IP Library Granted Patent US 10,771,450
Granted Patent B2
US 10,771,450 · App. 15/869,824 · Granted Sep 8, 2020

Method and system for securely provisioning a remote device

Inventors: Edward Snow Willis (Ottawa, CA); Hashim Mohammad Qaderi (Kitchener, CA); Scott Hutchens (Ottawa, CA); David Alan Inglis (Stittsville, CA)
Assignee: BlackBerry Limited
H04L63/0823G06F8/65H04L41/0806H04L63/06H04L63/0853H04L67/141H04W12/003H04W12/0609H04L63/10H04L67/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,771,450
App. No.
15/869,824
Granted
Sep 8, 2020
Kind
B2
Abstract

A method at a computing device for provisioning a network-connected device within a security platform, the method including receiving a first connection request, the first connection request being from an electronic apparatus and including a network-connected device identifier; authenticating the first connection request, thereby creating a first connection; receiving a second connection request, the second connection request being from the network-connected device and including the network-connected device identifier and a shared platform credential; receiving a request from the network-connected device to add the network-connected device to the security platform; and adding the network-connected device to the security platform based on a concurrent first connection and the request from the network-connected device to add the network-connected device to the security platform.

Claims (63)

1. A method at a computing device for provisioning a network-connected device within a security platform, the method comprising:

receiving a first connection request, the first connection request being from an electronic apparatus distinct from the network-connected device, and including a network-connected device identifier for the network-connected device;

authenticating the first connection request, thereby creating a first connection;

receiving a second connection request, the second connection request being from the network-connected device and including the network-connected device identifier and a shared platform credential;

receiving a request from the network-connected device to add the network-connected device to the security platform;

adding the network-connected device to the security platform based on a concurrent first connection and the request from the network-connected device to add the network-connected device to the security platform;

receiving a third connection request from a second network-connected device;

determining that no connection request including an identifier for the second network-connected device was received from any electronic apparatus; and

ignoring the third connection request.

2. The method of claim 1 , further comprising:

sending an acknowledgement to the network-connected device; and

receiving a public key from the network-connected device.

3. The method of claim 1 , wherein the second connection request is based on a physical interaction with the network-connected device.

4. The method of claim 1 , further comprising, prior to the receiving the first connection request:

sending client software to the network-connected device, the client software including the shared platform credential.

5. The method of claim 4 , wherein the shared platform credential includes a certificate and a private key.

6. The method of claim 1 , further comprising:

receiving a fourth connection request, the fourth connection request being from a second electronic apparatus and including a network-connected device identifier;

determining that authentication of the second electronic apparatus fails; and

ignoring the fourth connection request.

7. The method of claim 1 , further comprising, prior to the adding:

determining that the network-connected device has been previously added to the security platform;

ignoring the request from the network-connected device to add the network-connected device to the security platform; and

disabling the network-connected device from the security platform.

8. The method of claim 7 , further comprising creating a security flag for the network-connected device.

9. A computing device configured for provisioning a network-connected device within a security platform, the computing device comprising:

a processor;

a memory, and

a communications subsystem,

wherein the computing device is configured to:

receive a first connection request, the first connection request being from an electronic apparatus distinct from the network-connected device and including a network-connected device identifier for the network-connected device;

authenticate the first connection request, thereby creating a first connection;

receive a second connection request, the second connection request being from the network-connected device and including the network-connected device identifier and a shared platform credential;

receive a request from the network-connected device to add the network-connected device to the security platform;

add the network-connected device to the security platform based on a concurrent first connection and the request from the network-connected device to add the network-connected device to the security platform;

receive a third connection request from a second network-connected device;

determine that no connection request including an identifier for the second network-connected device was received from any electronic apparatus; and

ignore the third connection request.

10. The computing device of claim 9 , wherein the computing device is further configured to:

send an acknowledgement to the network-connected device; and

receive a public key from the network-connected device.

11. The computing device of claim 9 , wherein the second connection request is based on a physical interaction with the network-connected device.

12. The computing device of claim 9 , wherein the computing device is further configured to, prior to receiving the first connection request:

send client software to the network-connected device, the client software including the shared platform credential.

13. The computing device of claim 12 , wherein the shared platform credential includes a certificate and a private key.

14. The computing device of claim 9 , wherein the computing device is further configured to:

receive a fourth connection request, the fourth connection request being from a second electronic apparatus and including a network-connected device identifier;

determine that authentication of the second electronic apparatus fails; and

ignore the fourth connection request.

15. The computing device of claim 9 , wherein the computing device is further configured to, prior to adding:

determine that the network-connected device has been previously added to the security platform;

ignore the request from the network-connected device to add the network-connected device to the security platform; and

disable the network-connected device from the security platform.

16. The computing device of claim 15 , wherein the computing device is further configured to create a security flag for the network-connected device.

17. A non-transitory computer readable medium for storing instruction code, which when executed by a processor of a computing device configured for provisioning a network-connected device within a security platform, cause the computing device to:

receive a first connection request, the first connection request being from an electronic apparatus distinct from the network-connected device and including a network-connected device identifier for the network-connected device;

authenticate the first connection request, thereby creating a first connection;

receive a second connection request, the second connection request being from the network-connected device and including the network-connected device identifier and a shared platform credential;

receive a request from the network-connected device to add the network-connected device to the security platform;

add the network-connected device to the security platform based on a concurrent first connection and the request from the network-connected device to add the network-connected device to the security platform;

receive a third connection request from a second network-connected device;

determine that no connection request including an identifier for the second network-connected device was received from any electronic apparatus; and

ignore the third connection request.

Assignments (3)
NUNC PRO TUNC ASSIGNMENT Recorded Jun 19, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064271/0199 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064104/0103 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 30, 2018
From: WILLIS, EDWARD SNOW; HUTCHENS, SCOTT; INGLIS, DAVID ALAN; QADERI, HASHIM MOHAMMAD
To: BLACKBERRY LIMITED
Reel/Frame 046038/0128 →
Continuity (1)
Related Publication 20190222569A1 · Jul 18, 2019