MLchartDataset catalogue

Patent · US11552998B2 · B2 · US

Device and system with a root of trust

(11) Publication number
US11552998B2
(21) Application number
16/546,803
(22) Filing date
2019-08-21
(30) Priority date
2018-08-23
(43) Publication date
2023-01-10
(45) Date of grant
2023-01-10
(51) IPC
H04L 29/06; H04L 9/40
(52) CPC
  • H04L Transmission of digital information, e.g. telegraphic communication: 63/20, 2209/127, 2209/805, 63/0281, 9/0877
  • G06F Electric digital data processing: 21/57
(73) Assignee
Infineon Technologies AG
(72) Inventors
Josef Haid; Stefan Rueping
(54) Title
Device and system with a root of trust
(57) Abstract

A device includes a root of trust and a controller to perform a device function of the device using the root of trust. The root of trust is designed to control and/or observe the controller at least partially for the performance of the device function.

Full text
View on Google Patents

Claims (13)

  1. A device, comprising: a root of trust security controller; and a controller to perform a device function of the device; wherein the root of trust security controller is designed to control the controller at least partially for the performance of the device function, and the root of trust security controller is configured as a logical master of the device and the controller is configured as a logical slave of the device.
  2. The device as claimed in claim 1, wherein the root of trust security controller is designed to monitor the performance of the device function by the controller.
  3. A device, comprising: a root of trust security controller; a controller to perform a device function of the device; and a communication interface for communication between the controller and a security computer network, wherein the root of trust security controller is designed to control the controller at least partially for the performance of the device function, and the root of trust security controller is configured as a proxy for the communication between the controller and the security computer network.
  4. The device as claimed in claim 3, wherein the controller is connected to the communication interface and is designed to transmit communication signals between the communication interface and the root of trust security controller, and the root of trust security controller is designed to extract information from the communication signals and provide it as a proxy of the controller.
  5. The device as claimed in claim 1, wherein the device is designed to communicate with a security computer network to provide security functions for the device, exclusively via the root of trust security controller.
  6. The device as claimed in claim 1, wherein the root of trust security controller is designed to forward instructions to the controller to control the performance of the device function.
  7. The device as claimed in claim 6, wherein the instructions comprise instructions which at least partially define a use of the root of trust security controller for the device function.
  8. The device as claimed in claim 1, wherein the device is designed as a networked device.
  9. The device as claimed in claim 1, wherein the device is designed as an Internet of Things device.
  10. The device as claimed in claim 1, wherein the device function is a sensor function and/or an actuator function.
  11. The device as claimed in claim 1, wherein the device is configured for direct communication between the controller and an application network.
  12. A system, comprising: a device as claimed in claim 1; and a security computer network which is configured to communicate directly with the root of trust security controller and to provide security applications for the device.
  13. The system as claimed in claim 12, wherein the security computer network communicates with the device exclusively via the root of trust security controller.

Description

The present disclosure relates to a device with a root of trust and a system with a device of this type. The present disclosure also relates to an active root of trust.

Security-based applications can use a root of trust to ensure the trustworthiness of a device which is used at a distance from a partner device. Examples of this include chip cards containing chips that provide a corresponding function, such as for use in ATMs, access systems or the like.

A securing of corresponding devices is also sought in the domain of the Internet of Things (IoT) in order to enable sustainable functionalities or business models at system level. Distributed devices, and, in particular, IoT devices are therefore required to be safe. This can be achieved by adding a security component to the IoT device, for example a security controller. A security controller of this type is also known as a Root of Trust (RoT) and is used, for example, as a Trusted Platform Module (TPM).

Devices and systems with a root of trust which have a high level of security would be desirable.

Example embodiments provide a device with a root of trust and a control unit to perform a device function of the device using the root of trust. The root of trust is designed to control and/or observe the control unit at least partially for the performance of the device function.

Citations (8)

  • EP2484564B1
  • US20140181505A1
  • US20150012737A1
  • US20160378996A1
  • US20190026477A1
  • US20170055148A1
  • US20180109538A1
  • US20180285600A1
Record as JSON
{
  "publication_number": "US11552998B2",
  "country": "US",
  "kind": "B2",
  "title": "Device and system with a root of trust",
  "abstract": "A device includes a root of trust and a controller to perform a device function of the device using the root of trust. The root of trust is designed to control and/or observe the controller at least partially for the performance of the device function.",
  "claims": [
    "1. A device, comprising: a root of trust security controller; and a controller to perform a device function of the device; wherein the root of trust security controller is designed to control the controller at least partially for the performance of the device function, and the root of trust security controller is configured as a logical master of the device and the controller is configured as a logical slave of the device.",
    "2. The device as claimed in claim 1, wherein the root of trust security controller is designed to monitor the performance of the device function by the controller.",
    "3. A device, comprising: a root of trust security controller; a controller to perform a device function of the device; and a communication interface for communication between the controller and a security computer network, wherein the root of trust security controller is designed to control the controller at least partially for the performance of the device function, and the root of trust security controller is configured as a proxy for the communication between the controller and the security computer network.",
    "4. The device as claimed in claim 3, wherein the controller is connected to the communication interface and is designed to transmit communication signals between the communication interface and the root of trust security controller, and the root of trust security controller is designed to extract information from the communication signals and provide it as a proxy of the controller.",
    "5. The device as claimed in claim 1, wherein the device is designed to communicate with a security computer network to provide security functions for the device, exclusively via the root of trust security controller.",
    "6. The device as claimed in claim 1, wherein the root of trust security controller is designed to forward instructions to the controller to control the performance of the device function.",
    "7. The device as claimed in claim 6, wherein the instructions comprise instructions which at least partially define a use of the root of trust security controller for the device function.",
    "8. The device as claimed in claim 1, wherein the device is designed as a networked device.",
    "9. The device as claimed in claim 1, wherein the device is designed as an Internet of Things device.",
    "10. The device as claimed in claim 1, wherein the device function is a sensor function and/or an actuator function.",
    "11. The device as claimed in claim 1, wherein the device is configured for direct communication between the controller and an application network.",
    "12. A system, comprising: a device as claimed in claim 1; and a security computer network which is configured to communicate directly with the root of trust security controller and to provide security applications for the device.",
    "13. The system as claimed in claim 12, wherein the security computer network communicates with the device exclusively via the root of trust security controller."
  ],
  "description_excerpt": "The present disclosure relates to a device with a root of trust and a system with a device of this type. The present disclosure also relates to an active root of trust.\n\nSecurity-based applications can use a root of trust to ensure the trustworthiness of a device which is used at a distance from a partner device. Examples of this include chip cards containing chips that provide a corresponding function, such as for use in ATMs, access systems or the like.\n\nA securing of corresponding devices is also sought in the domain of the Internet of Things (IoT) in order to enable sustainable functionalities or business models at system level. Distributed devices, and, in particular, IoT devices are therefore required to be safe. This can be achieved by adding a security component to the IoT device, for example a security controller. A security controller of this type is also known as a Root of Trust (RoT) and is used, for example, as a Trusted Platform Module (TPM).\n\nDevices and systems with a root of trust which have a high level of security would be desirable.\n\nExample embodiments provide a device with a root of trust and a control unit to perform a device function of the device using the root of trust. The root of trust is designed to control and/or observe the control unit at least partially for the performance of the device function.",
  "cpc": [
    "H04L 63/20",
    "G06F 21/57",
    "H04L 2209/127",
    "H04L 2209/805",
    "H04L 63/0281",
    "H04L 9/0877"
  ],
  "ipc": [
    "H04L 29/06",
    "H04L 9/40"
  ],
  "assignees": [
    "Infineon Technologies AG"
  ],
  "inventors": [
    "Josef Haid",
    "Stefan Rueping"
  ],
  "filing_date": "2019-08-21",
  "publication_date": "2023-01-10",
  "grant_date": "2023-01-10",
  "priority_date": "2018-08-23",
  "application_number": "US-201916546803-A",
  "family_id": "69412758",
  "cited_by_count": 4,
  "citations": [
    "EP2484564B1",
    "US20140181505A1",
    "US20150012737A1",
    "US20160378996A1",
    "US20190026477A1",
    "US20170055148A1",
    "US20180109538A1",
    "US20180285600A1"
  ]
}

Record 875 of 8,000 in Patents full text (MLC-0201). Request the full dataset.