Invention Grant
- Patent Title: Technologies for secure software update using bundles and merkle signatures
-
Application No.: US15267355Application Date: 2016-09-16
-
Publication No.: US10552138B2Publication Date: 2020-02-04
- Inventor: Ned M. Smith , Igor Stoppa , Timothy C. Pepper
- Applicant: Intel Corporation
- Applicant Address: US CA Santa Clara
- Assignee: Intel Corporation
- Current Assignee: Intel Corporation
- Current Assignee Address: US CA Santa Clara
- Agency: Barnes & Thornburg LLP
- Main IPC: G06F21/00
- IPC: G06F21/00 ; G06F8/65 ; G06F16/23 ; H04L9/06 ; H04L9/14 ; H04L9/30 ; H04L9/32

Abstract:
Technologies for secure software update include an update server and one or more client computing devices. The update server generates a software release including release components, such as packages and/or bundles, and a version number. The update server generates an integrity hash tree over the software release and a Lamport one-time signature key pair for each node of the integrity hash tree. The update server generates a Merkle signature scheme authentication tree based on the key pairs and signs each node of the integrity hash tree. The update server signs the root of the authentication tree with an anchor private key. A client computing device downloads one or more release components and verifies the release components with the integrity hash tree, the signatures, and the authentication tree. The client computing device verifies the root of the authentication tree with an anchor public key. Other embodiments are described and claimed.
Public/Granted literature
- US20170357496A1 TECHNOLOGIES FOR SECURE SOFTWARE UPDATE USING BUNDLES AND MERKLE SIGNATURES Public/Granted day:2017-12-14
Information query