Device manufacturing stages verifications

A distributed stateful hash-based signature scheme with a single public key for multiple one-time-use private keys simplifies and secures electronic device verification and access management in complex supply chains, addressing inflexibility and storage issues in conventional methods.

WO2026010625A1PCT designated stage Publication Date: 2026-01-08HEWLETT PACKARD DEVELOPMENT COMPANY LP
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/US2024/036760
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-07-03
Publication Date
2026-01-08

AI Technical Summary

Technical Problem

Conventional solutions for verifying manufacturing stages of electronic devices in a supply chain require managing multiple public keys, leading to inflexibility and impractical storage requirements due to the addition or removal of entities in the supply chain, and lack a natural ordering of distinct public keys.

Method used

Implementing a distributed stateful hash-based signature scheme where a single public key is associated with multiple one-time-use private keys, allowing verification of signatures using a single public key and implying an ordering from the state contained within each signature.

Benefits of technology

This approach simplifies verification processes, reduces storage requirements, and enables flexibility in managing supply chain operations by allowing multiple entities to securely lock and unlock electronic devices without the need for multiple public keys.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure US2024036760_08012026_PF_FP_ABST
    Figure US2024036760_08012026_PF_FP_ABST
Patent Text Reader

Abstract

Examples relate to storing a public key, the public key being associated with a plurality of one-time-use private keys used by distinct devices to generate first distinct stateful hash-based signatures; and using the public key and signed messages to verify the first distinct stateful hash-based signatures of the distinct devices for a verification of a series of distributed supply chain operations performed on an electronic device and / or using another one-time-use private key to generate a second distinct stateful hash-based signature for a response message related to a challenge message from the electronic device for a verification of an authentication to lock or unlock the electronic device.
Need to check novelty before this filing date? Find Prior Art

Description

86311225 DEVICE MANUFACTURING STAGES VERIFICATIONS BACKGROUND

[0001] Electronic devices are often manufactured in several stages in what may commonly referred to as a manufacturing supply chain. Such a manufacturing supply chain for an electronic device may encompass a complex network of suppliers, manufacturers, logistics providers, and distributors involved in the manufacturing, testing, performing audits and delivery of the electronic device. In this context authentication for respective accesses to the electronic device and / or verifications of respective manufacturing steps or processes should be made. BRIEF DESCRIPTION OF THE DRAWINGS

[0002] Figure 1 is a diagram of an example apparatus and an example electronic device according to the present disclosure.

[0003] Figure 2 illustrates an example method for a verification of a series of distributed supply chain operations performed on an electronic device and / or for a verification of an authentication to unlock the electronic device.

[0004] Figure 3 is a diagram of a system comprising an example key management service, a plurality of distinct entities / parties involved in a workflow for an electronic device, as well as an example signing and / or locking / unlocking device according to an embodiment.

[0005] Figure 4 is a diagram of an example system according to the present disclosure. DETAILED DESCRIPTION

[0006] The present relates to supply chain manufacturing verification and / or on demand lock (ODL) and unlocking for an electronic device. The electronic device may be a computing device such as a personal computer (for example a laptop, a desktop), a mobile device (for example a smartphone, a tablet), a wearable device (such as a smart watch, a fitness tracker), a gaming console, an IoT device (for example a smart home device, a printer), a virtual and augmented reality device (for example a VR headset, AR glasses) or the like.

[0007] When an electronic device progresses or proceeds through a series of ordered steps of a workflow and / or is accessed by a series of entities or users, for example, in the context of a manufacturing supply chain, such a process typically involves multiple parties (entities or users) to perform or complete an action on or in connection with the electronic device before the electronic device is passed on to the next entity. For example, such a supply chain manufacturing may involve multiple entities within factory sites, audits, value-adding entities or the like before the electronic device reaches a customer.

[0008] Further, an ODL for an electronic device may be understood as a security feature for allowing a locking and unlocking of the electronic device, or a specific functionality of the electronic device. ODL may therefore prevent unauthorized access and may allow authorized access to the electronic device, specific portions of the electronic device, or specific functionalities of the electronic device. ODL may therefore contribute to enhanced security during the device manufacturing stages which may be performed by different and distributed entities. It may also contribute to enhanced security after the manufacturing chain, for example, for secure locking and unlocking of the electronic device.

[0009] A device (for associated with a manufacturing site during the manufacturing processes or related to a customer) should therefore be able to unlock the electronic device (to have access and perform an action on the electronic device) and / or to verify that a specific or every party / entity in the process has completed the required manufacturing or processing step and that no step has been missed. The verification apparatus may also operate to verify that the respective steps in the process occurred in a given or prescribed order.

[0010] In conventional solutions, this may be achieved by each party or entity in the supply chain manufacturing process having their own asymmetric signature key pair. In such a conventional solution, each party separately generates their private-public key pair, stores the private key, and distributes the public key to the verifying apparatus. The verifying apparatus would then have to securely store all the public keys corresponding to each of the parties. As the electronic device progresses through the multiple processes of corresponding multiple parties, each entity would generate a signature of a message providing some evidence of the manufacturing process using their private key. The message and signature may then be loaded or stored onto the electronic device or otherwise transferred to the verification apparatus. When the verifying apparatus receives the electronic device or accesses the message and signature otherwise transferred (for example, via a wireless communication infrastructure), the verifying apparatus can then use the locally stored public keys (sent previously, for example, or already stored securely on the electronic device) to verify each of the signatures and decide whether or not a process of the supply chain process has been successfully completed. The stored public keys may also be associated with an ordering of processing steps, which the verifying apparatus may leverage to verify whether events or processes have occurred in a given order. This conventional solution,where each party / entity a separate key pair has the following technical limitations:

[0011] The verifying apparatus must store and manage multiple public keys. In addition to increased storage requirements, as the supply chain processes get more complex and more entities / parties participate, or the supply chain process is changed or updated (which can involve some entities leaving and new entities being added to the supply chain manufacturing), this could become unmanageable and impractical for the verifying apparatus.

[0012] The skilled person also understands that distinct public keys have no natural ordering. That is, if the verifying apparatus operates to ensure that steps were completed in a particular order, alongside the public key information, additional information would have to be provided, managed and stored indicating the order in which the public keys should be used. As such, rather than storing just the set of public keys {^^^, ^^^, ^^^, … }, the verifyingapparatus also needs to store information{1,2,3, …}, for example as an appropriate data structure {^^^^, 1^, ^ ^^^, 2^, ^ ^^^, 3^, ... } and needs to update the expectedordering of the public keys if any changes occur in the process (such as if the ordering of expected signature changes, or if new entities participate in the manufacturing supply chain, requiring new steps in the process).

[0013] The conventional solution is therefore inflexible: If new steps and parties / entities are added to the processes of the manufacturing supply chain, this requires the new party / entity to generate at least one new key pair, for the at least one new public key to be distributed to the verifying apparatus, and for the verifying apparatus to store, manage and control the new public key in the data structure, potentially also rearranging an order indicated in that data structure.

[0014] To overcome these technical limitations in the context of verifications of supply chain manufacturing processes and / or on demand locking / unlocking for multiple distinct and distributed entities, the present disclosure applies distributed stateful hash-based signatures in which a single public key is associated with multiple one-time-use private keys. The multiple one-time-use private keys are respectively used by multiple distinct and distributed signing devices (signers). Here, each of the distributed signing devices may have been allocated with their own set of confidential one- time-use private keys. In particular, according to the distributed stateful hash-based signature scheme of the present disclosure, a private key and a state may be used to derive a one-time-use private key, which can each be used once to generate a single signature. All signatures produced using the one-time-use private keys are then verifiable using a single public key. As such, this distributed scheme allows to have multiple, distinct signers each with their own private keys, such that all signatures from each of the signers can be verified using a single public key, and each signature can be attributed to a distinct party / entity.

[0015] In particular, rather than each party (each entity) in the process having their own cryptographic key pair to generate a digital and electronic signature for a message, for example for providing evidence for (progress or completion of) a manufacturing or processing step, which would require the verification apparatus to store and manage multiple public keys and also to keep track of an expected ordering for use of these keys, according to the present disclosure, a stateful hash-based signature scheme is applied. As will be further elaborated below, this enables the verification apparatus to store (only) a single public key (corresponding to a plurality of one-time-use private keys), and the plurality of one-time-use private keys to be distributed across the different parties in the manufacturingor processing chain. As such, an ordering (manufacturing and / or access ordering) may be implied from a state contained within each signature. The skilled person understands that this simplifies the verification process and enables flexibility within the supply chain process and / or improvements as to distributed locking and unlocking of the electronic device.

[0016] Figure 1 is a diagram of an example apparatus 110 and an example electronic device 120 according to the present disclosure. The apparatus 110 may include multiple components, as illustrated in Figure 1, and may include a memory 112, a controller 114, and a communication device (communicator) 116. The electronic device 120 may include a memory 122, a controller 124, and a communication device (communicator) 126. In a non-limiting example, the apparatus 110 may be a user product such as a computer, a laptop, a mobile device or the like or may be related to a cloud device or cloud infrastructure. The communication, as indicated in Figure 1 via a communication network 130, may be an IoT or other 3GPP-based communication (such as LTE, 5G, 6G), a WiFi- based communication (such as based on the IEEE 802.11ax standard) between the apparatus 110 and the electronic device 120, or may be based on Bluetooth, LoRa radio communication, near field communication, low power wider area network (LPWAN) or the like.

[0017] The apparatus 110 in Figure 1 may be an apparatus for verifying processes in the supply chain manufacturing operation on the electronic device 120 and / or for locking / unlocking the electronic device 120. The memory 112 of the apparatus 110 may be a volatile memory such as a random access memory (RAM) and / or a non-volatile memory such as a read-only memory (ROM), a flash memory or the like. The memory 112 stores a public key, PK. Here, the (single) public key PK is associated, in a distributed stateful hash-based signature scheme, with a plurality of one-time-use privatekeys used at different devices (entities). In other words, the public key is to be used for a plurality of one-time-use private keys associated with distinct different devices (entities). For example, the plurality of one-time- use private keys may comprise a first set of one-time-use private keys associated with a first device and a second set of one-time-use private keys associated with a second device, the first and second device being distinct different devices (different hardware entities). That is, the first and second devices may be devices at different positions or sites (for example, in a factory) and be related to different manufacturing operations in a supply chain manufacturing process for the electronic device.

[0018] The controller 114 of the apparatus 110 may be a hardware and / or software component for operating the apparatus, such as a CPU controller, a GPU controller, a microprocessor, in conjunction with the memory 112. Here, in the context of the distributed stateful hash-based signature scheme, the controller 114 may use the stored public key, PK, as well as messages related to respective processes in a supply chain operation, to verify (first) distinct stateful hash-based signatures of the distinct devices (entities) for a verification of a series of distributed supply chain operations performed on the electronic device. Here, the messages may contain evidence of processes performed during the distributed supply chain operations and the messages may be signed at respective distinct devices (entities) using a one-time-use private key sk. The messages and signatures (distinct stateful hash-based signatures) may be acquired from the memory of the electronic device 120 itself or may otherwise be acquired from the respective distinct entities, for example via a telecommunication infrastructure or from a key management cloud service. The messages are thus related to corresponding processes in the supply chain operation, and the controller 114 may be configured (e.g. suitably programmed) to verify the distinct stateful hash-basedsignatures for a of a series of distributed supply chain operations performed on the electronic device.

[0019] In addition or alternatively, the controller 114 of the apparatus 110 may use another one-time-use private key sk to generate a (second) distinct stateful hash-based signature for a response message related to a challenge message from the electronic device. Here, the one-time-use private key sk may be one of a subset of private keys of a plurality of one- time-use private keys which is allocated to the apparatus 110 and may also be stored in the memory 112. In particular, the controller 114 may generate a response message and generated a signature using sk in response to a challenge message from the electronic device 120 to lock or unlock the electronic device. The challenge and response messages may be communicated between the apparatus 110 and the electronic device, for example between the respective communication devices 116 and 126. Upon receiving the response message, the controller 124 of the electronic device 120 may use the associate public key PK, stored at the electronic device, to verify authentication to lock or unlock the electronic device.

[0020] While the verification of a series of distributed supply chain operations and the verification of an authentication to lock or unlock the electronic device using the first and second distinct stateful hash-based signatures may be performed in connection with the same associated public key PK, in an alternative embodiment the respective verifications may also be performed using two different associated public keys, i.e. PK1 for the verification of the series of distributed supply chain operations and PK2 for the verification of authentication to lock or unlock the electronic device.

[0021] The skilled person understands that a stateful hash- based signature scheme, such as LMS (RFC 8554: Leighton-Micali Based Signatures, https: / / datatracker.ietf.org / doc / html / rfc8554) and XMSS (RFC 8391: XMSS: eXtended Merkle Signature Scheme, https: / / datatracker.ietf.org / doc / html / rfc8391), may be considered as a type of digital signature mechanism or cryptographic signature algorithm that uses (properties of) cryptographic hash functions and maintains internal state information (updated with each new signature generated) to generate signatures. The state information may be used to ensure security and uniqueness of each signature. For the present disclosure, the stateful hash-based signature scheme may employ a single public key and, correspondingly, multiple private keys (of respective states) for respective signature generations for distributed verification of a manufacturing process on an electronic device and / or distributed locking / unlocking process on the electronic device.

[0022] Here, a hash function may be considered as a cryptographic hash function that generates a fixed bit-sized output from input data. The output is computationally (by a conventional computer or a quantum computer) infeasible to invert and is preferably collision-resistant (i.e. difficult to find two different input bit strings that generate the same output).

[0023] Moreover, each of the private keys may be a one-time- use private key (required and enforced to be used only once for generating a signature) and may be associated with state information that may keep track of previously used values, as may be stored and updated by the signing apparatus. If a signing device (for example, one of the distinct devices) at a distinct site has a set of private keys, the signing device should maintain a state to track which of the private key(s) has (have) been used. The collection of one-time-use private keys can be distributed amongst the entities in the process.

[0024] The single public associated with the plurality of one-time-use private keys may be used by a verification apparatus (for example, apparatus 110) to validate each of the signatures generated using respective one-time-use private keys. As described above, the verification may be a verification that a certain process in a distributed supply chain manufacturing of the electronic device has been performed and / or for a distributed and ordered authorization to lock or unlock the electronic device. The verification may thus be performed by a third party. For example, when a third party company receives the electronic device, the company may verify all the signatures using the public key on the electronic device, to verify that the electronic device has been manufactured as expected prior to using the electronic device.

[0025] In general, a set of one-time-use private keys {sk, sk, …, sk} may be generated first and a corresponding single public key PK may be derived from the set of one-time- use private keys. Here, if the one-time-use private keys are generated and distributed, the state is not necessary at the signing entity as each one-time-use private key will be associated with a state and will only be used once. The state may, however, be valuable if the one-time-use private keys are being generated from the single private key as and when needed (rather than being generated in advance and distributed). For the signature generation, an unused one- time-use private key sk may be selected, preferably based on a current (updated) state. A signature of a message may then be generated using the one-time-use private key sk and the hash function. The private key sk may also be marked as being used. For the signature verification, which may be at the apparatus 110 or the electronic device 120, the one-time- use public key and the hash function may be used to verify the signature against the message. Advantageously, only one public key is required for the verification of a plurality of signatures and this is independent of the number of one-time-use private keys. This the verification process and the storage requirements, as will be further elaborated below.

[0026] Regarding a stateful hash-based signature scheme, the skilled person understands that an input parameter may be used in a process of key generation to generate a private key SK and a public key PK first. Based thereon, the private key SK may be used together with respective states {i, i+1, …, n} in a key derivation function (KDF), such as a HMAC-based Extract-and-Expand Key Derivation Function, a Password-Based Key Derivation Function or the like, to generate a plurality of one-time-use private keys {sk, sk , …, sk}. During the signature generation, a signing apparatus may use a generated one-time-use private key to generate a signature sig for a message. For the signature verification, only the public key PK is required to verify the signature as being a successful verification or a failed verification.

[0027] During a supply chain process of an electronic device, the electronic device may be required to be unlocked before a certain manufacturing process can be performed. As such, the stateful hash-based signature scheme of the present disclosure can also be applied to lock / unlock the electronic device in combination with performing a verification of a supply chain process. The skilled person understands that the stateful hash-based signature scheme of the present disclosure can also be applied to a distributed locking and unlocking of the electronic device independent from a verification of a supply chain process.

[0028] In a preferred embodiment, the controller 114 may further verify whether a particular supply chain operation has been completed by verifying a corresponding stateful hash-based signature. In particular, the controller 114 may determine whether a specific stateful hash-based signature has been used, for example a stateful hash-based signaturebeing related to a state, a specific state range, a specific one-time-use private key, or a specific one-time-use private key range.

[0029] In a preferred embodiment, the controller 114 may further verify whether a supply chain operation has occurred in an operation order in the series of supply chain operations by verifying the stateful hash-based signatures. That is, an expected order of states, an expected order of signatures, or details of chaining of signatures, or state information included or derived from the signatures may be used to determine that a prescribed order of supply chain manufacturing operations is adhered to. For example, the stateful hash-based signatures may be chained in an order by the respective distinct devices. This order may depend on the distribution of the one-time-use private keys between the different signing entities. That is, the verifying apparatus may operate on the assumption that the one-time-use private keys can be distributed in an order that corresponds to the ordering of the entities in the supply chain.

[0030] In a preferred embodiment, the controller 114 may further lock or unlock the electronic device 120 in an order corresponding to different subsets of state space of the plurality of one-time-use private keys. That is, the controller 114 may be able to lock or unlock the electronic device only if the (second) one-time-use private key used for the response message as associated with a certain state space that allows an authorization for locking or unlocking the electronic device. For example, the controller may unlock the electronic device 120 only in case of a valid verification of one of the stateful hash-based signatures having a corresponding state subsequent to a previously used state, in other words, follows a previous state (that is, a previous state should not be reused). If another distinct device had previously locked or unlocked the electronic device using a one-time-use private key being associated with a state spacethat is allocated to the distinct device (which is scheduled to perform an action on the electronic device before it reaches the apparatus 110), this another distinct device may not lock or unlock the electronic device anymore, even if the another distinct device has not used a one-time- use private key in the state space. Conversely, the controller 114 may be restricted to lock or unlock the electronic device in case of a verification of one of the stateful hash-based signatures having a corresponding state before a previously used state.

[0031] According to an embodiment, the memory 122 of the electronic device 120 may store a public key PK which is related to or associated with a plurality of distributed one- time-use private keys. It is preferred that the memory 122 stores the public key PK in a permanent, integrity protected or authenticated manner, for example using a read only memory or the like, so that the public key PK cannot be altered or modified.

[0032] The controller 124 may obtain, for example via communicator 126, a stateful hash-based signature to a message to verify an action event for the electronic device 120. Here, the stateful hash-based signature may have been generated using one of the plurality of distributed one-time- use private keys, for example by apparatus 110 or another distinct device (described below). The controller 124 may use the stored public key PK to verify the stateful hash-based signature and decide whether the action event for the electronic device is a valid action event. The action event may be an event related to a verification of a distributed supply chain operation performed on the electronic device and / or may be an event related to locking or unlocking the electronic device.

[0033] Preferably, the memory 122 of the electronic device 120 may store a plurality of distinct stateful hash-basedsignatures each related a different one of the action events in a supply chain manufacturing process of the electronic device. That is, the plurality of distinct stateful hash-based signatures may respectively be provided for a corresponding message and / or evidence that a distinct different action event, for example a specific processing step, has been performed on the electronic device.

[0034] Preferably, the controller 124 of the electronic device 120 may further lock or unlock the electronic device 120 as the action event if a specific stateful hash-based signature associated with a specific one of the plurality of distributed one-time-use private keys is provided. For example, locking or unlocking may be performed using a challenge-and-response communication between the apparatus 110 (or another distinct device during the workflow) and the electronic device 120. Here, the apparatus 110 may have generated a specific stateful hash-based signature for signing a response message to a challenge message triggered by the electronic device (for example, on the BIOS level of the electronic device). The specific stateful hash-based signature may have been generated using a one-time-use private key having a specific state space associated with locking / unlocking events.

[0035] Preferably, the controller 124 of the electronic device 120 may further block a locking or unlocking of the electronic device as the action event if a specific one of the plurality of distributed one-time-use private keys is used. In other words, even if the specific one of the plurality of distributed one-time-use private keys is associated with the common public key PK and used for generating a signature to a message indicating the action event, the controller 124 may not verify locking or unlocking the electronic device if the specific one of the plurality of distributed one-time-use private keys is not following a prescribed order, as will be further detailed below.

[0036] Figure 2 illustrates an example method 200 for a verification of a series of distributed supply chain operations performed on an electronic device and / or for a verification of an authentication to lock or unlock the electronic device.

[0037] Here, the method 200 may be a computer-implemented method. At 202, method 200 includes acquiring a public key PK. As described above, the public key PK is associated with a plurality of one-time-use private keys {sk} used by distinct devices to generate first distinct stateful hash- based signatures. The public key may be acquired from a memory, such as memory 112 of apparatus 110 or memory 122 of the electronic device 120.

[0038] At 204, method 200 includes using the public key and signed messages to verify (first) distinct stateful hash- based signatures of distinct devices for a verification of a series of distributed supply chain operations performed on the electronic device and / or using another one-time-use private key to generate a (second) distinct stateful hash- based signature for a response message related to a challenge message from the electronic device for a verification of an authentication to lock or unlock the electronic device.

[0039] Preferably, the signed messages to verify the first distinct stateful hash-based signatures of distinct devices may be stored at the memory 112 of apparatus 110 (for example, transferred via a communication infrastructure from respective distinct devices) or memory 122 of the electronic device 120 (for example, stored at the electronic device during the supply chain manufacturing by the respective distinct devices). In the latter scenario, the signed messages may be acquired by apparatus 110 after a successful unlocking of the electronic device 120 providing authorized access to the electronic device 120.

[0040] Figure 3 is a diagram of an example key management service 310, a plurality of distinct entities / parties 322, 324, 326, 328 involved in a workflow for an electronic device 340, as well as an example signing and / or locking / unlocking device 330 according to an embodiment. The workflow may be associated with a supply chain manufacturing process in which the electronic device 340 is manufactured in respective processes at the distinct entities / parties 322, 324, 326, 328. The key management service 310 may be realized by a cloud service, a key management server or the like to provide respective sets of distributed one-time-use private keys.

[0041] In particular, in regard to the verification of a supply chain manufacturing it may be considered that the electronic device 340 is progressing through a series of ordered steps during, for example, a manufacturing supply chain at distinct entities 322, 324, 326, 328. While Figure 3 indicates four distinct manufacturing entities, the skilled person understands that this is not a limiting example and that an actual supply chain manufacturing workflow for the electronic device may comprise many more distinct manufacturing entities. The process involves the multiple distinct entities 322, 324, 326, 328 to complete some action on the electronic device before the electronic device is then passed on to the next party or entity. A verification apparatus (such as apparatus 110) can, by applying the stateful hash-based signature scheme described above, verify that (i) a specific entity, a specific set of entities, or every entity of the manufacturing supply chain completed a required step, (ii) verify, whether a particular manufacturing or processing step was taken (if, for example, the supply chain processes were to be audited), and / or (iii) that the manufacturing or processing step have been completed in an expected or prescribed order.

[0042] While Figure 3 a single signing and / or locking / unlocking device 330 being associated with workflow entity 324, each of the distinct entities 322, 324, 326, 328 may be associated with such a device 330. The signing and / or locking / unlocking device 330 (referred to also as device) may have a memory 332, a controller 334, and a communicator 336 to communicate with the key management service 310 and may participate in the supply chain process to demonstrate that an action occurred on the electronic device and / or to lock or unlock the electronic device. In particular, the signing and / or locking / unlocking device 330 in the supply chain process should cryptographically sign a message including a statement, preferably also including some evidence, demonstrating that the respective party / entity 322 – 328 has completed the required step.

[0043] Here, according to an embodiment, the controller 334 of the device 330 may acquire a set of one-time-use private keys of a plurality of distributed one-time-use private keys associated with a public key PK. Here, the set of one-time- use private keys may be acquired via communicator 336 from the key management service 310 allocating different set of one-time-use private keys, as will be further detailed below. The set of one-time-use private keys may also be acquired from the memory 332 of the device 330. The controller 334 may use the set of acquired one-time-use private keys for a verification of a supply chain operation performed on the electronic device 340 and / or for an access verification for the electronic device 340. Here, the access verification may be a verification to lock or unlock the electronic device.

[0044] In particular, the verification of a supply chain operation performed on the electronic device 340 may be achieved by generating a signature to a message providing information and / or evidence of a specific action performed on the electronic device. In other words, the generated statefulhash-based signature for message indicates an action step in a supply chain operation process of the electronic device.

[0045] The controller 334 may further load the generated stateful hash-based signature onto the electronic device, preferably together with the message and / or evidence indicating a specific action performed on the electronic device 340.

[0046] The key management service 310 may provide a trusted service and may be responsible for generating, distributing, and optionally storing, the respective keys. In particular, the key management service may generate one or more stateful- hash-based signature pairs of public and private keys, and, considering the supply chain process and / or the locking / unlocking, may partition the set of generated one- time-use private keys such that a respective one-time-use private key, or a respective set of one-time-use private keys, are associated with a respective signing and / or locking / unlocking device 330. The skilled person understands that that there may be a fixed number of one-time-use private keys, with the number defined during key generation (e.g., there may be 2^^, 2^^, … , 2^^^, and that not every one-time-useprivate key immediately has to be associated with a signing and / or locking / unlocking apparatus.

[0047] For example, considering four signing and / or locking / unlocking device 330 respectively associated with parties / entities 322 – 327 in the process: ^^, ^^, ^^ and ^^. Thekey management service 310 may choose a parameter set of 2^^for the stateful hash-based signing and / or locking / unlocking scheme, the set of one-time-use private keys may thus have 2^^ = ^1024^ keys, {^^^, ^^^, … , ^^^^^^^}. The key management service310 may then choose to partition the keys such that each of the signing and / or locking / unlocking devices 330 receives (roughly) an equal share of the one-time-use private keys but withhold some keys for potential new entities (for futureuse). For example, the management service 310 may split the set of one-time-use private keys as follows: {^^^, … , ^^^^^} reserved for(114 shares) future use. {^^^^^, … , ^^^^^} allocated to ^^. (114 shares){^^^^^ ^^^^^} reserved for114 hWhile this table indicates an equal share of the one-time-use private keys to the respective signing and / or locking / unlocking apparatuses, the skilled person understands that this is not a limiting example, and that some signing and / or locking / unlocking apparatuses among the distributed set of entities may be allocated more one-time-use private keys than others. The one-time-use private keys may then either be distributed to the allocated parties to manage and store or be stored by the key management service 310 for use by the signing and / or locking / unlocking devices 330. The corresponding public key PK may be given to the verifying apparatus (for example, apparatus 110 described above). The corresponding public key PK may also be put onto the verifying apparatus in a non-updatable way. In other words, the public key PK may be stored in the verifying apparatus in such a way that the public key PK cannot be altered or modified. The skilled person understands that this can be done in a plurality of ways, such as using a read only memory (such as in a ROM), append-only logs, a blockchain or thelike. The key PK may also be sent to the verifying apparatus out of band, in other words, by using a separate and different communication channel than the one used for main data exchange. The allocation of states amongst the signing and / or locking / unlocking devices 330 may then optionally be made available to the verifying apparatus.

[0048] If the signing and / or locking / unlocking devices 330 are responsible for storing and using their allocated one-time- use private keys, they may each be responsible for signing a message or statement demonstrating the role they have played in the supply chain process for the verifying device to verify. Details of such a statement may vary according to the process and / or the signing party, but it may be, for example, a hash of some code that was put onto the electronic device, a summary of some configurations set, or the like. The statement should be understandable to or decodable by the verifying apparatus (such as apparatus 110), so that the verifying device can verify whether a step or process in the supply chain manufacturing was successfully completed. In conjunction with providing a verification signature to the message related to the supply chain manufacturing, or independent from this, the devices 330 may also use a one- time-use private key from the allocated set of one-time-use private keys to sign a message for a verification of an authentication to lock or unlock the electronic device. For example, before performing a step or process in the supply chain manufacturing, it may be necessary to unlock the electronic device (because it was locked by a previous party / entity in the manufacturing supply chain), or it is preferred to lock the electronic device after a step or process in the supply chain manufacturing was successfully completed and the electronic device is provided to the next entity in the workflow.

[0049] If, on the other hand, the key management service 310 is responsible for storing the signing keys, the signingand / or devices 330 may provide an authentication to the key management service 310 which will then sign the respective statement(s) or message(s) on their behalf.

[0050] The signatures sig may then be put into the electronic device 340, or otherwise made available to the verifying apparatus, for example via a wire-based or wireless communication channel between the distributed different devices 330 and the verifying apparatus. As described above, the verifying apparatus may use the single public key PK to verify all of the signatures produced using each of the one- time-use private keys at the distributed different devices 330 associated with the respective entities 322, 324, 326, 328. Thus, based on the example illustrated in Figure 3 for the purpose of explanation, the verifying apparatus may expect four signatures, one from each state space of four state ranges allocated by the key management service 310.

[0051] Alternatively, the verifying apparatus may not be provided with too much granular insight into the state space, and thus may just know to expect four signatures. This does not require to have any information about the one-time-use private key distribution among the distinct devices 330 and also reduces storage requirements. In still another alternative example, a third party device (that has knowledge of how many signatures should be expected) performs the verification.

[0052] The signatures ^ !"produced using the respective one- time-use private keys sk may each contain an authentication path, which may be used to verify the signature. Preferably, there is no overlap in the information of the authentication path in each signature, so the signatures may be compressed to minimise storage. In general, the authentication path may be a sequence of hash values to indicate how a leaf node (corresponding to the one-time-use signature) is connected tothe root of the tree. example, when signing a message using a Merkle-based stateful hash signature scheme, the process may involve the step of generating a one-time signature for the message and the one-time signature being associated with a leaf node in the Merkle tree. To allow the verifying apparatus to confirm that the one-time signature is valid, an authentication path may also be provided. Here, the authentication path may include intermediate hashes to trace a path from the leaf node up to the root hash of the Merkle tree. Then, by iteratively combining the leaf node's hash with a sibling hash and moving up the tree, the verifying apparatus may check if the final computed hash matches the known root hash. If they match, the signature is deemed valid, confirming that the one-time signature is indeed part of the Merkle tree.

[0053] Further, the state used to produce the signature may be contained in the signature, so the verifying apparatus may imply an ordering if the states were distributed among the distinct entities / devices 330 taking the ordering into consideration. For example, the verifying apparatus may be able to derive or imply that the signature ^ !"came before the signature ^ !"#^, and therefore that the step being signed by the first signature preceded the step signed by the second signature. However, this may also depend on the distribution of the state between the distinct different entities / apparatuses (as there is no cryptographic requirement that state + 1 is not be used before state ).This may be addressed by chaining the signatures, so that, for example, the signature ^ !"is appended to the message signed with the subsequent signature ^^"#^. This may be performed using a coordination amongst the signing devices 330, which the key management service 310 may be able to provide. Alternatively, an interactive protocol between the electronic device 340 and distinct entities 322, 324, 326, 328 may be performed (not involving key management service 310). For example, if entity 322 generates a signature on astatement and electronic 340 is passed or transferred to the next entity 324, then this next entity 324 may request the last signature and then hash this signature and include it in the message that it signs.

[0054] The verifying apparatus may be given information by the key management service 310 about which states each of the signing devices 330 has access to, how many signatures can be expected, and so on. This may be used to derive which steps were signed by each signing apparatus, and whether any steps of the process of the supply chain manufacturing have been missed.

[0055] This has the following technical advantages: One-time- use private keys sk can be shared amongst the multiple devices 330 (distinct devices). Based thereon: (i) The verifying apparatus (e.g. apparatus 110) is only required to store a corresponding single public key PK. (ii) The verifying apparatus may also distinguish between different stateful hash-based signatures generated by different devices 330. The skilled person understands that this may be implied by the state in the signature. Further, the different stateful hash-based signatures can be ordered. In particular, such an ordering may also be implied by the state. Alternatively, the different stateful hash-based signatures may also be chained; for example, the last signature may be appended to the message being signed next. In that way, the verifying apparatus may also identify whether or not a step has been missed, implied from the states that have and have not been used.

[0056] Further, locking and unlocking of the electronic device enables a user or operator (such as an administrator) to lock and unlock an electronic device, for example at the BIOS level, preventing unauthorized use of the electronic device, until the operator or user unlocks it. As explained above, the locking and unlocking may be performed in conjunctionwith the chain (for example, an operator unlocking the electronic device in order to perform a specific process during the supply chain manufacturing) or independent thereof. Here, the unlocking may be performed via a challenge-and-response between the apparatus of a one-time- use private key holder and the BIOS or another lower level system mode (e.g. running on a more privileged level than BIOS) of the electronic device which should have the corresponding public key (which may be installed into a platform management key hierarchy) to identify it as an authorized operator’s public key.

[0057] In some use cases, it may be necessary to permit multiple actors or operators, other than an administrator, to lock and unlock the electronic device. Such a scenario may thus occur while the electronic device is progressing through a one-way workflow, such as during the manufacturing supply chain. For example, when the electronic device or platform related to the electronic device is moving through individual steps of the supply chain to customer delivery, but also in other scenarios, such as if the customer is locking the electronic device during a flight.

[0058] Conventional systems do not permit multiple authorities or operators to lock and unlock the electronic device, certainly not in a prescribed order. Enabling these scenarios with a conventional setup would either require swapping public keys during the workflow or sharing the private key with the other party / entity. Conventional systems may also require interactions between a key holder and other parties which may require the parties to be online at the time of locking / unlocking the electronic device as well as an authentication infrastructure. Such scenarios are also distinctly one-way. That is, while multiple parties / entities may need to access the electronic device (for example, to perform a certain manufacturing process in a supply chain), once the electronic device is passed on or transported to anext party / entity of workflow (e.g. to the next manufacturing site), the previous operator should not get access to the electronic device again.

[0059] The skilled person understands that the use of the stateful hash-based signatures, as described above, also overcomes these technical limitations, as multiple entities can be given different one-time-use signing keys that may be used to lock or unlock the electronic device, while the electronic device itself has to store only a single public key.

[0060] According to a preferred embodiment, the key management service 310 may store and maintain the generated one-time-use private keys. The skilled person understands that the key management service may flexibly re-allocate the one-time-use private keys (not distributed yet), as the keys may have been logically allocated only and no keys have been given to any entities. This may facilitate adding new parties / entities, re-allocating the sets of keys (so that some signing parties have a larger proportion of one-time-use private keys than other signing parties), and / or re-ordering the parties / entities according to a new process.

[0061] By contrast, if the signing devices 330 themselves are storing the one-time-use keys, then the key management service 310 may be able to insert new entities into the manufacturing workflow by allocating some of the one-time-use private keys that were reserved, as described above.

[0062] To maximise the key management service’s ability to do this, the key management service may begin by giving each signing device 330 only a small number of one-time-use private keys (for example, ten), and then requiring the signing device 330 to request more one-time-use private keys as and when they are required.

[0063] In the setting, an electronic device may be locked in the factory, for example during the supply chain manufacturing process described above but requires unlocking for another process in the supply chain manufacturing process or for auditing prior to being shipped to the customer. To unlock the electronic device, a respective signing and / or locking / unlocking device 330 may demonstrate ownership of a private one-time-use private key corresponding to a public key that is installed on the electronic device. As such, each of respective devices 330 may have a one-time-use private key to unlock the electronic device.

[0064] According to an alternative embodiment, multiple public keys may be installed on the electronic device, one belonging to the signing and / or locking / unlocking device 330 (and associated with an auditor or operator in the supply chain process) and one to the verifying apparatus (e.g. apparatus 110), for example associated with a customer. A logic could then be used to enable the auditor’s key to unlock the electronic device only until the customer’s key is first used, ensuring that the auditor’s key cannot unlock the electronic device after the customer has claimed ownership of the electronic device (meaning that the customer has received the electronic device, and the auditor should no longer be able to unlock and audit the electronic device). This may also be enforced via the state. In other words, as indicated above, all states smaller or equal than a specific state X may be used within the supply chain, but states larger than X are owned by the user of the electronic device. When a signature is produced with a state larger than X, the electronic device may lock so that no signature with a state smaller than or equal to X are accepted.

[0065] According to another alternative embodiment, a single stateful hash-based signature public key may be installed on the electronic device and the factory operator(s) and / or theauditor(s) may be given first few one-time-use private signing keys (for example, the first three, respectively). The customer then has access to the rest of the one-time use signing keys. The electronic device will unlock to any valid signature that uses a state that is more or higher than the last state used. The skilled person understands that once the customer has used a one-time-use private signing key, the factory operator’s or auditor’s keys will no longer be able to unlock the electronic device, and the electronic device only has to store a single stateful hash-based signature public key (and a counter).

[0066] As explained, this means that multiple parties / entities may have different subsets of the state space (corresponding to respective sets of one-time-use private signing keys) to enable them to lock and unlock the electronic device in an ordered manner, in particular according to a prescribed order in which they should be able to lock or unlock the electronic device.

[0067] Based on the above it becomes possible to verify multiple steps of a supply chain process without the requirement to manage and store multiple public keys. As explained, this allows flexibility of the supply chain process. Advantageously, this may be combined with distributed (on-demand) locking / unlocking functionality, so that multiple distributed and different entities can lock and unlock the electronic device without introducing multiple public keys to the electronic device.

[0068] Figure 4 is a diagram of an example system 400 according to the present disclosure. The system may include a processor 402 and a non-transitory computer-readable storage medium 404 to store a computer program. Although the description may refer to a single processor and a single computer readable storage medium, the description may also apply to a system with multiple processors and multiplecomputer readable mediums. In such example, the instructions may be distributed and stored across multiple computer readable storage mediums and the instructions may be distributed and executed across multiple processors.

[0069] Processor 402 may be a central processing unit (CPU), a semiconductor based microprocessor, and / or hardware devices suitable for retrieval and execution of instructions stored in computer-readable storage medium 602. The processor 402 may fetch, decode, and execute instructions 412 and 414 or a combination thereof. The processor may be part of a controller of an apparatus 110, an electronic device 120, or a (signing and / or locking / unlocking) device 330 as described above.

[0070] Referring to Figure 4, acquire public key instruction 412, when executed by a processor of a controller, may comprise acquiring a public key PK which, as described above, is associated with a plurality of one-time-use private keys used by distinct (signing and / or locking / unlocking) devices to generate first distinct stateful hash-based signatures for respective messages and / or evidence of processes performed on an electronic.

[0071] Further referring to Figure 4, verify distributed supply chain operations and / or verify authentication to lock or unlock the electronic device instruction 414, when executed by the processor of the controller, may comprise using the public key and signed messages and / or evidence to verify (first) distinct stateful hash-based signatures of the distinct (signing and / or locking / unlocking) devices for a verification of a series of distributed supply chain operations performed on the electronic device and / or using another one-time-use private key, being also associated with the public key PK, to generate a (second) distinct stateful hash-based signature for a response message related to a challenge message from the electronic device for averification of an to lock or unlock the electronic device, as described above.

[0072] In the foregoing detailed description of the present disclosure, reference is made to the accompanying drawings that form a part hereof, and in which is shown by way of illustration how examples of the disclosure may be practiced. These examples are described in sufficient detail to enable those of ordinary skill in the art to practice the examples of this disclosure, and it is to be understood that other examples may be utilized and that process, electrical, and / or structural changes may be made without departing from the scope of the present disclosure.

[0073] The figures herein follow a numbering convention in which the first digit corresponds to the drawing figure number and the remaining digits identify an element or component in the drawing. Elements shown in the various figures herein can be added, exchanged, and / or eliminated so as to provide a number of additional examples of the present disclosure. In addition, the proportion and the relative scale of the elements provided in the figures are intended to illustrate the examples of the present disclosure and should not be taken in a limiting sense.

Claims

1. An apparatus, comprising: a memory to store a public key, the public key being associated with a plurality of one-time-use private keys used by distinct devices to generate first distinct stateful hash- based signatures; and a controller to use the public key and signed messages to verify the first distinct stateful hash-based signatures of the distinct devices for a verification of a series of distributed supply chain operations performed on an electronic device and / or to use another one-time-use private key to generate a second distinct stateful hash-based signature for a response message related to a challenge message from the electronic device for a verification of an authentication to lock or unlock the electronic device.

2. The apparatus of claim 1, the controller further to verify whether a particular supply chain operation has been completed by verifying a corresponding stateful hash-based signature.

3. The apparatus of claim 1, the controller further to verify whether a supply chain operation has occurred in an operation order in the series of supply chain operations by verifying the stateful hash-based signatures.

4. The apparatus of claim 3, wherein the stateful hash-based signatures are chained in an order.

5. The apparatus of claim 1, controller further to lock or unlock the electronic device in an order corresponding to different subsets of state space of the plurality of one- time-use private keys.

6. The apparatus of claim 1, the controller further to lock or unlock the electronic device in case of a valid verification of one of the stateful hash-based signatures having a corresponding state subsequent to a previously used state.

7. The apparatus of claim 1, the controller further to be restricted to lock or unlock the electronic device in case of a verification of one of the stateful hash-based signatures having a corresponding state before a previously used state.

8. A device, comprising: a controller to acquire a set of one-time-use private keys of a plurality of distributed one-time-use private keys associated with a public key; the controller further to use the set of one-time-use private keys for a verification of a supply chain operation performed on an electronic device and / or for an access verification to the electronic device.

9. The apparatus of claim 8, wherein the generated stateful hash-based signature indicates an action step in a supply chain operation process of the electronic device.

10. The apparatus of claim 9, the controller further to load the generated stateful hash-based signature onto the electronic device.

11. An electronic device, comprisinga memory to store a the public key being related to a plurality of distributed one-time-use private keys; a controller to obtain a stateful hash-based signature to a message to verify an action event for the electronic device.

12. The electronic device of claim 11, the memory further to store a plurality of distinct stateful hash-based signatures each related to a different one of action events in a supply chain process of the device.

13. The electronic device of claim 11, the controller further to lock or unlock the electronic device as the action event for a specific stateful hash-based signature associated with a specific one of the plurality of distributed one-time-use private keys.

14. The electronic device of claim 11, the controller further to block locking or unlocking the electronic device as the action event if a specific one of the plurality of distributed one-time-use private keys is used.

15. The electronic device of claim 11, the memory further to permanently store the public key.

Citation Information

Patent Citations

  • System and method for block-chain verification of goods

    US20160098723A1

  • Signing system for validating stateful hash-based digital signatures

    US20240039734A1

  • Stateful HASH-based signing with a single public key and multiple independent signers

    WO2023063957A1