ESTABLISHING A PROTECTED COMMUNICATION CHANNEL THROUGH A TTP

    公开(公告)号:EP3624394A1

    公开(公告)日:2020-03-18

    申请号:EP19197652.1

    申请日:2019-09-17

    申请人: Trustonic Limited

    发明人: HAYTON, Richard

    IPC分类号: H04L9/08 H04L9/32

    摘要: To establish a first protected communication channel between a device D and a first server S, a symmetric key K S is derived at the device D, based on a device identifying key K D and public key information dependent on a first server public key S public of the first server S. The symmetric key K S is derived in a corresponding way at a second server T. The symmetric key K S is transmitted from the second server T to the first server S on a second protected communication channel. Communication on the first protected communication channel between the device D and the first server S is protected using a communication key K C which is dependent on the symmetric key K S . This can enable a device D lacking support for asymmetric key cryptography to securely enter into communication with the first server S.

    DEVICE ATTESTATION TECHNIQUES
    2.
    发明公开

    公开(公告)号:EP3647979A1

    公开(公告)日:2020-05-06

    申请号:EP19206402.0

    申请日:2019-10-31

    申请人: Trustonic Limited

    发明人: HAYTON, Richard

    摘要: A method for providing an attestation for enabling a device to attest to an assertion concerning the device, comprising: generating an attestation identifier and a base-secret code corresponding to the attestation identifier; providing the attestation identifier and a validation-secret code to a validation apparatus for storage in conjunction with the assertion, wherein the validation-secret code is based on the base-secret code; providing the attestation identifier and a device-secret code to a manufacturer or adapter for provision to a device, wherein the device-secret code is based on the base-secret code.

    EVENT ATTESTATION FOR AN ELECTRONIC DEVICE
    3.
    发明公开

    公开(公告)号:EP3591564A1

    公开(公告)日:2020-01-08

    申请号:EP19192167.5

    申请日:2017-11-09

    申请人: Trustonic Limited

    IPC分类号: G06F21/73 G06F21/57 G06F21/44

    摘要: A method for validating an electronic device 2 comprises receiving attestation information provided by the electronic device 2 attesting that the electronic device 2 has received a plurality of event attestations, each event attestation providing a cryptographically authenticated attestation to the occurrence of a respective event during a lifecycle of the electronic device, and determining a validation result indicating whether the attestation information is valid. By providing separate cryptographically authenticated attestations for respective events in the lifecycle of the device, this can simplify manufacturing of the devices in a multistage manufacture process compared to an approach using a single device-specific attestation attesting that the entire process is trusted.

    EVENT ATTESTATION FOR AN ELECTRONIC DEVICE
    5.
    发明公开

    公开(公告)号:EP3346415A3

    公开(公告)日:2018-10-10

    申请号:EP17200828.6

    申请日:2017-11-09

    申请人: Trustonic Limited

    IPC分类号: G06F21/73 G06F21/57

    摘要: A method for validating an electronic device 2 comprises receiving attestation information provided by the electronic device 2 attesting that the electronic device 2 has received a plurality of event attestations, each event attestation providing a cryptographically authenticated attestation to the occurrence of a respective event during a lifecycle of the electronic device, and determining a validation result indicating whether the attestation information is valid. By providing separate cryptographically authenticated attestations for respective events in the lifecycle of the device, this can simplify manufacturing of the devices in a multistage manufacture process compared to an approach using a single device-specific attestation attesting that the entire process is trusted.

    EVENT ATTESTATION FOR AN ELECTRONIC DEVICE
    6.
    发明公开

    公开(公告)号:EP3346415A2

    公开(公告)日:2018-07-11

    申请号:EP17200828.6

    申请日:2017-11-09

    申请人: Trustonic Limited

    IPC分类号: G06F21/73 G06F21/57

    摘要: A method for validating an electronic device 2 comprises receiving attestation information provided by the electronic device 2 attesting that the electronic device 2 has received a plurality of event attestations, each event attestation providing a cryptographically authenticated attestation to the occurrence of a respective event during a lifecycle of the electronic device, and determining a validation result indicating whether the attestation information is valid. By providing separate cryptographically authenticated attestations for respective events in the lifecycle of the device, this can simplify manufacturing of the devices in a multistage manufacture process compared to an approach using a single device-specific attestation attesting that the entire process is trusted.