IP Library Patent Application 14240050
Patent Application
App. No. 14/240,050

METHOD FOR A SECURED BACKUP AND RESTORE OF CONFIGURATION DATA OF AN END-USER DEVICE, AND DEVICE USING THE METHOD

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
14/240,050
Abstract

The method for a backup and restore of configuration data of an end-user device comprises the steps: encrypting the configuration data by using symmetric-key encryption with a symmetrical key, signing the encrypted configuration data with a device private key, and sending the encrypted and signed configuration data to a personal computer of a user of the end-user device, and/or to a storage location of a service provider network, for storage. For restoring of configuration data intended for use within the end-user device, a first or a second public key of an asymmetric key encryption system is used for validating signed configuration data provided by the service provider network or for validating signed configuration data stored on the personal computer of the user.

Claims (24)

1 . Method for a backup and restore of configuration data of an end-user device, comprising the steps of

encrypting the configuration data by using symmetric-key encryption with a symmetrical key,

signing the encrypted configuration data with a device private key of an asymmetric key encryption system,

sending the encrypted and signed configuration data to a personal computer of a user of the end-user device and/or to a storage location of a service provider network for storage, and

restoring of configuration data of the end-user device by using a first or a second public key for validating signed configuration data provided by the service provider network or for validating signed configuration data stored on the personal computer.

2 . Method according to claim 1 , comprising the steps of using an administration public key as the second public key for validating the signed configuration data as provided by the service provider network, and

using a device public key as the first public key for validating the signed configuration data stored on the personal computer.

3 . Method according to claim 2 , wherein the device private key is a device-specific private key, and the device-specific private key, the device public key and the administration public key of the asymmetric key encryption system are keys of an RSA public key algorithm.

4 . Method according to claim 1 , wherein the symmetrical key is common to a specific model of end-user devices of a service provider network, or is common to all of the end-user devices of the service provider network.

5 . Method according to claim 4 , wherein the symmetrical key is a shared secret key, for example a key in accordance with the Advanced Encryption Standard.

6 . Method according to claim 2 , comprising the step of using the restored configuration data for replacing the current configuration data of the end-user device.

7 . The method according to claim 2 , wherein the device-specific private key and the device public key constitute a first pair of an asymmetric key cryptographic system, and wherein the service provider network adds an administration private key to encrypted configuration data intended for restoring of the configuration data of the end-user device, the administration private key and the administration public key constituting a second pair of an asymmetric key cryptographic system.

8 . The method of claim 7 , wherein the end-user device uses the administration public key for validating the administration private key in case of restoring of configuration data provided by the service provider network.

9 . Method according to claim 9 , wherein the end-user device is a customer-premises equipment device and the service provider network is a network service provider network.

10 . Method according to claim 9 , wherein the customer-premises equipment device is coupled via a broadband connection to an auto configuration server of the network service provider network, and the backup is requested by the network service provider network via the auto configuration server.

11 . End-user device, utilizing a method according claim 1 .

12 . End-user device, comprising

a memory including configuration data, a symmetric key for encrypting the configuration data,

a private key of an asymmetric key encryption system for signing the encrypted configuration data, and

at least a first public key of the asymmetric key encryption system for validating signed configuration data for restoring of the configuration data.

13 . The end-user device of claim 12 , comprising a first public key of the asymmetric key encryption system for validating signed configuration data provided by a service provider network and a second public key of the asymmetric key encryption system for validating signed configuration data stored by a user of the end-user device on a personal computer of the user.

14 . The end-user device of claim 13 , comprising a user interface allowing a user of the end-user device to perform backup and restore operations of the configuration data, and a CWMP Client including a TR-069 standard compliant software component to enable the service provider network to perform backup and restore operations of the configuration data, by using a remote location of the service provider network for storage.

15 . The end-user device of claim 13 , wherein the end-user device is a customer-premises equipment device, a tablet PC or a smartphone.

16 . The end-user device of claim 13 , the symmetrical key is a shared secret key, for example a key in accordance with the Advanced Encryption Standard, and wherein the symmetrical key is common to a specific model of end-user devices of a service provider network, or is common to all of the end-user devices of the service provider network.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 20, 2020
From: THOMSON LICENSING S.A.S.
To: MAGNOLIA LICENSING LLC
Reel/Frame 053570/0237 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 27, 2014
From: VAN DEN BROECK, ROELAND; VAN DE POEL, DIRK
To: THOMSON LICENSING
Reel/Frame 032968/0438 →