IP Library Granted Patent US 12713238
Granted Patent B2
US 12713238 · App. 18/658,696 · Granted Aug 18, 2026

Verifying user premises equipment identity with deployed firmware and expired authentication

Inventors: James Kruczek (Lone Tree, CO); Tyson Vinson (Denver, CO); Dan Mattox (Parker, CO); Ashish Ranjan (Lone Tree, CO)
Assignee: Charter Communications Operating, LLC
H04W12/069H04W12/63H04W12/66H04W60/04
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12713238
App. No.
18/658,696
Granted
Aug 18, 2026
Kind
B2
Abstract

An authentication request is received from a User Premises Equipment (UPE). The authentication request is responsive to expiration of a prior authentication certificate provided to the UPE. The authentication request comprises a set of metadata information elements. A subset of metadata information elements are selected from the set, comprising a static element descriptive of a UPE establishment event, and environmental elements indicative of a physical environment of the UPE. The static element is validated based on validation information. A trust score for the UPE is generated based on a comparison between the environmental elements and a UPE environmental profile descriptive of a known physical environment of a geographic area associated with the UPE. An authentication certificate is provided to the UPE based on the trust score being greater than a threshold trust score.

Claims (79)

1 . A method, comprising:

receiving, by a computing system, an authentication request from a User Premises Equipment (UPE), wherein the authentication request is responsive to expiration of a prior authentication certificate provided to the UPE, and wherein the authentication request comprises a set of metadata information elements;

selecting, by the computing system, a subset of metadata information elements from the set of metadata information elements, wherein the subset of metadata information elements comprises:

a static metadata information element descriptive of a UPE establishment event that occurred prior to provision of the prior authentication certificate to the UPE; and

a plurality of environmental metadata information elements indicative of a physical environment of the UPE;

validating, by the computing system, the static metadata information element based on validation information descriptive of the UPE establishment event;

generating, by the computing system, a trust score for the UPE based on a comparison between the plurality of environmental metadata information elements and a UPE environmental profile descriptive of a known physical environment of a geographic area associated with the UPE; and

providing, by the computing system, an authentication certificate to the UPE based on the trust score being greater than a threshold trust score.

2 . The method of claim 1 , wherein selecting the subset of metadata information elements from the set of metadata information elements comprises:

determining, by the computing system, the geographic area associated with the UPE; and

determining, by the computing system, that the UPE environmental profile is available for the geographic area associated with the UPE.

3 . The method of claim 2 , wherein determining the geographic area associated with the UPE comprises:

identifying, by the computing system, a user account to which the UPE is assigned; and

obtaining, by the computing system, user registration information for the user, wherein the user registration information is indicative of the geographic area associated with the UPE.

4 . The method of claim 3 , wherein obtaining the user registration information for the user further comprises:

obtaining, by the computing system, logging information from intermediate network devices located within the geographic area; and

based on the logging information, identifying, by the computing system, one or more occurrences prior to receiving the authentication request in which the intermediate network devices received information from the UPE.

5 . The method of claim 1 , wherein, prior to receiving the authentication request, the method comprises:

receiving, by the computing system, a plurality of initial environmental metadata information elements from a plurality of UPEs located within the geographic area; and

generating, by the computing system, the UPE environmental profile descriptive of the known physical environment for the geographic area associated with the UPE.

6 . The method of claim 1 , wherein the UPE establishment event comprises:

a manufacturing event during which the UPE was manufactured;

a configuration event during which the UPE was last configured; or

a deployment event during which the UPE was last deployed.

7 . The method of claim 6 , wherein the UPE establishment event comprises the manufacturing event during which the UPE was manufactured; and

wherein, prior to receiving the authentication request, the method comprises:

obtaining, by the computing system, manufacturing information descriptive of a manufacturing date for the UPE; and

storing, by the computing system, the manufacturing information as the validation information descriptive of the UPE establishment event.

8 . The method of claim 6 , wherein the UPE establishment event comprises the configuration event during which the UPE was last configured; and

wherein, prior to receiving the authentication request, the method comprises:

obtaining, by the computing system, configuration information descriptive of prior values applied to configuration parameters of the UPE during the configuration event; and

storing, by the computing system, the validation information descriptive of the UPE establishment event based on the configuration information.

9 . The method of claim 8 , wherein the prior values comprise an initial firmware version number for firmware installed to the UPE.

10 . The method of claim 1 , wherein selecting the subset of metadata information elements from the set of metadata information elements comprises:

performing, by the computing system, a threat analysis to identify one or more types of threat actors;

generating, by the computing system, a sampling rule based on the one or more types of threat actors; and

using, by the computing system, the sampling rule to select the subset of metadata information elements from the set of metadata information elements.

11 . A computing system, comprising:

one or more processor devices configured to:

receive an authentication request from a User Premises Equipment (UPE), wherein the authentication request is responsive to expiration of a prior authentication certificate provided to the UPE, and wherein the authentication request comprises a set of metadata information elements;

select a subset of metadata information elements from the set of metadata information elements, wherein the subset of metadata information elements comprises:

a static metadata information element descriptive of a UPE establishment event that occurred prior to provision of the prior authentication certificate to the UPE; and

a plurality of environmental metadata information elements indicative of a physical environment of the UPE;

access validation information descriptive of the UPE establishment event to validate the static metadata information element;

generate a trust score for the UPE based on a comparison between the plurality of environmental metadata information elements and a UPE environmental profile descriptive of a known physical environment of a geographic area associated with the UPE; and

provide an authentication certificate to the UPE based on the trust score being greater than a threshold trust score.

12 . The computing system of claim 11 , wherein selecting the subset of metadata information elements from the set of metadata information elements comprises:

determining the geographic area associated with the UPE; and

determining that the UPE environmental profile is available for the geographic area associated with the UPE.

13 . The computing system of claim 12 , wherein determining the geographic area associated with the UPE comprises:

identifying a user account to which the UPE is assigned; and

obtaining user registration information for the user, wherein the user registration information is indicative of the geographic area associated with the UPE.

14 . The computing system of claim 13 , wherein obtaining the user registration information for the user further comprises:

obtaining logging information from intermediate network devices located within the geographic area; and

based on the logging information, identifying one or more occurrences prior to receiving the authentication request in which the intermediate network devices received information from the UPE.

15 . The computing system of claim 11 , wherein, prior to receiving the authentication request, the one or more processor devices are configured to:

receive a plurality of initial environmental metadata information elements from a plurality of UPEs located within the geographic area; and

generate the UPE environmental profile descriptive of the known physical environment for the geographic area associated with the UPE.

16 . The computing system of claim 11 , wherein the UPE establishment event comprises:

a manufacturing event during which the UPE was manufactured;

a configuration event during which the UPE was last configured; or

a deployment event during which the UPE was last deployed.

17 . The computing system of claim 16 , wherein the UPE establishment event comprises the manufacturing event during which the UPE was manufactured; and

wherein, prior to receiving the authentication request, the one or more processor devices are configured to:

obtain manufacturing information descriptive of a manufacturing date for the UPE; and

store the manufacturing information as the validation information descriptive of the UPE establishment event.

18 . The computing system of claim 16 , wherein the UPE establishment event comprises the configuration event during which the UPE was last configured; and

wherein, prior to receiving the authentication request, the one or more processor devices are configured to:

obtain configuration information descriptive of prior values applied to configuration parameters of the UPE during the configuration event; and

store the validation information descriptive of the UPE establishment event based on the configuration information.

19 . The computing system of claim 18 , wherein the prior values comprise an initial firmware version number for firmware installed to the UPE.

20 . A non-transitory computer-readable storage medium that includes executable instructions configured to cause one or more processor devices to:

receive an authentication request from a User Premises Equipment (UPE), wherein the authentication request is responsive to expiration of a prior authentication certificate provided to the UPE, and wherein the authentication request comprises a set of metadata information elements;

select a subset of metadata information elements from the set of metadata information elements, wherein the subset of metadata information elements comprises:

a static metadata information element descriptive of a UPE establishment event that occurred prior to provision of the prior authentication certificate to the UPE; and

a plurality of environmental metadata information elements indicative of a physical environment of the UPE;

access validation information descriptive of the UPE establishment event to validate the static metadata information element;

generate a trust score for the UPE based on a comparison between the plurality of environmental metadata information elements and a UPE environmental profile descriptive of a known physical environment of the UPE; and

provide an authentication certificate to the UPE based on the trust score being greater than a threshold trust score.