1. A method of fabricating a microstructure device with an improved anchor, the method comprising:
providing a substrate;
forming an oxide layer on the substrate;
etching a cavity in the oxide layer, such that the cavity includes a sidewall in the oxide layer;
bonding a microstructure device layer to the oxide layer, over the cavity;
etching a trench in the device layer to define an outer boundary of a microstructure device, wherein the outer boundary is outside of the sidewall of the cavity; and
etching away the sidewall of the cavity through the trench in the device layer, thereby suspending the microstructure device over the cavity.
2. The method of claim 1, further comprising forming an anchor in the device layer to support the microstructure device.
3. The method of claim 2, wherein the etching away the sidewall of the cavity creates an undercut below the anchor in the oxide layer, the undercut being formed to have a length along the anchor that is less than one-half a length of the outer boundary of the microstructure.
4. The method of claim 1, further comprising forming the microstructure device as a microelectromechanical system (MEMS) device.
5. The method of claim 1, wherein the forming the oxide layer on the substrate includes forming the oxide layer as a silicon oxide layer.
6. The method of claim 5, wherein the etching away the sidewall of the cavity through the trench includes etching the silicon oxide layer using a vapor or a wet etch process.
7. The method of claim 1, further comprising hermetically sealing the microstructure device in a package.
8. A method of fabricating a microstructure device, the method comprising:
providing a substrate;
forming an oxide layer on the substrate;
etching a patterned cavity in the oxide layer, by forming a photoresist pattern on the oxide layer, wherein the pattern defines a sidewall around a perimeter of the cavity and a plurality of pillars within the cavity, which remain after the etching of the patterned cavity;
bonding a microstructure device layer to the oxide layer and the plurality of pillars, over the patterned cavity;
etching a trench in the device layer to define an outer boundary of a microstructure device, wherein the outer boundary is outside of the sidewall of the cavity; and
etching away the sidewall of the cavity and the plurality of pillars through the trench in the device layer, creating an open cavity, thereby suspending the microstructure device over the open cavity.
9. The method of claim 8, further comprising forming an anchor in the device layer to support the microstructure device.
10. The method of claim 9, wherein the etching away the sidewall of the cavity creates an undercut below the anchor in the oxide layer, the undercut being formed to have a length along the anchor that is less than one-half a length of the outer boundary of the microstructure.
11. The method of claim 8, further comprising forming the microstructure device as a microelectromechanical system (MEMS) device.
12. The method of claim 8, wherein the forming the oxide layer on the substrate includes forming the oxide layer as a silicon oxide layer.
13. The method of claim 12, wherein the etching away the sidewall of the cavity through the trench includes etching the silicon oxide layer using a vapor or a wet etch process.
14. The method of claim 8, further comprising hermetically sealing the microstructure device in a package.
The claims below are in addition to those above.
All refrences to claim(s) which appear below refer to the numbering after this setence.
1. A method comprising:
generating an encrypted data structure associated with a device, the encrypted data structure comprising a private key and a private key digest;
generating an identifier, based on the a pseudo-randomly generated value, for the encrypted data structure;
storing the identifier and the encrypted data structure in a signed group record on a removable storage medium; and
storing the pseudo-random value and a group number corresponding to the signed group record into non-volatile storage within the device.
2. The method of claim 1, further comprising distributing the removable storage medium and the device.
3. The method of claim 1, further comprising generating a Direct Proof family key pair for a class of devices.
4. The method of claim 1, further comprising generating a key pair for signing and verifying the group record.
5. The method of claim 4, further comprising storing a hash of the public key of the group record key pair into non-volatile storage of the device.
6. The method of claim 1, further comprising selecting a group size for the signed group record.
7. The method of claim 3, wherein the private key comprises a Direct Proof private key associated with a public key of the Direct Proof family key pair, and further comprising hashing the Direct Proof private key to generate the private key digest.
8. The method of claim 1, further comprising generating a symmetric key based on the pseudo-random value for the device.
9. The method of claim 8, wherein generating the identifier comprises encrypting a data value using the symmetric key.
10. The method of claim 8, further comprising encrypting the data structure using the symmetric key.
11. The method of claim 1, wherein the encrypted data structure further comprises a random initialization vector.
12. The method of claim 1, wherein the removable storage medium comprises at least one of a CD and a digital versatile disk (DVD).
13. The method of claim 1, wherein the pseudo-random value for the device is unique.
14. An article comprising: a first storage medium having a plurality of machine readable instructions, wherein when the instructions are executed by a processor, the instructions provide for delivering private keys in signed groups to devices by
generating an encrypted data structure associated with a device, the encrypted data structure comprising a private key and a private key digest;
generating an identifier, based on a pseudo-randomly generated value, for the encrypted data structure;
storing the identifier and the encrypted data structure in a signed group record on a removable storage medium; and
causing the storing the pseudo-random value and a group number corresponding to the signed group record into non-volatile storage within the device.
15. The article of claim 14, further comprising instructions for generating a key pair for signing and verifying the group record.
16. The article of claim 15, further comprising instructions for storing a hash of the public key of the group record key pair into non-volatile storage of the device.
17. The article of claim 14, further comprising instructions for selecting a group size for the signed group record.
18. The article of claim 14, further comprising instructions for generating a Direct Proof family key pair for a class of devices.
19. The article of claim 14, wherein the private key comprises a Direct Proof private key associated with a public key of the Direct Proof family key pair, and further comprising instructions for hashing the Direct Proof private key to generate the private key digest.
20. The article of claim 14, further comprising instructions for generating a symmetric key based on the pseudo-random value for the device.
21. The article of claim 20, wherein instructions for generating the identifier comprise instructions for encrypting a data value using the symmetric key.
22. The article of claim 20, further comprising instructions for encrypting the data structure using the symmetric key.
23. The article of claim 14, wherein the encrypted data structure further comprises a random initialization vector.
24. The article of claim 14, wherein the pseudo-random value for the device is unique.
25. A method comprising:
determining if an encrypted data structure, comprising a private key and a private key digest, associated with a device installed in a computer system is stored in a memory on the computer system; and
if the encrypted data structure is not stored, obtaining the encrypted data structure associated with the device in a signed group record from a removable storage medium accessible by the computer system, the removable storage medium storing a database of signed group records.
26. The method of claim 25, wherein the removable storage medium comprises at least one of a CD and a digital versatile disk (DVD) created by a manufacturer of the device.
27. The method of claim 25, wherein obtaining the encrypted data structure comprises issuing the acquire key command to the device to initiate a private key acquisition process.
28. The method of claim 25, wherein the private key comprises a Direct Proof private key associated with a public key of a Direct Proof family key pair for a class of devices.
29. The method of claim 27, wherein the private key acquisition process comprises generating a symmetric key based on a unique pseudo-random value stored in the device.
30. The method of claim 29, wherein the private key acquisition process comprises generating a device identifier, based on the pseudo-random value, for the encrypted data structure.
31. The method of claim 27, wherein the private key acquisition process comprises obtaining the signed group record corresponding to a group number of the device from the removable storage medium.
32. The method of claim 30, further comprising parsing the signed group record to obtain a group number, a group public key, and the encrypted data structure corresponding to the device identifier.
33. The method of claim 31, further comprising verifying the signed group record.
34. The method of claim 32, wherein the private key acquisition process further comprises decrypting the encrypted data structure received from the removable storage medium using the symmetric key to obtain the private key and the private key digest.
35. The method of claim 34, wherein the private key acquisition process further comprises hashing the private key to generate a new private key digest, comparing the private key digest from the decrypted data structure with the new private key digest, and accepting the private key as valid for the device when the digests match.
36. An article comprising: a first storage medium having a plurality of machine readable instructions, wherein when the instructions are executed by a processor, the instructions provide for obtaining a private key from a signed group record for a device installed in a computer system by
determining if an encrypted data structure, comprising a private key and a private key digest, associated with a device installed in a computer system is stored in a memory on the computer system (904); and
if the encrypted data structure is not stored, obtaining the encrypted data structure associated with the device in a signed group record from a removable storage medium accessible by the computer system, the removable storage medium storing a database of signed group records.
37. The article of claim 36, wherein instructions for obtaining the encrypted data structure comprise instructions for issuing the acquire key command to the device to initiate a private key acquisition process.
38. The article of claim 36, wherein the private key comprises a Direct Proof private key associated with a public key of a Direct Proof family key pair for a class of devices.
39. The article of claim 37, wherein the private key acquisition process comprises generating a symmetric key based on a unique pseudo-random value stored in the device.
40. The article of claim 37, wherein the private key acquisition process comprises generating a device identifier, based on the pseudo-random value, for the encrypted data structure.
41. The article of claim 37, wherein the private key acquisition process comprises obtaining the signed group record corresponding to a group number of the device from the removable storage medium.
42. The article of claim 40, further comprising parsing the signed group record to obtain a group number, a group public key, and the encrypted data structure corresponding to the device identifier.
43. The article of claim 41, further comprising verifying the signed group record.
44. The article of claim 42, wherein the private key acquisition process further comprises decrypting the encrypted data structure received from the removable storage medium using the symmetric key to obtain the private key and the private key digest.
45. The method of claim 44, wherein the private key acquisition process further comprises hashing the private key to generate a new private key digest, comparing the private key digest from the decrypted data structure with the new private key digest, and accepting the private key as valid for the device when the digests match.