Online secure device provisioning with online device binding using whitelists
US8627083B2 · kind B2 · utility
Assignee
Inventors
Key dates
| Filing date | Oct 6, 2011 |
| Grant date | Jan 7, 2014 |
| Priority date | — |
| Expiry date | Oct 6, 2031 |
Classification
- Technology area (CPC H)Electricity
- CPC primaryH04L9/321
- WIPO fieldDigital communication
- WIPO sectorElectrical engineering
Abstract
One or more servers are provided including a session manager, authentication module, authorization module, encryption module, database, and protocol handler. The session manager is configured to receive requests for new identity data from network-enabled devices. Each request is authenticated first by the update server via its authentication module by validating the signature of the request message as well as the certificate chain trusted by the update server. The authorization module is configured to determine if the network-enabled devices specified on a whitelist are authorized to be provisioned with new identity data. The database is configured to receive new identity records generated by an identity data generation system. Each of the new identity records includes a new identifier. The new identifier is not associated or linked to any previously assigned/used identifiers and identity data, thus all the new identity records are generated independently and then loaded to the update server.
Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.