Systems and procedures for cryptographically improved management and enforcement of blacklists
The system addresses the challenge of authenticating devices in non-networked environments by using a device with a public verification key and a global blacklist to verify unique identifiers from an accessory's authentication chip, effectively preventing forgery and cloning.
Patent Information
- Application Number
- DE102010063955
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2009-12-22
- Filing Date
- 2010-12-22
- Publication Date
- 2025-05-08
- Estimated Expiration
- 2030-12-22
AI Technical Summary
Existing technologies struggle to authenticate devices in non-networked environments, making it difficult to prevent forgery and cloning, as blacklists cannot be automatically managed or enforced in these settings.
A system that includes an accessory with an authentication chip containing data signed using a private verification key, and a device with a public verification key and a global blacklist, allowing the device to read and match unique identifiers from the accessory with the blacklist, and reject unauthenticated devices.
This solution enables effective authentication and prevention of forgery in non-networked devices by allowing for the use of blacklists, ensuring secure operation and maintaining the integrity of authenticated accessories.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[0001] The invention relates generally to accessory authentication in personal electronic devices, and more particularly to the automatic management and enforcement of blacklists of counterfeit, cloned, or otherwise unauthenticated devices.
[0002] The use of encryption to authenticate devices is well known. Traditionally, a message or "request" is sent from a system or device to an object to be authenticated, and a message-dependent response is sent back to the system by the object in response. The system then evaluates the response to determine whether the response was sufficient to authenticate the object.
[0003] Such a method can be used, for example, to verify components of a system or device, including those that are removable, replaceable, or retrofittable. For example, an ink cartridge for an inkjet printer can be authenticated to determine whether it is an authorized and compatible cartridge for that printer. If the cartridge is successfully authenticated, normal printing operations using the cartridge can begin. If an attempt is made to use a cartridge that is not successfully authenticated, no operation or only limited operation can be authorized as a result of the failed authentication process.
[0004] However, counterfeiters can attempt to circumvent authentication processes by brute-force cloning the authentication chip, resulting in the production of large numbers of devices with seemingly authentic, yet identical, authentication chips. Online or network applications often use blacklists to detect such clones, with a database containing the blacklisted devices available for verification. However, many devices for which authentication and / or counterfeiting or cloning is desired are not networked, so there is no way to automatically check against such a database.
[0005] US 2006 / 0 146 081 A1 discloses a printer that stores a blacklist of ribbon cartridge identifiers that have already been used by the printer. Before printing, the printer checks whether a ribbon cartridge identifier is on the blacklist and, if so, refuses to print.
[0006] US 2005 / 0 052 661 A1 describes the verification of an identifier of a printer ink cartridge, where the identifier is signed with a private key and stored on a chip in the ink cartridge. The printer verifies the digital signature of the identifier using the associated public key.
[0007] CN 101 378 315 A discloses a method for authenticating a message which is signed using a private key.
[0008] US 2006 / 0 161 976 A1 discloses a receiver that can be coupled to an access module with an identifier. Depending on a comparison between a list and the access module's identifier, the receiver can be rendered inoperable.
[0009] The object of the invention is therefore to provide a prevention for this and other types of counterfeiting and to enable the use of blacklists even for non-networked devices, in particular for low-cost devices produced in high quantities.
[0010] This object is achieved by a system according to claim 1, a semiconductor chip according to claim 12, a microcontroller according to claim 13, and a method according to claim 14. Refinements and developments of the invention are the subject of subclaims.
[0011] Embodiments of the present invention relate to systems and methods for managing and enforcing blacklists of counterfeit, cloned, or otherwise unauthenticated devices.In one embodiment, a system comprises: an accessory having an authentication chip containing data signed by a private verification key, the data containing an identifier unique to the accessory; and a device having: a public verification key forming a verification key pair with the private verification key, and an identifier list configured as a global blacklist of unique identifiers maintained at least partially external to the system, the device configured to read the data from the authentication chip, compare the unique identifier with the identifier list, and reject the accessory if the unique identifier is found in the identifier list.
[0012] In another embodiment, a method comprises: reading signed data from a first device by a second device; extracting a unique identifier from the data; comparing the unique identifier to a global identifier blacklist stored in the second device and maintained at least partially external to the semiconductor chip; rejecting the first device for use with the second device if the unique identifier is found in the unique identifier blacklist; and accepting the first device for use with the second device and adding the unique identifier to the unique identifier blacklist if the unique identifier is not found in the unique identifier blacklist.
[0013] In a further embodiment, a semiconductor chip configured to be incorporated in a first device includes: a memory having data signed by means of a private verification key, wherein the data includes a unique identifier relating to the semiconductor chip and a global blacklist of unique identifiers maintained at least partially external to the semiconductor chip, and wherein a private authentication key is stored in a secure portion of the memory; and a communication interface configured to communicate with a second device containing a public verification key using an asymmetric cryptography method, wherein the communication interface is configured to transmit the signed data to the second device.
[0014] In another embodiment, a microcontroller comprises: a circuit configured to store a private authentication key, a public authentication key, and data signed by a private verification key, the data including a unique identifier and a global blacklist; and a communication circuit configured to transmit the public authentication key and the data, receive a request encrypted with the public authentication key, and send a response associated with the encrypted request decrypted with the private authentication key.
[0015] Embodiments of the invention are explained in more detail below with reference to the accompanying drawings. The drawings serve to explain the basic principle, so only those features necessary for understanding the basic principle are shown. The drawings are not necessarily to scale. Like reference numerals denote like features with the same meaning. Fig. 1 shows a block diagram of a device according to an embodiment. Fig. 2 shows a block diagram of an object containing an authentication chip according to an embodiment. Fig. 3 shows a flowchart of an authentication process according to an embodiment. Fig. 4 shows a flowchart of a verification process according to an embodiment. Fig. 5 shows a block diagram of a signature generation process according to an embodiment. Fig. 6 shows a block diagram of a verification process according to the embodiment of Fig. 4. Fig. 7 shows a block diagram of a device according to an embodiment. Fig. 8 shows a block diagram of a memory of a device according to an embodiment. Fig. 9 shows a flowchart of a blacklist method according to an embodiment. Fig. 10 shows a flowchart of a blacklist and counter verification method according to an embodiment.
[0016] Embodiments of the invention relate to systems and methods for asymmetric cryptographic accessory authentication, such as those described in U.S. patent application Ser. No. 12 / 582,362, entitled "SYSTEMS AND METHODS FOR ASYMMETRIC CRYPTOGRAPHIC ACCESSORY AUTHENTICATION," filed October 19, 2009. As discussed in this application, more secure authentication of accessories, batteries, parts, and other objects can be provided at low cost, making it suitable for low-cost applications, using signed certificates and unique public-private key pairs.
[0017] Fig. 1, for example, illustrates one embodiment of an authentication system 100. The authentication system 100 includes a device 102, such as a mobile phone; a personal digital assistant (PDA); a camera; an MP3 player; a gaming system; an audio and / or video system or other entertainment device; a computer, a computer system, a network or computing device; a printer, scanner, or other digital imaging device; a medical device or diagnostic accessory; a motor vehicle or motor vehicle system; an industrial system; or other electronic device or computing device. The device 102 includes a public verification key 103, which will be explained in more detail below, and an object 104 with which the device 102 cooperates. In embodiments, the object 104 may include: a battery; an accessory, such asHeadphones, a headset, speakers, a docking station, a game controller, a charger, a microphone, and others; an ink cartridge for a printer; a component of a computer or computer system, a network device, a peripheral storage device, a USB storage device, or other storage device; a part, component, or accessory of a motor vehicle; an industrial component or part; or any other part or component for which authentication is needed or desired. In embodiments, object 104 is a replaceable component, such as an aftermarket accessory or a battery, but object 104 may also be a genuine part.The object 104 may be provided by the same manufacturer or distributor as the device 102 or by another party, such as an authorized manufacturer and / or distributor of replacement or aftermarket parts and accessories.
[0018] Object 104 is in Fig. 1 as functioning within or as part of device 102, such as in one embodiment where device 102 includes a printer and object 104 includes a printer cartridge. In other embodiments, object 104 is external to the device, such as where device 102 is a mobile phone and object 104 is a wireless earpiece. These embodiments are merely examples, and many other device-object combinations and pairings may be used in other embodiments.
[0019] Referring to Fig. 2, the object 104, in one embodiment, includes an authentication chip 106. The authentication chip 106, in one embodiment, includes a semiconductor chip and a memory 108. The memory 108, in one embodiment, is a non-volatile memory configured to store data objects, such as a private authentication key 110 and a public authentication key 111, stored in a secure portion of the memory 108. The public authentication key 110 and the private authentication key 111 form an authentication key pair. The memory 108 may also store one or more of the following data: a unique identifier (ID) and / or a serial number of the object 104, application-specific data, or other information contained in Fig. 2 are collectively represented as data 112. Additional data objects that may be stored in memory 108 include, for example, a unique portion of an authentication certificate, which will be explained in more detail below.
[0020] In one embodiment, the functionality and features of authentication chip 106 are implemented as one or more system-on-chip components of object 104 to achieve cost or space savings. Object 104 may, for example, include a BLUETOOTH headset, which is often very small and therefore unable to accommodate an additional chip 106. Instead, the required features and functionality are integrated into an existing chip within the headset, thereby saving space and potentially also cost.In such an embodiment, a manufacturer of the headset or other device containing the object 104 may, for example, be provided with a VHDL netlist for integration into an existing controller or processor of the headset or other device, requiring little or no change in features, functionality, and security, rather than implementing a discrete authentication chip 106.
[0021] Referring to Fig. 3, a method may be implemented between device 102 and object 104 to determine whether object 104 is authenticated to operate with or through device 102. At 301, device 102 reads a public authentication key 111 from object 104. Device 102 now has two public keys: public verification key 103 and public authentication key 106.
[0022] However, before the device 102 uses the public authentication key 111, it determines whether the public authentication key 111 is verified or genuine. In a conventional system that uses global or constant key pairs with public and private keys for devices, verification can be performed by simply comparing the global key (the public authentication key 111) received from the object 104 with the same global key, or a hash of that key, stored in the device 102. However, the use of global keys does not provide the highest level of security, as global keys are vulnerable to hacking or other forms of corruption.In other embodiments, therefore, unique public and private keys are used for each device, while in other embodiments, the public keys are reused. For example, a first million objects 104 can each be created with a unique public key, with the public keys being repeated thereafter. In these embodiments, a unique identifier is additionally used. Various embodiments will be explained in more detail below.
[0023] At 302, and after verifying the public authentication key 111, the device 102 uses the public authentication key 111 to encrypt a challenge. In one embodiment, the challenge includes a random number. In another embodiment, the challenge includes additional data. In some embodiments, the encryption is performed using an asymmetric encryption method, such as an elliptic curve cryptography algorithm. In other embodiments, an RSA cryptography algorithm or another cryptography algorithm is used.
[0024] At 304, the encrypted request is transmitted from device 102 to object 104. In embodiments, the request is transmitted between device 102 and object 104 wirelessly, such as using radio frequencies, or wired, such as via a power line or other wired connection. At 306, object 104 decrypts the received encrypted request using private authentication key 110. At 308, object 104 sends the decrypted request as a response to device 102, and device 102 determines whether the response is suitable to authenticate object 104.
[0025] After method 300, device 102 may retain both keys 103 and 111, or device 102 may delete the public key 111 read from object 104. Retaining both keys may save time and computational effort in the future, while deleting one key may free up memory space.
[0026] In one embodiment, and with reference to Fig. 4, a certificate procedure 400 is performed together with the procedure 300 to enable the use of unique key pairs with public and private keys for devices and objects. At 402, a digest is generated by a certificate authority. The certificate authority can be a manufacturer, processor, or other entity related to the chip 106 and / or the object 104. A private verification key 510 (in Fig. 5) is held by the certificate authority and forms a verification key pair with the public key 103 stored in the device 102.
[0027] The generation of the extract by the certificate authority is in Fig. 5. First, a message 507 is generated by concatenating a unique device identifier 502 related to the object 104 and / or the chip 106, such as a serial number or identification number, serial code or identification code; a public authentication key 111; and data 112. A hash algorithm is applied to the message 507 to generate a digest 508. In one embodiment, an SHA-1 cryptographic hash algorithm is used, while other embodiments use other hash algorithms, such as SHA-256.
[0028] The digest 508 is signed using a certificate holder's private verification key 510 to generate a signature 512. In one embodiment, an elliptic curve cryptography algorithm is used to sign the digest 508. The advantages of an elliptic curve cryptography algorithm are shorter keys and fewer computations due to the brevity of the keys, which can be advantageous for small, low-cost, and / or embedded objects that have low processing capacity. In other embodiments, an RSA cryptography algorithm or another cryptography algorithm is used.
[0029] Referring to the Fig. 4-6, the signature 512 is stored at 404 in a memory 108 of the object 104. In one embodiment, this is performed by the certificate authority. In another embodiment, this is performed by a manufacturer or another authority related to the object 104. The certificate authority and the manufacturer may be the same authority or may be different authorities, but generally, access to and handling of the signature is carefully controlled to increase security.
[0030] The first time an attempt is made to use object 104 with a device 102, device 102 must authenticate object 104 and verify that any data, information, content, media, or other quantities originating from object 104 are legitimate, or that object 104 itself is legitimate. Accordingly, device 102 reads signature 512 and other data 520 from object 104 at 406. As part of this reading, device 102 obtains public authentication key 111 from object 104, as previously described. However, device 102 cannot know whether public key 111 is corrupt or compromised, so it must verify the key.
[0031] This can be done using signature 512. Device 102 first reconstructs message 507 from data 520 and applies the same hash algorithm used to generate digest 508 to message 507, thereby obtaining a digest (508') at 408. At 410, device 102 then extracts the original digest 508 from the signature read from object 104 using public verification key 103, which—barring forgery or corruption—should match the public verification key 510 used to generate the original signature 512. If the extraction is successful, device 102 compares digest (508') with digest 508 at 412.If the digest 508 and the digest' (508') match, the device 102 has verified that the data and information received from the object 104 is not corrupt and can use the public authentication key 111 received from the object 104 to authenticate the object 104 according to the method 300.
[0032] As previously explained, one way to circumvent authentication methods, such as authentication system 100, is to clone an authentic authentication chip 106 and use the clones in counterfeit items. One challenge for counterfeiters using brute-force cloning of authentication chips 106 is the difficulty of generating new key pairs and signature verifications using cryptographic processes for each item 104. This is due, in part, to the amount of computing power required to generate signed certificates, which counterfeiters are unwilling to expend on high-volume, relatively low-cost items, such as printer cartridges and other devices and accessories.While the signature can also be obtained through theft, such as spying, counterfeiters cannot reliably rely on obtaining signed certificates this way. Counterfeit objects containing cloned authentication chips may appear authentic when examined or used alone, but they all possess identical certificates, which are obtained as part of the cloning process by simple copying.
[0033] Embodiments of the invention relate to detecting, preventing the use of, and blacklisting these and other counterfeit devices.
[0034] Fig. 7 illustrates another embodiment of an authentication system 900 that is similar to system 100. In system 900, device 102 includes a memory 902. Referring to Fig. 8, the memory 902 contains an object identification (ID) list 904 and a unidirectional counter 906.
[0035] When use of object 104 with device 102 is attempted for the first time, in one embodiment, device 102 reads data from object 104 (see, for example, Fig. 6 and Fig. 8 and data 520), where the data 520 includes a unique identifier 502 related to the object 104. In other embodiments, such as those in which public keys are repeated as previously explained, the data 520 may include other unique identifiers. Whether a unique identifier 502 or another unique identifier is used is irrelevant, as both are part of the data within the signed certificate explained above and are therefore protected from tampering. While either the unique identifier 502 of the chip 106 or another unique identifier may be used in various embodiments depending on the particular application, the term unique identifier is generally used below to refer to any such identifier.
[0036] If a counterfeiter clones many objects, each object has the same unique identifier. In one embodiment, device 102 maintains each unique identifier in an object identifier list 904 stored in memory 902. When attempting to use a new object 104 with device 102, device 102 first checks whether the unique identifier of object 104 is already stored in object identifier list 904. If not, object 104 can be authenticated. If the unique identifier is found in list 904, object 104 is not authenticated.
[0037] Referring to Fig. 9, a non-limiting example of a method 1000 is explained, which relates to a printer as device 102 and a printer cartridge as object 104. At 1002, and as previously described with reference to the Fig. 3-8, the printer reads data from the cartridge. In one embodiment, the data is part of a signed certificate and includes a unique cartridge identifier. At 1004, the printer compares the unique cartridge identifier obtained from the data with an identifier list stored locally in a memory of the printer and determines at 1006 whether the unique cartridge identifier is included in the identifier list. If the unique cartridge identifier is in the list, the cartridge is rejected by the printer at 1008. Rejection can take various forms, such as rendering the printer inoperable until a new authenticated cartridge is inserted.
[0038] If the unique cartridge identifier is not found in the identifier list, the unique cartridge identifier is added to the identifier list at 1010, creating a self-learning local blacklist, and the cartridge is authenticated for use at 1012. In one embodiment, the printer maintains a plurality or all of the most recent unique identifiers in the list so that each subsequent cartridge can be compared against a larger list. The number of unique identifiers maintained in the printer is limited only by memory capacity. In one embodiment, the printer maintains all unique identifiers of cartridges whose use has been attempted. In other embodiments, printer memory may be limited such that the printer maintains only a number of the most recent unique identifiers, for example, the last 50 unique identifiers.
[0039] Referring again to the rejection of the cartridge in step 1008, the rejected unique identifier may also be communicated back to a manufacturer or distributor to request that this identifier be added to a global blacklist. Additionally or alternatively, a manufacturer may use market information or other information to build or supplement a global blacklist of rejected identifiers. In one embodiment, and referring to Fig. 7, the most current version of the global blacklist may be included in the data on the authentication chip 108, so that an encrypted version of the global blacklist is made available to the printer each time a new authentic cartridge is attempted to be used with the printer. Providing the global blacklist as part of the encrypted data provides additional security by preventing forgery of the blacklist. One disadvantage, however, is time; since the global blacklist is stored in the authentication chip earlier in the manufacturing process, there is a time gap between the time the global list is stored in the chip 106 and the time the item 104 containing the chip 106 is ultimately sold, during which time gap additional forged unique identifiers may be discovered.In other embodiments, the global blacklist may alternatively or additionally be stored directly in the memory 902 of a newly manufactured printer, so that every printer rejects the use of a cartridge with an identifier stored in the printer. The printer manufacturer could also, in one embodiment, sign the certificate. Providing the global blacklist also has the advantage that the printer can identify a growing number of counterfeit cartridges the first time an attempt is made to use them with the printer, rather than accepting a counterfeit cartridge because the cartridge's unique identifier is not stored in the local blacklist (object identifier list 904).These other embodiments may reduce the time between the deployment of the global blacklist and the sale of the product, thereby providing the most up-to-date information available.
[0040] Embodiments also include a unidirectional counter 906 (see Fig. 8) to prevent unjustified rejection of authentic objects. Consider again the example with the printer and the printer cartridge. For this example, assume that a user needs to remove and reinstall an authentic printer cartridge for some reason, such as to remove dust or dirt from the cartridge or a printing mechanism. In this situation, according to method 1000, the printer would reject the cartridge upon reinstallation because the unique cartridge identifier would be found in the identifier list, and because the printer would not know that the (authentic) cartridge was simply removed and reinstalled. However, the use of a unidirectional counter 906 can reduce or prevent such false rejections.
[0041] In the Fig.10, such a unidirectional counter 906 is used. If the unique cartridge identifier is not found in the identifier list in step 1006, the printer checks the unidirectional counter at 1007. The unidirectional counter can be implemented in various ways, as long as it is ensured that the counter only counts in one direction (i.e., up or down; but not in both directions). In the example with the printer and the cartridge, the unidirectional counter can be a fill level indicator or part of a fill level indicator that counts downwards. The fill level is stored in the unidirectional counter 906 of the printer's memory 902, and if the cartridge fill level is higher than the value stored in the unidirectional counter 906 at 1007, the cartridge is rejected at 1008.If the fill level at 1007 is the same as or less than the value stored in the unidirectional counter 906, the cartridge is considered authentic at 1012. In other embodiments, such as those where the device 102 is an electronic device and the object 104 is a battery, the unidirectional counter 906 may be related to a charge level or a lifetime recharge cycle of the battery. In an embodiment where the device 102 is a medical device and the object 104 is a consumable accessory with a limited number of uses, the unidirectional counter 906 may count a number of uses and, for example, count up. In these and other embodiments, the count of the unidirectional counter, and in particular whether the count at 1007 is higher or lower than a stored value, is an indication of counterfeiting or authenticity, respectively.In one embodiment, the unidirectional counter is contained within object 104, with only a reading or indicator of the counter being stored in memory 906. In other embodiments, unidirectional counter 906 is contained within device 102.
[0042] In embodiments of method 1200 where a blacklist is provided to device 102 by object 104 as part of the signed certificate, and where an attempt is later made to use an object 104 with a blacklisted identifier with device 102, device 102 will reject the object regardless of the unidirectional counter check. In other embodiments, unidirectional counter 906 also prevents the use of forged "piggybacked" objects, such as when a forged object is coupled with an authentic object to use the authentic object to obtain authentication for the device.If the unidirectional counter 906 is a unidirectional incrementing or decrementing counter, the object is considered consumed when a predetermined value is reached, regardless of the presence of the piggyback device.
[0043] Embodiments of the invention enable secure authentication of accessories, batteries, parts, and other objects at low cost and are therefore suitable for low-cost applications. Additionally, embodiments provide recovery options in the event of hacking or key misuse through blacklisting. Therefore, if public key hacking is discovered, the key can be revoked or blacklisted and deactivated globally, rather than blocking each individual key in the conventional manner. This provides increased security and more efficient key management. Logistical improvements are also achieved by eliminating the need to preconfigure the device with the correct public key for a specific object, as the key is extracted from the certificate stored in the object upon first use.This improves overall security while ensuring cost-effective authentication. Furthermore, the use of local and global blacklists and the use of directional counters provide additional security against cloned and otherwise counterfeit accessories.
[0044] Various embodiments of systems, devices, and methods have been described above. These embodiments are for illustrative purposes only and do not limit the scope of the invention. It should be noted that various features of the embodiments described above may also be combined with features of other embodiments, even if not explicitly explained. While various materials, dimensions, shapes, and locations have been described, it should be noted that this has been done merely by way of example and does not limit the scope of the invention.
[0045] Furthermore, it should be noted that the invention may also contain fewer features than those shown in the embodiments.
Claims
[1] System that has: an accessory (104) having an authentication chip (106) containing data signed by a private verification key, the data including a unique identifier related to the accessory; and a device (102) comprising: a public verification key forming a verification key pair with the private verification key, and an identifier list configured as a global blacklist of unique identifiers maintained at least partially outside the system, wherein the device (102) is configured to read the data from the authentication chip (106), compare the unique identifier with the identifier list, and reject the accessory if the unique identifier is found in the identifier list (904). [2] The system of claim 1, wherein the device 102 is configured to add the unique identifier to the identifier list (904) and to authenticate the accessory (104) if the unique identifier is not found in the identifier list (904). [3] The system of claim 1 or 2, wherein the authentication chip (106) is a semiconductor chip. [4] System according to one of the preceding claims, wherein the device (102) has a memory (902) and wherein the identification list (904) is stored in the memory (902). [5] The system of claim 4, wherein the device (102) further comprises a unidirectional counter whose count is stored in the memory (902), and wherein the device (102) is configured to compare the count with a parameter of the accessory when the unique identifier is found in the identifier list (904). [6] System according to claim 5, wherein the device (102) is configured to reject the accessory (104) only if the unique identifier is found in the identifier list and if the comparison of the counter reading with the parameter of the accessory (104) indicates non-authenticity. [7] A system according to any preceding claim, wherein the data includes a global blacklist of unique identifiers, and wherein the identifier list is updated by means of the global blacklist. [8] A system according to any preceding claim, wherein the identifier list includes a global blacklist of unique identifiers added during manufacture of the devices (102). [9] A system according to any one of the preceding claims, wherein the authentication chip (106) further comprises: a private authentication key and a public authentication key, wherein the device (102) is configured to read the public authentication key from the authentication chip (106), verify the data and the public authentication key using the public verification key, and authenticate the accessory (104) for use with the device (102) using the public authentication key when the public authentication key is verified. [10] The system of any preceding claim, wherein the device (102) and the accessory (104) form a pair selected from the group consisting of: a mobile phone and a battery; a mobile phone and a mobile phone accessory; a printer and a printer cartridge; a gaming unit and a gaming unit controller; an electronic device and a battery; an electronic device and an accessory; a computing device and an accessory; a computing device and a battery; a computing device and a peripheral device; a network and a network device; a USB port device connected to a USB device via a USB port; a media device and a battery; a media device and an accessory; a medical device and a battery; a medical device and an accessory; a personal digital assistant and a battery; a personal digital assistant and an accessory; an industrial system and an industrial system component;a motor vehicle and a motor vehicle accessory; a motor vehicle system and a motor vehicle part; [11] A system according to any preceding claim, wherein the identifier list holds a number of unique identifiers each relating to one of a plurality of accessories attempted to be used with the device (102). [12] A semiconductor chip adapted to be embedded in a first device (102) comprising: a memory (108) comprising: data signed by a private verification key, the data including a unique identifier related to the semiconductor chip (108) and a global blacklist of unique identifiers maintained at least partially external to the semiconductor chip, and a private authentication key stored in a secure portion of the memory; and a communication interface configured to communicate with a second device having a public verification key using an asymmetric cryptography method, wherein the communication interface is configured to communicate the signed data to the second device. [13] Microcontroller that has: a circuit configured to store a private authentication key, a public authentication key, and data signed by a private verification key, the data including a unique identifier and a global blacklist; and a communication circuit configured to communicate the public authentication key and the data and to receive a request encrypted with the public authentication key, and to communicate a message related to the encrypted request decrypted using the private authentication key. [14] Method comprising: Reading signed data from a first device (104) by means of a second device (102); Extracting a unique identifier from the data; Comparing the unique identifier with a global blacklist of unique identifiers stored in the second device and maintained at least partially external to the second device; Rejecting the first device (104) for use with the second device (102) if the unique identifier is found in the blacklist of unique identifiers; and Accepting the first device (104) for use with the second device; and adding the unique identifier to the unique identifier blacklist if the unique identifier is not found in the unique identifier blacklist. [15] The method of claim 14, further comprising: Providing the first device (104) with an authentication chip (106), wherein the signed data is stored in a memory (108) of the authentication chip. [16] The method of claim 14 or 15, further comprising: using a public verification key stored in the second device (102) to verify the signed data, wherein the signed data is signed by a private verification key that forms a key pair with the public verification key. [17] A method according to any one of claims 14 to 16, further comprising: Comparing a counter reading of a unidirectional counter in the second device (102) with a parameter in the first device (104) and, if the comparison results in a predetermined result, accepting the first device (104) for use with the second device (102); if the comparison does not lead to a predetermined result, rejecting the first device (104) for use with the second device (102). [18] The method of claim 17, further comprising: Storing the counter reading of the unidirectional counter in a memory of the second device (102). [19] A method according to any one of claims 14 to 18, further comprising: Extracting a global blacklist from the signed data; and Updating the blacklist with unique identifiers using the global blacklist. [20] The method of claim 19, further comprising: Storing the blacklist with unique identifiers in a memory of the second device (102). [21] A method according to any one of claims 14 to 20, further comprising: Storing a large number of unique identifiers associated with a large number of initial devices in a unique identifier blacklist. [22] The method of claim 14, further comprising: Storing a global blacklist in the second device (102). [23] The method of claim 22, further comprising: Update the blacklist of unique identifiers to include the global blacklist. [24] The method of claim 22, wherein storing a global blacklist further comprises: storing the global blacklist in a memory of the second device (102) during manufacture of the second device (102).
Citation Information
Patent Citations
Method, system, equipment and server for packet authentication
CN101378315A
Cartridge with identifiers
US20050052661A1
Validation of consumables
US20060146081A1
Embedded blacklisting for digital broadcast system security
US20060161976A1
Systems and methods for asymmetric cryptographic accessory authentication
US20110093714A1