Key revocation for edge devices

Techniques are described herein for remotely performing key revocation on a device that cannot communicate outside a local network of the device. The techniques involve including key revocation instructions in software update instructions sent to a device. The device may use one or more keys to vali...

Ausführliche Beschreibung

Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: POO TZE LEI, SIMON, JAMES, N
Format: Patent
Sprache:chi ; eng
Schlagworte:
Online-Zugang:Volltext bestellen
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
Beschreibung
Zusammenfassung:Techniques are described herein for remotely performing key revocation on a device that cannot communicate outside a local network of the device. The techniques involve including key revocation instructions in software update instructions sent to a device. The device may use one or more keys to validate the software update instructions to determine if they are secure executing on the device. For example, the device may verify whether a software update instruction has been sent by a trusted software provider. The device may execute a key revocation instruction included in the software update instruction to revoke use of a key in the keys and initiate use of a new key in place of the revoked key. 本文描述了在不能在设备的本地网络之外通信的设备上远程执行密钥撤销的技术。这些技术涉及在发送到设备的软件更新指令中包括密钥撤销指令。设备可以使用一个或多个密钥来验证软件更新指令,以确定它们在设备上执行是否安全。例如,该设备可以验证软件更新指令是否已经由可信软件提供商发送。该设备可以执行包括在软件更新指令中的密钥撤销指令,以撤销对密钥中的密钥的使用,并启动使用新密钥来代替被撤销的密钥。