of, the two entities.

[0078] In some respects, the computing device (or component thereof) may select the first secure storage location during the first cryptographic key derivation to store the first trusted measurement value based on a parameter associated with the first entity, such as based on a version number of the first entity (e.g., included with the software image, etc.), an instruction included with the first entity (e.g., the software image, etc.) indicating a particular secure storage location to which the trusted measurement value should be written, any combination thereof and / or other parameter(s) or information(s).In some cases, the computing device (or component thereof) may select the second secure storage location during the second cryptographic key derivation to store the second reliable measurement value based on a parameter associated with the second entity, such as based on a version number of the second entity (e.g., the software image, etc.), an instruction included with the second entity (e.g., included with the software image, etc.) indicating a particular secure storage location to which the reliable measurement value should be written, any combination thereof, and / or other parameter(s) or information. Petition 870250083986, dated 09 / 18 / 2025, page 56 / 170 51 / 73

[0079] As mentioned above, process 300, or any other process described in the present invention, can be performed by a computing apparatus or device (for example, the computing device 100 of Figure 1, the computing system of Figure 4, etc.), and / or one or more components therein and / or to which the computing device is operationally connected.The computing device may be, include, or be a component of any suitable device, such as a vehicle or a vehicle computing device (e.g., a vehicle driver monitoring system (DMS)), a mobile device (e.g., a mobile phone), a desktop computing device, a tablet computing device, a wearable device (e.g., a VR headset, an AR headset, AR glasses, a smartwatch or network-connected watch or other wearable device), a server computer, a robotic device, a television, a smart speaker, a voice assistant device, a SoC, and / or any other device with resource capabilities to perform the processes described in the present invention, including process 500 and / or another process described in the present invention.In some cases, a computing device or apparatus (for example, one that includes a hardware identity imitator) may include several components, such as one or more input devices, one or more output devices, one or more processors, one or more microprocessors, one or more microcomputers, one or more cameras, one or more sensors, and / or other component(s) that are configured to perform process operations. Petition 870250083986, dated 09 / 18 / 2025, page 57 / 170 52 / 73 described in the present invention. In some examples, the computing device may include a display, a network interface configured to communicate and / or receive data, an RF sensor detection component, any combination thereof and / or other component(s). The network interface may be configured to communicate and / or receive data based on the Internet Protocol (IP) or other data type.

[0080] The components of a computing device (for example, computing device 100 of Figure 1, computing system 400 of Figure 4) may be implemented, at least in part, in circuit assemblies. For example, the components may include, and / or may be implemented with, the use of electronic circuits or other electronic hardware, which may include one or more programmable electronic circuits (for example, microprocessors, graphics processing units (GPUs), digital signal processors (DSPs), central processing units (CPUs), finite state machines and / or other suitable electronic circuits), and / or may include, and / or may be implemented with, the use of computer software or firmware or any combination thereof, to perform the various operations described in the present invention.

[0081] Process 300, shown in Figure 3, is illustrated as a logical flow diagram, where the operation represents a sequence of operations that can be implemented in hardware, computer instructions, or a combination thereof. In the context of computer instructions, the operations represent computer-executable instructions stored in one or more computer-readable storage media that, when executed Petition 870250083986, dated 09 / 18 / 2025, page 58 / 170 53 / 73 by one or more processors, perform the aforementioned operations. In general, computer executable instructions include routines, programs, objects, components, data structures, and the like that perform particular functions or implement particular data types. The order in which the operations are described is not intended to be interpreted as a limitation, and several of the described operations can be combined in any order and / or in parallel to implement the processes.

[0082] Additionally, process 300 and / or another process described in the present invention may be carried out under the control of one or more computer systems configured with executable instructions and may be implemented in the form of code (e.g., executable instructions, one or more computer programs, or one or more applications) collectively running on one or more processors, by hardware or by combinations thereof. As mentioned above, the code may be stored on a computer-readable or machine-readable storage medium, for example, in the form of a computer program comprising a plurality of instructions executable by one or more processors. The computer-readable or machine-readable storage medium may be non-transient.

[0083] Figure 4 is a diagram illustrating an example of a system for implementing certain aspects of the present technology. In particular, Figure 4 illustrates an example of a computing system 400, which may be, for example, any computing device that makes up an internal computing system, a remote computing system, a camera, or any component thereof in Petition 870250083986, dated 09 / 18 / 2025, page 59 / 170 54 / 73 that the system components are communicating with each other using the 405 connection. The 405 connection can be a physical connection using a bus or a direct connection to the processor 410, as in a chipset architecture. The 405 connection can also be a virtual connection, a network connection, or a logical connection.

[0084] In some examples, the 400 computing system is a distributed system in which the functions described in this disclosure may be distributed across a single data center, multiple data centers, a peer-to-peer network, etc. In some examples, one or more of the described system components represent many such components, wherein each performs part or all of the function for which the component is described. In some examples, the components may be physical or virtual devices.

[0085] The example system 400 includes at least one processing unit (CPU or processor) 410 and a connection 405 that connects various system components, including a system memory 415, such as a read-only memory (ROM) 420 and a random-access memory (RAM) 425 to the processor 410. The computing system 400 may include a high-speed memory cache 412 connected directly to, in close proximity to, or integrated as part of the processor 410.

[0086] Processor 410 may include any general-purpose processor and a hardware service or a software service, such as services 432, 434, and 436 stored in storage device 430, configured to control processor 410, as well as a special-purpose processor where software instructions are Petition 870250083986, dated 09 / 18 / 2025, pp. 60 / 170 55 / 73 incorporated into the actual processor design. The 410 processor can essentially be a completely single-piece computing system, containing multiple cores or processors, a bus, memory controller, cache, etc. A multi-core processor can be symmetric or asymmetric.

[0087] To enable user interaction, the computing system 400 includes an input device 445, which may represent various input mechanisms or sensors, such as a microphone for speech (e.g., a user speaking), a touch screen for graphical or gesture input (e.g., a user performing sign language symbols, a user shaking a phone, etc.), a keyboard (e.g., a user pressing a key), a mouse, motion input, a determination that a user is in a location indicated by a positioning system or modem subsystem, etc., which may be used to activate counters described in previous sections and enable / disable the asset transmission chain at any stage previously described. The computing system 400 may also include the output device 435, which may be one or more of several output mechanisms.In some cases, multimodal systems may enable a user to provide multiple types of input / output to communicate with the computing system. The computing system may include a communication interface that can generally govern and manage user inputs and system outputs. The communication interface may perform or facilitate the reception and / or transmission of wired or wireless communications using wired and / or wireless transceivers, including those that make use of one. Petition 870250083986, dated 09 / 18 / 2025, pp. 61 / 170 56 / 73 audio connector / plug, one microphone connector / plug, one Universal Serial Bus (USB) port / plug, one Apple® Lightning® port / plug, one Ethernet port / plug, one fiber optic port / plug, one proprietary wired port / plug, one BLUETOOTH® wireless signal transfer, one BLUETOOTH® Low Energy (BLE) wireless signal transfer, one IBEACON® wireless signal transfer, one radio-frequency identification (RFID) wireless signal transfer, one near-field communications (NFC) wireless signal transfer, one dedicated short-range communication (DSRC) wireless signal transfer, one WiFi 802 wireless signal transfer.11, wireless local area network (WLAN) signal transfer, visible light communication (VLC), worldwide interoperability for microwave access (WiMAX), wireless infrared (IR) signal transfer, public switched telephone network (PSTN) signal transfer, integrated services digital network (ISDN) signal transfer, wireless cellular data network (3G / 4G / 5G / LTE) signal transfer, ad-hoc network signal transfer, radio wave signal transfer, microwave signal transfer, infrared signal transfer, visible light signal transfer, ultraviolet light signal transfer, wireless signal transfer over the... Petition 870250083986, dated 09 / 18 / 2025, page 62 / 170 57 / 73 electromagnetic spectrum or some combination thereof. The communication interface 440 may also include one or more global navigation satellite system (GNSS) receivers or transceivers that are used to determine a location of the computing system 400 based on the reception of one or more signals from one or more satellites associated with one or more GNSS systems. GNSS systems include, but are not limited to, the US-based Global Positioning System (GPS), the Russian-based Global Navigation Satellite System (GLONASS), the Chinese-based BeiDou Navigation Satellite System (BDS), and the European-based Galileo GNSS. There is no restriction on operation in any particular hardware arrangement, and therefore the basic attributes herein can be easily replaced by improved hardware or firmware arrangements as they are developed.

[0088] Storage device 430 may be a non-volatile and / or non-transient and / or computer-readable memory device, and may be a hard disk or other types of computer-readable media that can store data that is accessible by a computer, such as magnetic cassettes, flash memory cards, solid-state memory devices, digital versatile disks, cartridges, a floppy disk, a floppy disk, a hard disk, a magnetic tape, a magnetic strip / band, any other magnetic storage media, flash memory, memristor memory, any other solid-state memory, a compact disc read-only memory (CDROM) optical disc, a rewritable compact disc (CD) optical disc, an optical disc of Petition 870250083986, dated 09 / 18 / 2025, pp. 63 / 170 58 / 73 digital video disc (DVD), a Blu-ray® optical disc (BDD), a holographic optical disc, other optical media, a Secure Digital (SD) card, a micro Secure Digital (microSD) card, a Memory Stick® card, a smart card chip, an EMV chip, a subscriber identity module (SIM) card, a mini / micro / nano / pico SIM card, other integrated circuit (IC) chip / card, random access memory (RAM), static RAM (SRAM), dynamic RAM (DRAM), read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), flash EPROM (FLASHEPROM), cache memory (L1 / L2 / L3 / L4 / L5 / Ln°),Resistive random-access memory (RRAM / ReRAM), phase-change memory (PCM), spin transfer torque RAM (STT RAM), other memory chip or cartridge, and / or a combination thereof. The storage device 430 may include software instructions or code that can be executed by the processor 410 to cause the system 400 to perform a function.

[0089] As used in the present invention, the term computer-readable media includes, but is not limited to, portable or non-portable storage devices, optical storage devices, and various other media capable of storing, containing, or carrying instructions and / or Petition 870250083986, dated 09 / 18 / 2025, pp. 64 / 170 59 / 73 data. A computer-readable medium may include a non-transient medium in which data can be stored and which does not include carrier waves and / or transient electronic signals that are propagated wirelessly or through wired connections. Examples of a non-transient medium may include, but are not limited to, a magnetic disk or tape, optical storage media such as a compact disc (CD) or digital versatile disc (DVD), flash memory, memory, or memory devices. A computer-readable medium may have stored therein machine-executable code and / or instructions that may represent a procedure, a function, a subprogram, a program, a routine, a subroutine, a module, a software package, a class, or any combination of instructions, data structures, or program statements.A code segment can be coupled to another code segment or a hardware circuit through the passing and / or receiving of information, data, arguments, parameters, or memory content. Information, arguments, parameters, data, etc., can be passed, forwarded, or transmitted using any suitable means, such as memory sharing, message forwarding, token forwarding, network transmission, or similar methods.

[0090] In some examples, computer-readable storage devices, media, and memories may include a cable or wireless signal containing a bit stream and the like. However, when mentioned, computer-readable non-transient storage media expressly exclude media such as energy, carrier signals, electromagnetic waves, and signals themselves. Petition 870250083986, dated 09 / 18 / 2025, pp. 65 / 170 60 / 73

[0091] The above description provides specific details for a complete understanding of the aspects and examples provided in the present invention. However, it will be understood by those skilled in the art that the examples can be practiced without these specific details. For clarity of explanation, in some cases, the present technology may be presented as including individual functional blocks comprising devices, device components, operations, steps, or routines in a method embodied in software, hardware, or combinations of hardware and software. Additional components may be used beyond those shown in the figures and / or described in the present invention. For example, circuits, systems, networks, processes, and other components may be shown as components in block diagram form so as not to obscure the examples with unnecessary details.In other instances, well-known circuits, processes, algorithms, structures, and techniques can be shown without unnecessary detail in order to avoid obscuring the examples.

[0092] The individual examples above can be described as a process or method that is depicted as a flowchart, a flow diagram, a data flow diagram, a structure diagram, or a block diagram. Although a flowchart may depict operations as a sequential process, many of the operations may be performed in parallel or simultaneously. Furthermore, the order of operations can be rearranged. A process is interrupted when its operations are completed, but it could have additional operations not included in a figure. A process can correspond to a method, a function, a procedure, Petition 870250083986, dated 09 / 18 / 2025, pp. 66 / 170 61 / 73 a subroutine, a subprogram, etc. When a process corresponds to a function, its termination may correspond to a return from the function to the calling function or to the main function.

[0093] The processes and methods according to the examples described above can be implemented using computer-executable instructions that are stored or otherwise available from computer-readable media. Such instructions may include, for example, instructions and data that cause or otherwise configure a general-purpose computer, a special-purpose computer, or a processing device to perform a certain function or group of functions. The portions of computer resources used may be accessible through a network. The computer-executable instructions may be, for example, binaries, intermediate-format instructions such as assembly language, firmware, source code, etc.Examples of computer-readable media that can be used to store instructions, information used, and / or information created during methods according to the examples described include magnetic or optical disks, flash memory, USB devices provided with non-volatile memory, network storage devices, and so on.

[0094] Devices that implement processes and methods in accordance with these disclosures may include hardware, software, firmware, middleware, microcode, hardware description languages, or any combination thereof, and may take any of several form factors. When implemented in software, firmware, middleware, or microcode, the program code or the Petition 870250083986, dated 09 / 18 / 2025, pp. 67 / 170 62 / 73 code segments to perform the necessary tasks (e.g., a computer program product) can be stored on a computer-readable or machine-readable medium. A processor(s) can perform the necessary tasks. Typical examples of form factors include laptops, smartphones, cell phones, tablet-type devices or other small form factor personal computers, personal digital assistants, rack-mounted devices, standalone devices, and so on. The functionality described in the present invention can also be incorporated into peripherals or expansion cards. By way of further example, this functionality can also be implemented on a circuit board between different chips or different processes that are executed on a single device.

[0095] The instructions, the means for transporting such instructions, the computational resources for executing them, and other structures for supporting such computational resources are exemplary means for providing the functions described in the disclosure.

[0096] As mentioned above, aspects of the application are described with reference to specific examples thereof, but those skilled in the art will recognize that the application is not limited to this. Thus, although illustrative examples of the application have been described in detail in the present invention, it should be understood that the inventive concepts may otherwise be incorporated and employed in various ways, and that the appended claims are intended to be interpreted as including such variations, except as limited by the prior art. Several Petition 870250083986, dated 09 / 18 / 2025, pages 68 / 170 63 / 73 attributes and aspects of the application described above can be used individually or in combination. Additionally, the examples described in the present invention can be used in various environments and applications beyond those described in the present invention without departing from the broader spirit and scope of the descriptive report. The descriptive report and drawings should, therefore, be considered illustrative and not restrictive. For illustrative purposes, the methods have been described in a particular order. It should be considered that, in alternative examples, the methods may be carried out in a different order than that described.

[0097] A person skilled in the art will recognize that the less than (<) and greater than (>) symbols or terminology used in the present invention may be replaced by the less than or equal to (^) and greater than or equal to (>) symbols, respectively, without departing from the scope of this description.

[0098] Where components are described as being configured to perform certain operations, such configuration may be effected, for example, by designing electronic circuits or other hardware to perform the operation, by programming programmable electronic circuits (for example, microprocessors or other suitable electronic circuits) to perform the operation, or any combination thereof.

[0099] The phrase coupled to refers to any component that is physically connected to another component, directly or indirectly, and / or to any component that is in communication with another component (for example, connected to the other component via a wired or wireless connection and / or other interface). Petition 870250083986, dated 09 / 18 / 2025, pp. 69 / 170 64 / 73 adequate communication) directly or indirectly.

[00100] A claim language or other language that mentions at least one of a set and / or one or more of a set indicates that a member of the set or multiple members of the set (in any combination) satisfy the claim. For example, a claim language citing at least one of A and B or at least one of A or B means A, B, or A and B. In another example, a claim language citing at least one of A, B, and C or at least one of A, B, or C means A, B, C, or A and B, or A and C, or B and C, or A and B and C. The language "at least one of a set and / or one or more of a set" does not limit the set to the items listed in the set. For example, a claim language citing at least one of A and B or at least one of A or B may mean A, B, or A and B and may additionally include items not mentioned in the set of A and B.

[00101] The various illustrative logic blocks, modules, circuits, and algorithmic operations described in conjunction with the examples disclosed in the present invention can be implemented as electronic hardware, computer software, firmware, or combinations thereof. To clearly illustrate this interchangeability of hardware and software, various illustrative components, blocks, modules, circuits, and operations have been described above in terms of their functionality. The possibility of such functionality being implemented as hardware or software depends on the particular application and the design constraints imposed on the overall system. Those skilled in the art can implement the Petition 870250083986, dated 09 / 18 / 2025, pp. 70 / 170 65 / 73 functionality described in various ways for each particular application, but such implementation decisions should not be interpreted as causing a deviation from the scope of the present application.

[00102] The techniques described in the present invention can also be implemented in electronic hardware, computer software, firmware, or any combination thereof. Such techniques can be implemented in any of several devices, such as general-purpose computers, handsets of wireless communication devices, or integrated circuit devices that have multiple uses, including application in handsets of wireless communication devices and other devices. Any attributes described as modules or components can be implemented together in an integrated logic device, or separately as distinct but interoperable logic devices. If implemented in software, the techniques can be performed, at least in part, by a computer-readable data storage medium comprising program code including instructions that, when executed, perform one or more of the methods described above.Computer-readable data storage media may form part of a computer program product, which may include packaging materials. Computer-readable media may comprise memory or data storage media such as random access memory (RAM), such as synchronous dynamic random access memory (SDRAM), read-only memory (ROM), non-volatile random access memory (NVRAM). Petition 870250083986, dated 09 / 18 / 2025, pp. 71 / 170 66 / 73 Electrically erasable programmable read-only memory (EEPROM), FLASH memory, magnetic or optical data storage media and the like. The techniques may, additionally or alternatively, be implemented, at least in part, by a computer-readable communication medium that carries or communicates program code in the form of instructions or data structures and that can be accessed, read and / or executed by a computer as propagated signals or waves.

[00103] The program code may be executed by a processor, which may include one or more processors, such as one or more digital signal processors (DSPs), general-purpose microprocessors, application-specific integrated circuits (ASICs), field-programmable logic arrays (FPGAs), or other equivalent set of integrated or discrete logic circuits. Such a processor may be configured to perform any of the techniques described in this disclosure. A general-purpose processor may be a microprocessor; but alternatively, the processor may be any conventional processor, controller, microcontroller, or state machine.A processor can also be implemented as a combination of computing devices, for example, a combination of a DSP and a microprocessor, a plurality of microprocessors, one or more microprocessors together with a DSP core, or any other similar configuration. Consequently, the term processor, as used in the present invention, can refer to any of the aforementioned structures. Petition 870250083986, dated 09 / 18 / 2025, pp. 72 / 170 67 / 73 mentioned, any combination of the aforementioned structures, or any other structure or apparatus suitable for implementing the techniques described in the present invention.

[00104] Illustrative aspects of the disclosure include:

[00105] Aspect 1. A method for establishing a key, wherein the method comprises: during a first cryptographic key derivation: storing a first reliable measurement value associated with a first entity in a first secure storage location; storing an expected measurement value associated with a second entity in a second secure storage location; and generating a first instance of a cryptographic key using the first reliable measurement value, the expected measurement value, and a key derivation function; and during a second cryptographic key derivation: obtaining, after generating the first instance of the cryptographic key during the first cryptographic key derivation, the expected measurement value as a second reliable measurement value associated with the second entity; storing the second reliable measurement value in the second secure storage location;Obtain the first reliable measurement value as a second expected measurement value; store the second expected measurement value in the first secure storage location; and generate a second instance of the cryptographic key using the second expected measurement value, the second reliable measurement value, and the key derivation function.

[00106] Aspect 2. The method of aspect 1, in which the first entity is a first software image, and the Petition 870250083986, dated 09 / 18 / 2025, pp. 73 / 170 68 / 73 second entity is a second software image.

[00107] Aspect 3. The method of aspect 2, where the first reliable measurement value includes a hash of the first software image and the expected measurement value includes a hash of the second software image.

[00108] Aspect 4. The method of any of aspects 1 to 3, wherein the first entity is a first component, and the second entity is a second component.

[00109] Aspect 5. The method of aspect 4, wherein the first reliable measurement value includes a first item of identification information associated with the first component, and the expected measurement value includes a second item of identification information associated with the second component.

[00110] Aspect 6. The method of any of aspects 1 to 5, wherein the first secure storage location is selected during the first cryptographic key derivation to store the first trusted measurement value based on a parameter associated with the first entity.

[00111] Aspect 7. The method of any of aspects 1 to 6, wherein the second secure storage location is selected during the second cryptographic key derivation to store the second trusted measurement value based on a parameter associated with the second entity.

[00112] Aspect 8. The method of any of aspects 1 to 7, wherein the generation of the first instance of the cryptographic key and the second instance of the cryptographic key comprises using the key derivation function. Petition 870250083986, dated 09 / 18 / 2025, pp. 74 / 170 69 / 73 and use a platform key common to the first entity and the second entity.

[00113] Aspect 9. A key-establishing apparatus, wherein the apparatus comprises: at least one memory; and at least one processor coupled to at least one memory and configured to: during a first cryptographic key derivation: cause a first reliable measurement value associated with a first entity to be stored in a first secure storage location; cause an expected measurement value associated with a second entity to be stored in a second secure storage location; and generate a first instance of a cryptographic key using the first reliable measurement value, the expected measurement value, and a key derivation function; and during a second cryptographic key derivation: obtain, after generating the first instance of the cryptographic key during the first cryptographic key derivation, the expected measurement value as a second reliable measurement value associated with the second entity;Cause the second reliable measurement value to be stored in the second secure storage location; obtain the first reliable measurement value as a second expected measurement value; cause the second expected measurement value to be stored in the first secure storage location; and generate a second instance of the cryptographic key using the second expected measurement value, the second reliable measurement value, and the key derivation function.

[00114] Aspect 10. The method of aspect 9, in which the first entity is a first software image, and the Petition 870250083986, dated 09 / 18 / 2025, pp. 75 / 170 70 / 73 second entity is a second software image.

[00115] Aspect 11. The apparatus of aspect 10, wherein the first reliable measurement value includes a hash of the first software image and the expected measurement value includes a hash of the second software image.

[00116] Aspect 12. The apparatus of any of aspects 9 to 11, wherein the first entity is a first component, and the second entity is a second component.

[00117] Aspect 13. The method of aspect 12, wherein the first reliable measurement value includes a first item of identification information associated with the first component, and the expected measurement value includes a second item of identification information associated with the second component.

[00118] Aspect 14. The apparatus of any of aspects 9 to 13, in which at least one processor is configured to select the first secure storage location during the first cryptographic key derivation to store the first trusted measurement value based on a parameter associated with the first entity.

[00119] Aspect 15. The apparatus of any of aspects 9 to 14, in which at least one processor is configured to select the second secure storage location during the second cryptographic key derivation to store the second trusted measurement value based on a parameter associated with the second entity.

[00120] Aspect 16. The apparatus of any of aspects 9 to 15, in which at least one processor is configured to use the key derivation function and a platform key common to the first entity and the second. Petition 870250083986, dated 09 / 18 / 2025, pp. 76 / 170 71 / 73 entity to generate the first instance of the cryptographic key and the second instance of the cryptographic key.

[00121] Aspect 17. The apparatus of any of aspects 9 to 16, in which at least one memory comprises the first secure storage location and the second secure storage location.

[00122] Aspect 18. A non-transient, computer-readable medium having stored instructions that, when executed by at least one processor, cause at least one processor to: during a first cryptographic key derivation: cause a first reliable measurement value associated with a first entity to be stored in a first secure storage location; cause an expected measurement value associated with a second entity to be stored in a second secure storage location; and generate a first instance of a cryptographic key using the first reliable measurement value, the expected measurement value, and a key derivation function; and during a second cryptographic key derivation: obtain, after generating the first instance of the cryptographic key during the first cryptographic key derivation, the expected measurement value as a second reliable measurement value associated with the second entity;cause the second reliable measurement value to be stored in the second secure storage location; obtain the first reliable measurement value as a second expected measurement value; cause the second expected measurement value to be stored in the first secure storage location; and generate a second instance of the cryptographic key using the second measurement value. Petition 870250083986, dated 09 / 18 / 2025, pp. 77 / 170 72 / 73 expected, the second reliable measurement value and the key derivation function.

[00123] Aspect 19. The non-transient, computer-readable medium of aspect 18, wherein the first entity is a first software image, and the second entity is a second software image.

[00124] Aspect 20. The non-transient, computer-readable medium of aspect 19, wherein the first reliable measurement value includes a hash of the first software image and the expected measurement value includes a hash of the second software image.

[00125] Aspect 21. The non-transient, computer-readable medium of any of aspects 18 to 20, wherein the first entity is a first component, and the second entity is a second component.

[00126] Aspect 22. The non-transient, computer-readable medium of aspect 21, wherein the first reliable measurement value includes a first item of identification information associated with the first component, and the expected measurement value includes a second item of identification information associated with the second component.

[00127] Aspect 23. The non-transient, computer-readable means of any of aspects 18 to 22, wherein the instructions, when executed by at least one processor, cause at least one processor to select the first secure storage location during the first cryptographic key derivation to store the first trusted measurement value based on a parameter associated with the first entity. Petition 870250083986, dated 09 / 18 / 2025, pp. 78 / 170 73 / 73

[00128] Aspect 24. The non-transient, computer-readable means of any of aspects 18 to 23, wherein the instructions, when executed by at least one processor, cause at least one processor to select the second secure storage location during the second cryptographic key derivation to store the second trusted measurement value based on a parameter associated with the second entity.

[00129] Aspect 25. The non-transient, computer-readable means of any of aspects 18 to 24, wherein the instructions, when executed by at least one processor, cause at least one processor to use the key derivation function and a platform key common to the first entity and the second entity to generate the first instance of the cryptographic key and the second instance of the cryptographic key.

[00130] A key-setting device, the device comprising one or more means for performing operations in accordance with any of aspects 1 to 8. Petition 870250083986, dated 09 / 18 / 2025, pp. 79 / 170

Claims

1 / 7 CLAIMS 1. A method for establishing a key, characterized by comprising: during a first cryptographic key derivation: storing a first reliable measurement value associated with a first entity in a first secure storage location; storing an expected measurement value associated with a second entity in a second secure storage location; and generating a first instance of a cryptographic key using the first reliable measurement value, the expected measurement value, and a key derivation function; and during a second cryptographic key derivation: obtaining, after generating the first instance of the cryptographic key during the first cryptographic key derivation, the expected measurement value as a second reliable measurement value associated with the second entity; storing the second reliable measurement value in the second secure storage location;obtain the first reliable measurement value as a second expected measurement value; store the second expected measurement value in the first secure storage location; and generate a second instance of the cryptographic key using the second expected measurement value, the second reliable measurement value, and the key derivation function. Petition 870250083986, dated 09 / 18 / 2025, pp. 154 / 170 2 / 7; 2. Method according to claim 1, characterized in that the first entity is a first software image, and the second entity is a second software image.

3. Method, according to claim 2, characterized in that the first reliable measurement value includes a hash of the first software image, and the expected measurement value includes a hash of the second software image.

4. Method according to claim 1, characterized in that the first entity is a first component, and the second entity is a second component.

5. Method according to claim 4, characterized in that the first reliable measurement value includes a first item of identification information associated with the first component, and the expected measurement value includes a second item of identification information associated with the second component.

6. A method according to claim 1, characterized in that the first secure storage location is selected during the first cryptographic key derivation to store the first reliable measurement value based on a parameter associated with the first entity.

7. A method according to claim 1, characterized in that the second secure storage location is selected during the second cryptographic key derivation to store the second reliable measurement value based on a parameter associated with the second entity.

8. Method according to claim 1, Petition 870250083986, dated 09 / 18 / 2025, pp. 155 / 170 3 / 7 characterized in that the generation of the first instance of the cryptographic key and the second instance of the cryptographic key comprises using the key derivation function and using a platform key common to the first entity and the second entity.

9. Apparatus for key establishment characterized by comprising: at least one memory; and at least one processor coupled to at least one memory and configured to: during a first cryptographic key derivation: cause a first reliable measurement value associated with a first entity to be stored in a first secure storage location; cause an expected measurement value associated with a second entity to be stored in a second secure storage location; and generate a first instance of a cryptographic key using the first reliable measurement value, the expected measurement value and a key derivation function; and during a second cryptographic key derivation: obtain, after generating the first instance of the cryptographic key during the first cryptographic key derivation, the expected measurement value as a second reliable measurement value associated with the second entity;cause the second reliable measurement value to be stored in the second secure storage location; Petition 870250083986, dated 09 / 18 / 2025, pp. 156 / 170 4 / 7 obtain the first reliable measurement value as a second expected measurement value; cause the second expected measurement value to be stored in the first secure storage location; and generate a second instance of the cryptographic key using the second expected measurement value, the second reliable measurement value, and the key derivation function.

10. Device according to claim 9, characterized in that the first entity is a first software image, and the second entity is a second software image.

11. Device according to claim 10, characterized in that the first reliable measurement value includes a hash of the first software image, and the expected measurement value includes a hash of the second software image.

12. Apparatus, according to claim 9, characterized in that the first entity is a first component, and the second entity is a second component.

13. Apparatus, according to claim 12, characterized in that the first reliable measurement value includes a first item of identification information associated with the first component, and the expected measurement value includes a second item of identification information associated with the second component.

14. Device, according to claim 9, characterized in that at least one processor is configured to select the first secure storage location during the first cryptographic key derivation to store the first reliable measurement value based on a parameter associated with the first entity.

15. Device, according to claim 9, characterized in that at least one processor is configured to select the second secure storage location during the second cryptographic key derivation to store the second reliable measurement value based on a parameter associated with the second entity.

16. Device, according to claim 9, characterized in that at least one processor is configured to use the key derivation function and a platform key common to the first entity and the second entity to generate the first instance of the cryptographic key and the second instance of the cryptographic key.

17. Device according to claim 9, characterized in that at least one memory comprises the first secure storage location and the second secure storage location.

18. Non-transient, computer-readable medium characterized by having, stored therein, instructions that, when executed by at least one processor, cause the at least one processor to: during a first cryptographic key derivation: cause a first reliable measurement value associated with a first entity to be stored in a first secure storage location; cause an expected measurement value associated with a second entity to be stored in a second secure storage location; and generate a first instance of a key. Petition 870250083986, dated 09 / 18 / 2025, p.158 / 170 6 / 7 cryptographic using the first reliable measurement value, the expected measurement value, and a key derivation function; and during a second cryptographic key derivation: obtain, after generating the first instance of the cryptographic key during the first cryptographic key derivation, the expected measurement value as a second reliable measurement value associated with the second entity; cause the second reliable measurement value to be stored in the second secure storage location; obtain the first reliable measurement value as a second expected measurement value; cause the second expected measurement value to be stored in the first secure storage location; and generate a second instance of the cryptographic key using the second expected measurement value, the second reliable measurement value, and the key derivation function.

19. Non-transient, computer-readable medium according to claim 18, characterized in that the first entity is a first software image, and the second entity is a second software image.

20. A non-transient, computer-readable medium according to claim 19, characterized in that the first reliable measurement value includes a hash of the first software image, and the expected measurement value includes a hash of the second software image.

21. Non-transient, computer-readable medium according to claim 18, characterized in that the first entity is a first component, and the second entity is a second component.

22. A non-transient, computer-readable medium according to claim 21, characterized in that the first reliable measurement value includes a first item of identification information associated with the first component, and the expected measurement value includes a second item of identification information associated with the second component.

23. Non-transient, computer-readable medium according to claim 18, characterized in that the instructions, when executed by at least one processor, cause at least one processor to select the first secure storage location during the first cryptographic key derivation to store the first reliable measurement value based on a parameter associated with the first entity.

24. Non-transient, computer-readable medium according to claim 18, characterized in that the instructions, when executed by at least one processor, cause at least one processor to select the second secure storage location during the second cryptographic key derivation to store the second reliable measurement value based on a parameter associated with the second entity.

25. Non-transient, computer-readable medium according to claim 18, characterized in that the instructions, when executed by at least one processor, cause at least one processor to use the key derivation function and a platform key common to the first entity and the second entity to generate the first instance of the cryptographic key and the second instance of the cryptographic key. Petition 870250083986, dated 09 / 18 / 2025, pp. 160 / 170