IP Library Granted Patent US 9,219,607
Granted Patent B2
US 9,219,607 · App. 14/132,295 · Granted Dec 22, 2015

Provisioning sensitive data into third party

Inventor: Madjid F. Nakhjiri (San Diego, CA)
Assignee: ARRIS Technology, Inc.
H04L9/321G06F21/10G06F21/33H04L9/006
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,219,607
App. No.
14/132,295
Granted
Dec 22, 2015
Kind
B2
Abstract

A method for providing identity data to network-enabled devices includes receiving a request for identity data from a network-enabled device that is deployed to an end-user. The network-enabled device is pre-provisioned with a PIN, a global key pair, a user-accessible first device identifier, and a second device identifier usable by a service provider delivering a service to the device. The identity data request includes the first and second identifiers, a protected rendition of the PIN, and an encryption key or other data from which an encryption key is derivable. The identifiers, the protected rendition of the PIN, and the encryption key or the other data are signed by a private key in the global key pair. The validity of the PIN included in the request is verified to authenticate the device. If the PIN is valid, identity data for the device is generated, encrypted and sent to the network-enabled device.

Claims (27)

1. A method for providing identity data to a network-enabled device, comprising:

receiving a request for identity data from a network-enabled device that is provided to enable the network-enabled device to be authorized to operate to play videos in a network providing video content, the identity data being deployed to an end-user, the network-enabled device being pre-provisioned with a PIN and a service provider's public key from a web portal, a global key pair used by multiple network-enabled devices belonging to a particular population, a first device identifier that is user-accessible used in a key exchange for delivering the PIN, a second device identifier issued by the service provider and used by the service provider for delivering at least one service to the network-enabled device, the request for identity data including the first and second identifiers, a protected rendition of the PIN, and an encryption key or data from which an encryption key is derivable, the first and second identifiers, the protected rendition of the PIN, and the encryption key or the data from which an encryption key is derivable being signed by a private key in the global key pair;

verifying validity of the PIN included in the request to authenticate the network-enabled device to enable use of the network-enabled device in the network;

generating the identity data for the network-enabled device if the PIN is valid;

encrypting the identity data;

sending the encrypted identity data to the network-enabled device;

wherein the protected rendition of the PIN is a cryptographic hash computed over at least the combination of the PIN and second device identifier; and

wherein the protected rendition of the PIN is encrypted with the service provider's public key.

2. The method of claim 1 further comprising encrypting the identity data with a public key in the global key pair.

3. The method of claim 1 further comprising:

deriving a symmetric key from the data from which an encryption key is derivable as part of a key exchange protocol, when the symmetric key is not provided; and encrypting the identity data with the symmetric key.

4. The method of claim 3 wherein the key exchange protocol is Deffie-Hellman (D-H).

5. The method of claim 1 wherein the PIN is pre-provisioned in the network-enabled device during a registration process between the end user and the service provider.

6. The method of claim 5 wherein the PIN is delivered to the network-enabled device over a secure network connection.

7. The method of claim 6 wherein the PIN is delivered to the service provider by a provisioning system.

8. The method of claim 7 wherein the PIN is encrypted prior to delivery by the public key in the global key pair.

9. The method of claim 5 wherein a hash of the PIN is delivered to the network-enabled device by the service provider.

10. The method of claim 9 wherein the protected rendition of the PIN included in the identity data request includes the hash of the PIN.

11. The method of claim 1 wherein the second device identifier is also pre-provisioned in the network-enabled device during the registration process.

12. A method for providing identity data to a network-enabled device, comprising:

receiving a request for identity data from a network-enabled device that is provided to enable the network-enabled device to be authorized to operate to play videos in a network providing video content, the identity data being deployed to an end-user, the network-enabled device being pre-provisioned with a PIN, a global key pair used by multiple network-enabled devices belonging to a particular population, a first device identifier that is user-accessible used in a key exchange for delivering the PIN, a second device identifier issued by a service provider and used by the service provider for delivering at least one service to the network-enabled device, the request for identity data including the first and second identifiers, a protected rendition of the PIN, and an encryption key or data from which an encryption key is derivable, the first and second identifiers, the protected rendition of the PIN, and the encryption key or the data from which an encryption key is derivable being signed by a private key in the global key pair;

verifying validity of the PIN included in the request to authenticate the network-enabled device;

generating the identity data for the network-enabled device if the PIN is valid;

encrypting the identity data; and

sending the encrypted identity data to the network-enabled device,

wherein the protected rendition of the PIN is a cryptographic hash computed over at least the combination of the PIN and second device identifier; and

wherein verifying validity of the PIN comprises computing the same hash over the PIN and the second device identifier and verifying that the hash value is the same as the hash included is in the request message.

Assignments (14)
SECURITY INTEREST Recorded Apr 8, 2026
From: ARRIS ENTERPRISES LLC; RUCKUS IP HOLDINGS LLC
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 075476/0814 →
RELEASE OF SECURITY INTEREST AT REEL/FRAME 049905/0504 Recorded Dec 19, 2024
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: ARRIS ENTERPRISES LLC (F/K/A ARRIS ENTERPRISES, INC.); ARRIS TECHNOLOGY, INC.; ARRIS SOLUTIONS, INC.; COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; RUCKUS WIRELESS, LLC (F/K/A RUCKUS WIRELESS, INC.)
Reel/Frame 071477/0255 →
SECURITY INTEREST Recorded Dec 17, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE INC., OF NORTH CAROLINA; OUTDOOR WIRELESS NETWORKS LLC; RUCKUS IP HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC
Reel/Frame 069889/0114 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 23, 2022
From: ARRIS TECHNOLOGY, INC.
To: ARRIS ENTERPRISES, INC.
Reel/Frame 060791/0583 →
SECURITY INTEREST Recorded Nov 19, 2021
From: ARRIS SOLUTIONS, INC.; ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA; RUCKUS WIRELESS, INC.
To: WILMINGTON TRUST
Reel/Frame 060752/0001 →
ABL SECURITY AGREEMENT Recorded Jul 3, 2019
From: COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; ARRIS ENTERPRISES LLC; ARRIS TECHNOLOGY, INC.; RUCKUS WIRELESS, INC.; ARRIS SOLUTIONS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 049892/0396 →
TERM LOAN SECURITY AGREEMENT Recorded Jul 3, 2019
From: COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; ARRIS ENTERPRISES LLC; ARRIS TECHNOLOGY, INC.; RUCKUS WIRELESS, INC.; ARRIS SOLUTIONS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 049905/0504 →
PATENT SECURITY AGREEMENT Recorded Jul 3, 2019
From: ARRIS ENTERPRISES LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 049820/0495 →
CHANGE OF NAME Recorded Jul 2, 2019
From: ARRIS ENTERPRISES, INC.
To: ARRIS ENTERPRISES LLC
Reel/Frame 049649/0062 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Apr 8, 2019
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: ARRIS GROUP, INC.; ARRIS ENTERPRISES, INC.; ARRIS INTERNATIONAL LIMITED; ARRIS TECHNOLOGY, INC.; ARCHIE U.S. MERGER LLC; ARCHIE U.S. HOLDINGS LLC; ARRIS GLOBAL SERVICES, INC.; ARRIS HOLDINGS CORP. OF ILLINOIS, INC.; ARRIS SOLUTIONS, INC.; BIG BAND NETWORKS, INC.; TEXSCAN CORPORATION; POWER GUARD, INC.; JERROLD DC RADIO, INC.; NEXTLEVEL SYSTEMS (PUERTO RICO), INC.; GIC INTERNATIONAL HOLDCO LLC; GIC INTERNATIONAL CAPITAL LLC
Reel/Frame 050721/0401 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 18, 2015
From: ARRIS TECHNOLOGY, INC
To: ARRIS ENTERPRISES, INC.
Reel/Frame 037328/0341 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 11, 2015
From: NAKHJIRI, MADJID F.
To: GENERAL INSTRUMENT CORPORATION
Reel/Frame 037014/0986 →
SECURITY INTEREST Recorded Jun 26, 2015
From: ARRIS GROUP, INC.; ARRIS ENTERPRISES, INC.; ARRIS INTERNATIONAL LIMITED; ARRIS TECHNOLOGY, INC.; ARCHIE U.S. MERGER LLC; ARCHIE U.S. HOLDINGS LLC; ARRIS GLOBAL SERVICES, INC.; ARRIS HOLDINGS CORP. OF ILLINOIS, INC.; ARRIS SOLUTIONS, INC.; BIG BAND NETWORKS, INC.; TEXSCAN CORPORATION; POWER GUARD, INC.; JERROLD DC RADIO, INC.; NEXTLEVEL SYSTEMS (PUERTO RICO), INC.; GIC INTERNATIONAL HOLDCO LLC; GIC INTERNATIONAL CAPITAL LLC
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 036020/0789 →
MERGER AND CHANGE OF NAME Recorded Mar 10, 2015
From: GENERAL INSTRUMENT CORPORATION; GENERAL INSTRUMENT CORPORATION
To: ARRIS TECHNOLOGY, INC.
Reel/Frame 035176/0620 →
Continuity (2)
Provisional Application 61785673 · Mar 14, 2013
Related Publication 20140281493A1 · Sep 18, 2014