IP Library Granted Patent US 10,503,881
Granted Patent B2
US 10,503,881 · App. 15/812,510 · Granted Dec 10, 2019

Secure provisioning and management of devices

Inventors: William L. Lattin (Los Altos, CA); David R. Sequino (Leesburg, VA); Alan T. Meyer (Anaheim Hills, CA); Gregory A. Powell (Ladera Ranch, CA)
Assignee: INTEGRITY SECURITY SERVICES LLC
G06F21/12G06F21/572H04L9/007H04L9/0827H04L9/0877H04L9/321H04L9/3263H04L63/0823H04W4/50H04W4/70H04W12/0023H04W12/04H04W12/06H04L63/0414H04L63/18H04W12/00518
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,503,881
App. No.
15/812,510
Granted
Dec 10, 2019
Kind
B2
Abstract

Systems for secure provisioning and management of computerized devices. The system may include a distributor appliance that is communicatively connected to the computerized device, and that is operable to receive a digital asset and to load the digital asset into the computerized device. It may also include a digital asset management system that is connected via a first secure communication channel to the distributor appliance, and that is operable to generate and conditionally transmit the digital asset to the distributor appliance; and a provisioning controller that is connected via a second secure communication channel to the distributor appliance and is connected via a third secure communication channel to the digital asset management system, and that is operable to direct the digital asset management system to transmit the digital asset to the distributor appliance. The computerized device is not fully functional before the digital asset is loaded into it.

Claims (31)

1. A system for securely provisioning a computerized device, the system comprising:

a first secure distributor appliance that is communicatively connected to the computerized device, and that is operable to receive a first digital asset and to load the first digital asset into the computerized device;

a digital asset management server that is connected via a first secure communication channel to the first secure distributor appliance, and that is operable to generate and conditionally transmit the first digital asset to the first secure distributor appliance;

a provisioning controller that is connected via a second secure communication channel to the first secure distributor appliance and is connected via a third secure communication channel to the digital asset management server, and that is operable to direct the digital asset management server to transmit the first digital asset to the first secure distributor appliance;

a second secure distributor appliance that is connected via a fourth secure communication channel to the digital asset management server and that is communicatively connected to the computerized device after the first secure distributor appliance is disconnected, and that is operable to receive a second digital asset and to load the second digital asset into the computerized device;

wherein the provisioning controller is further operable to direct the digital asset management server to transmit the second digital asset to the second secure distributor appliance;

wherein the computerized device is fully functional after the second digital asset is loaded into the computerized device; and

wherein the computerized device is nonfunctional before the second digital asset is loaded into the computerized device.

2. The system for securely provisioning a computerized device of claim 1 , wherein the system further comprises:

one or more virtual machines that run a registration authority application and that are communicatively connected to one or more compute engines that perform cryptographic computations required by the registration authority application;

one or more virtual machines that run an enrollment certificate authority application and that are communicatively connected to one or more compute engines that perform cryptographic computations required by the enrollment certificate authority application;

one or more virtual machines that run a pseudonym certificate authority application and that are communicatively connected to one or more compute engines that perform cryptographic computations required by the pseudonym certificate authority application;

one or more virtual machines that run a first linkage authority application and that are communicatively connected to one or more compute engines that perform cryptographic computations required by the first linkage authority application; and

one or more virtual machines that run a second linkage authority application and that are communicatively connected to one or more compute engines that perform cryptographic computations required by the second linkage authority application.

3. The system for securely provisioning a computerized device of claim 2 , wherein the system further comprises:

a database that is operably connected to the one or more virtual machines that run the registration authority application, the one or more virtual machines that run the enrollment certificate authority application, the one or more virtual machines that run the pseudonym certificate authority application, the one or more virtual machines that run the first linkage authority application, and the one or more virtual machines that run the second linkage authority application.

4. The system for securely provisioning a computerized device of claim 1 , further comprising:

a first portal that is operably connected to the provisioning controller and that authenticates a manufacturer of the computerized device and enables the manufacturer to manage provisioning of the computerized device.

5. The system for securely provisioning a computerized device of claim 4 , further comprising:

a second portal that is operably connected to the provisioning controller and that authenticates an installer of the computerized device and enables the installer to manage provisioning of the computerized device.

6. The system for securely provisioning a computerized device of claim 1 , further comprising:

a third portal that is operably connected to the provisioning controller and that authenticates a regulator of the computerized device and enables the regulator to regulate provisioning of the computerized device.

7. The system for securely provisioning a computerized device of claim 1 , wherein the provisioning controller is further operable to transmit the first digital asset to the first secure distributor appliance for loading into the computerized device.

8. The system for securely provisioning a computerized device of claim 7 , wherein the first digital asset is executable code that is run by the computerized device.

9. The system for securely provisioning a computerized device of claim 1 , wherein the second digital asset is at least one of: a digital certificate, a cryptographic key, and executable software.

10. The system for securely provisioning a computerized device of claim 1 , wherein the provisioning controller is further operable to create and maintain a log that is associated with the computerized device and that stores information regarding the provisioning activities for the computerized device.

11. The system for securely provisioning a computerized device of claim 10 , wherein the digital asset management server is further operable to transmit information regarding provisioning activities related to the computerized device to the provisioning controller for storing in the log.

12. The system for securely provisioning a computerized device of claim 10 , wherein the first secure distributor appliance is further operable to transmit information regarding provisioning activities related to the computerized device to the provisioning controller for storing in the log.

13. The system for securely provisioning a computerized device of claim 1 , wherein the provisioning controller is further operable to authenticate the computerized device before directing the digital asset management server to transmit the first digital asset.

14. The system for securely provisioning a computerized device of claim 1 , wherein the computerized device is an embedded Universal Integrated Circuit Card (eUICC).

15. The system for securely provisioning a computerized device of claim 1 , wherein the digital asset management server comprises a plurality of servers.

Assignments (4)
ENTITY CONVERSION Recorded Nov 26, 2019
From: INTEGRITY SECURITY SERVICES, INC.
To: INTEGRITY SECURITY SERVICES LLC
Reel/Frame 051115/0963 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 26, 2019
From: MEYER, ALAN T.; POWELL, GREGORY A.
To: INTEGRITY SECURITY SERVICES LLC
Reel/Frame 051116/0104 →
ENTITY CONVERSION Recorded Dec 31, 2018
From: INTEGRITY SECURITY SERVICES, INC.
To: INTEGRITY SECURITY SERVICES LLC
Reel/Frame 047996/0186 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 14, 2018
From: LATTIN, WILLIAM L.; SEQUINO, DAVID R.
To: INTEGRITY SECURITY SERVICES, INC.
Reel/Frame 045799/0328 →
Continuity (4)
Provisional Application 62421878 · Nov 14, 2016
Provisional Application 62421852 · Nov 14, 2016
Provisional Application 62487909 · Apr 20, 2017
Related Publication 20180137261A1 · May 17, 2018