IP Library Granted Patent US 10,382,437
Granted Patent B2
US 10,382,437 · App. 15/458,454 · Granted Aug 13, 2019

Efficient and secure connection of devices to a network without user interfaces

Inventors: Daniel N. Bauer (Birmensdorf, CH); Gero Dittmann (Zurich, CH)
Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
H04L63/0876H04L63/0435H04L63/0442H04L63/061H04W12/003H04L63/0823H04W12/00512H04W12/00522
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,382,437
App. No.
15/458,454
Granted
Aug 13, 2019
Kind
B2
Abstract

Embodiments of the invention is directed to a method for connecting a device to a network. An example method comprises providing a device assigned with a device identifier and an asymmetric cryptographic key pair that includes a public key and a private key. The device stores the private key on a memory thereof. The device is provided with information as to the assigned device identifier and/or the public key. This information is detectable by a detector so as to be transmissible to a server for it to identify the device identifier and the public key assigned to the device.

Claims (29)

1. A system comprising a device connectable to network and a medium encoding information, wherein:

the device comprises a memory storing a private key of an asymmetric cryptographic key pair assigned to the device; and

said medium encodes information pertaining to at least one of a device identifier assigned to the device and a public key corresponding to said asymmetric cryptographic key pair, wherein said information is encoded so to be detectable by a detector and be in turn transmissible to a server for the server to identify the device identifier and the public key assigned to the device;

and wherein the device is configured to:

detect a signal encrypted at least in part with the public key of the device, wherein the signal invites the device to connect to a network, said signal encoding both:

a device identifier as identified by the server based at least in part on information transmitted to the server; and

a network identifier of said network, the network identifier encrypted with the public key of the device as identified by the server based at least in part on information detected by the detector;

decrypt, utilizing the private key of device, the signal to obtain the network identifier of the network; and

initiate a network connection with said network, based at least in part on such a decrypted network identifier, upon decrypting this network identifier.

2. The system according to claim 1 , wherein:

said information is encoded as a machine-readable optical label of the device.

3. The system according to claim 2 , wherein:

said machine-readable optical label is a matrix code.

4. The system according to claim 1 , wherein:

said device is deprived of any user interface for connecting said device to the network.

5. The system according to claim 1 , wherein:

the device further comprises one or more wireless connectivity modules, the modules configured for detecting said signal and initiating said network connection with the network.

6. A server configured to interact with a device assigned with a device identifier and an asymmetric cryptographic key pair that includes a public key and a private key, wherein the device stores the private key on a memory thereof and is provided with information as to at least one of the assigned device identifier and the public key, said information detectable by a detector so as to be transmissible to a server, wherein the server comprises one or more computer processors configured to:

identify the device identifier and the public key assigned to the device based at least in part on the information received, upon receiving information from the detector; and

instruct one or more network access points of a network to transmit a signal encrypted, at least in part, with the public key assigned to the device as identified by the server;

wherein the signal invites the device to connect to a network, and wherein the signal encodes both the device identifier as identified by the server and a network identifier of said network;

wherein the device is configured to decrypt the network identifier using the private key of the device and to initiate a network connection with said network.

7. The network comprising the server according to claim 6 and the one or more network access points, wherein:

the network is configured to complete a network connection as initiated by the device to subsequently communicate therewith.

8. A computer program product for allowing a server to interact with a device assigned with a device identifier and an asymmetric cryptographic key pair, the asymmetric cryptographic key pair comprising a public key and a private key, wherein the device stores the private key on a memory thereof and is provided with information as to at least one of the assigned device identifier and the public key, said information detectable by a detector so as to be transmissible to a server, the computer program product comprising a non-transitory computer readable storage medium having program instructions embodied therewith, the program instructions being executable by one or more processors of the server to cause the server to:

identify the device identifier and the public key assigned to the device based at least in part on the information received, upon receiving the information from the detector; and

instruct one or more network access points of a network in communication with the server to transmit a signal encrypted, at least in part, with the public key assigned to the device as identified by the server;

wherein the signal invites the device to connect to the network, and wherein the signal encodes both the device identifier as identified by the server and a network identifier of said network;

wherein the device is configured to decrypt the network identifier using the private key of the device and to initiate a network connection with said network.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 14, 2017
From: BAUER, DANIEL N.; DITTMANN, GERO
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 041571/0794 →
Continuity (1)
Related Publication 20180270228A1 · Sep 20, 2018
Cited By (1)
US 12,306,976