IP Library Granted Patent US 10,469,480
Granted Patent B2
US 10,469,480 · App. 16/047,507 · Granted Nov 5, 2019

System and method for securing data transport between a non-IP endpoint device that is connected to a gateway device and a connected service

Inventors: Srinivas Kumar (Cupertino, CA); Atul Gupta (Sunnyvale, CA); Ruslan Ulanov (Dublin, CA); Shreya Uchil (Millbrae, CA)
Assignee: MOCANA CORPORATION
H04L63/0823G06F8/65G06F8/71G06F21/57G06F21/575H04L9/0637H04L9/0825H04L9/30H04L9/321H04L9/3247H04L9/3268H04L63/12H04L67/104H04W8/005G06F9/4401H04L63/0428H04L63/20H04W12/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,469,480
App. No.
16/047,507
Granted
Nov 5, 2019
Kind
B2
Abstract

A method of securing data transport between an endpoint device, without an IP address and connected to a gateway device, and a connected service using a discovery agent, a discovery service, and an enrollment service. The method includes: sending to the discovery service on the gateway device, an authenticated identity beacon with a device profile of the endpoint device; verifying authentication of the endpoint device and the device profile and generating a certificate request for the endpoint device; processing, by the enrollment service, the certificate request for the endpoint device to translate the certificate request for a certificate authority and receiving a certificate for the endpoint device issued by the certificate authority; processing the received certificate for the endpoint device to translate the received certificate for the endpoint device to represent a privacy certificate authority; and performing cryptographic operations on data using the certificate for the endpoint device.

Claims (62)

1. A method of device identification for enrollment and registration of an endpoint device that is connected to a gateway device using a multi-stage verified boot loader, a discovery agent at the endpoint device, a discovery service at the gateway device, an enrollment service, a policy service, and a device management service, the method comprising:

sending, by the discovery agent on the endpoint device, to the discovery service on the gateway device, an authenticated identity beacon with an endpoint device profile;

verifying, by the discovery service, the authenticated identity beacon of the endpoint device and the endpoint device profile;

generating, by the discovery service, a certificate request for the endpoint device from a privacy certificate authority;

sending, by the discovery service, the certificate request for the endpoint device to the enrollment service;

processing, by the enrollment service, the certificate request for the endpoint device that is received in order to translate the certificate request for a certificate authority;

sending, by the enrollment service to the certificate authority, the translated certificate request for the endpoint device;

receiving, by the enrollment service, a certificate for the endpoint device issued by the certificate authority;

processing, by the enrollment service, the received certificate for the endpoint device in order to translate the received certificate for the endpoint device to represent a privacy certificate authority;

sending, by the enrollment service, the certificate for the endpoint device to the discovery service;

sending, by the enrollment service, a notification of endpoint device registration to the policy service;

sending, by the policy service, a directive to add the endpoint device to a device management service; and

storing, by the discovery service, the issued endpoint device certificate in a local certificate store,

wherein the identity beacon includes a unique endpoint device identifier, endpoint device type, endpoint device make, and endpoint device model, wherein the endpoint device identifier is authenticated based on a multi-stage verified boot sequence of the endpoint device from power on, and

wherein the multi-stage verified boot sequence is performed by a multi-stage verified boot loader that verifies multiple sets of digital signatures associated with a signed program image on the endpoint device using multiple matching sets of public keys to verify digital signatures generated using corresponding private signing keys by an image signer.

2. The method of claim 1 , wherein the program image to be verified is at least one of: a first stage boot loader, a second stage boot loader, and an operating system loader on the endpoint device, wherein the multi-stage verified boot loader may be injected at any stage of the boot sequence.

3. The method of claim 1 , wherein the digital signatures are verified based on a logical AND or OR operator as a countermeasure to detect compromise of one or more public-private key pairs associated with the signing and verification process, wherein placement order of the digital signatures and signature match criteria is based on a signing specification.

4. The method of claim 3 , wherein the logical AND operation requires at least two unique digital signatures in the signed program image to be verified.

5. The method of claim 1 , wherein the multi-stage verified boot loader is injected into a boot sequence to forward verify a plurality of subsequent stage boot loaders, images, configuration and data files without requiring any modification to the subsequent stage boot loaders.

6. A non-transitory computer readable medium having stored thereon executable instructions that when executed by a processor of a computer control the computer to perform steps comprising:

sending, by the discovery agent on the endpoint device, to the discovery service on the gateway device, an authenticated identity beacon with an endpoint device profile;

verifying, by the discovery service, the authenticated identity beacon of the endpoint device and the endpoint device profile;

generating, by the discovery service, a certificate request for the endpoint device from a privacy certificate authority;

sending, by the discovery service, the certificate request for the endpoint device to the enrollment service;

processing, by the enrollment service, the certificate request for the endpoint device that is received in order to translate the certificate request for a certificate authority;

sending, by the enrollment service to the certificate authority, the translated certificate request for the endpoint device;

receiving, by the enrollment service, a certificate for the endpoint device issued by the certificate authority;

processing, by the enrollment service, the received certificate for the endpoint device in order to translate the received certificate for the endpoint device to represent a privacy certificate authority;

sending, by the enrollment service, the certificate for the endpoint device to the discovery service;

sending, by the enrollment service, a notification of endpoint device registration to the policy service;

sending, by the policy service, a directive to add the endpoint device to a device management service; and

storing, by the discovery service, the issued endpoint device certificate in a local certificate store,

wherein the identity beacon includes a unique endpoint device identifier, endpoint device type, endpoint device make, and endpoint device model, wherein the endpoint device identifier is authenticated based on a multi-stage verified boot sequence of the endpoint device from power on, and

wherein the multi-stage verified boot sequence is performed by a multi-stage verified boot loader that verifies multiple sets of digital signatures associated with a signed program image on the endpoint device using multiple matching sets of public keys to verify digital signatures generated using corresponding private signing keys by an image signer.

7. The non-transitory computer readable medium according to claim 6 , wherein the program image to be verified is at least one of: a first stage boot loader, a second stage boot loader, and an operating system loader on the endpoint device, wherein the multi-stage verified boot loader may be injected at any stage of the boot sequence.

8. The non-transitory computer readable medium according to claim 6 , wherein the digital signatures are verified based on a logical AND or OR operator as a countermeasure to detect compromise of one or more public-private key pairs associated with the signing and verification process, wherein placement order of the digital signatures and signature match criteria is based on a signing specification.

9. The non-transitory computer readable medium according to claim 8 , wherein the logical AND operation requires at least two unique digital signatures in the signed program image to be verified.

10. The non-transitory computer readable medium according to claim 6 , wherein the multi-stage verified boot loader is injected into a boot sequence to forward verify a plurality of subsequent stage boot loaders, images, configuration and data files without requiring any modification to the subsequent stage boot loaders.

11. A system for of device identification for enrollment and registration of an endpoint device, the system comprising:

a processor couple to a memory;

the processor executing the following agent and services;

a discovery agent on the endpoint device for sending, to a discovery service on a gateway device, an authenticated identity beacon with an endpoint device profile;

the discovery service for:

(1) verifying the authenticated identity beacon of the endpoint device and the endpoint device profile,

(2) generating a certificate request for the endpoint device from a privacy certificate authority, and

(3) sending the certificate request for the endpoint device to the enrollment service;

an enrollment service for:

(1) processing the certificate request for the endpoint device that is received in order to translate the certificate request for a certificate authority,

(2) sending, to the certificate authority, the translated certificate request for the endpoint device,

(3) receiving a certificate for the endpoint device issued by the certificate authority,

(4) processing the received certificate for the endpoint device in order to translate the received certificate for the endpoint device to represent a privacy certificate authority,

(5) sending the certificate for the endpoint device to the discovery service, and

(6) sending a notification of endpoint device registration to a policy service; and

the policy service for:

(1) sending a directive to add the endpoint device to a device management service, and

(2) storing the issued endpoint device certificate in a local certificate store,

wherein the identity beacon includes a unique endpoint device identifier, endpoint device type, endpoint device make, and endpoint device model, wherein the endpoint device identifier is authenticated based on a multi-stage verified boot sequence of the endpoint device from power on, and

wherein the multi-stage verified boot sequence is performed by a multi-stage verified boot loader that verifies multiple sets of digital signatures associated with a signed program image on the endpoint device using multiple matching sets of public keys to verify digital signatures generated using corresponding private signing keys by an image signer.

12. The system according to claim 11 , wherein the program image to be verified is at least one of: a first stage boot loader, a second stage boot loader, and an operating system loader on the endpoint device, wherein the multi-stage verified boot loader may be injected at any stage of the boot sequence.

13. The system according to claim 11 , wherein the digital signatures are verified based on a logical AND or OR operator as a countermeasure to detect compromise of one or more public-private key pairs associated with the signing and verification process, wherein placement order of the digital signatures and signature match criteria is based on a signing specification.

14. The system according to claim 13 , wherein the logical AND operation requires at least two unique digital signatures in the signed program image to be verified.

15. The system according to claim 11 , wherein the multi-stage verified boot loader is injected into a boot sequence to forward verify a plurality of subsequent stage boot loaders, images, configuration and data files without requiring any modification to the subsequent stage boot loaders.

Assignments (4)
FIRST LIEN INTELLECTUAL PROPERTY AGREEMENT SUPPLEMENT Recorded Sep 24, 2025
From: DIGICERT, INC.
To: HPS INVESTMENT PARTNERS, LLC, AS COLLATERAL AGENT
Reel/Frame 072947/0203 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT SUPPLEMENT Recorded Jul 30, 2025
From: DIGICERT, INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 072295/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 2, 2022
From: MOCANA CORPORATION
To: DIGICERT, INC.
Reel/Frame 058946/0369 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 27, 2018
From: KUMAR, SRINIVAS; GUPTA, ATUL; ULANOV, RUSLAN; UCHIL, SHREYA
To: MOCANA CORPORATION
Reel/Frame 046484/0738 →
Cited By (10)
US 12,254,435 US 12,261,838 US 12,294,583 US 12,301,563 US 12,309,262 US 12,368,580 US 12,463,802 US 12,470,372 US 12,476,793 US 12,639,507