IP Library Granted Patent US 10,390,227
Granted Patent B2
US 10,390,227 · App. 16/108,027 · Granted Aug 20, 2019

Authentication of a gateway device in a sensor network

Inventors: John Bicket (San Francisco, CA); James Michael Rowson (San Francisco, CA); Chase Phillips (San Francisco, CA)
Assignee: Samsara Networks Inc.
H04W12/06H04L12/66H04L63/0428H04L63/0823H04W4/38H04W4/70H04W4/80H04W12/02H04W12/04H04W28/085H04W84/18G06F2221/2151
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,390,227
App. No.
16/108,027
Granted
Aug 20, 2019
Kind
B2
Abstract

A set of certificates are received at a gateway device from a management server, where each one of the certificates was generated by the management server upon determination that the gateway device is associated with a respective wireless sensing device (WSD). The gateway device receives from a first WSD an advertisement message indicating it is available for connecting to a gateway device. In response to confirming based on a first certificate of the set of certificates associated with the first WSD, that it is authorized to connect to the WSD, the gateway device transmits to the first WSD the first certificate and an identifier of the gateway device for enabling authentication of the gateway device at the WSD. The gateway device receives data from the first WSD, upon confirmation at the WSD that it is authorized to connect with the gateway device.

Claims (20)

1. A method in a gateway device, the method comprising:

receiving, from a management server, a set of one or more certificates, wherein each one of the set of certificates was generated by the management server upon a determination that the gateway device is associated with a respective one of a set of one or more wireless sensing devices, and wherein each one of the set of certificates is a digital document including data and a digital signature generated by the management server based on the data and a private key of the management server, and wherein the data of each one of the set of certificates includes a first identifier and a second identifier, wherein the first identifier matches a gateway identifier of the gateway device;

receiving from a first of the set of wireless sensing devices an advertisement message indicating it is available for connecting to a gateway device;

in response to confirming, based on a first certificate of the set of certificates associated with the first wireless sensing device, that the gateway device is authorized to connect to the first wireless sensing device, transmitting to the first wireless sensing device the first certificate; and

receiving data from the first wireless sensing device, upon confirmation at the first wireless sensing device that the first wireless sensing device is authorized to connect with the gateway device based on the first certificate, wherein the data is indicative of a plurality of sensor measurements taken over time and is to be transmitted to the management server, wherein the plurality of sensor measurements are representative of physical events detected at the wireless sensing device.

2. The method of claim 1 , wherein the first certificate is transmitted over a secure communication channel between the gateway device and the first wireless sensing device.

3. The method of claim 2 , wherein the secure communication channel between the gateway device and the first wireless sensing device is established using a shared secret stored in both the first wireless sensing device and the gateway device at the time of manufacture.

4. The method of claim 1 , wherein the determination that the gateway device and the first wireless sensing device are associated includes a determination that the gateway device and the first wireless sensing device are associated with a same organization identifier from a plurality of organization identifiers as a result of being claimed by a same organization from a plurality of organizations.

5. The method of claim 1 , wherein data of the first certificate further includes a public key of the gateway device, and the method further comprises, prior to the transmitting to the first wireless sensing device the first certificate, generating a second digital signature based upon the first certificate with a private key of the gateway device and transmitting the certificate with the second digital signature to be used by the first wireless sensing device for the confirmation at the first wireless sensing device that the first wireless sensing device is authorized to upload data to the gateway device and causing the receiving of the data from the first wireless sensing device.

6. A gateway device to be coupled with a wireless sensing device of a sensor network, wherein the sensor network includes a management server, the gateway device comprising:

a communication interface to receive, from a management server, a set of one or more certificates, wherein each one of the set of certificates was generated by the management server upon a determination that the gateway device is associated with a respective one of a set of one or more wireless sensing devices, and wherein each one of the set of certificates is a digital document including data and a digital signature generated by the management server based on the data and a private key of the management server, and wherein the data of each one of the set of certificates includes a first identifier and a second identifier, wherein the first identifier matches a gateway identifier of the gateway device;

a non-transitory computer readable storage medium to store instructions; and

a processor coupled with the non-transitory computer readable storage medium to process the stored instructions to:

receive from a first of the set of wireless sensing devices an advertisement message indicating it is available for connecting to a gateway device,

in response to confirming, based on a first certificate of the set of certificates associated with the first wireless sensing device, that the gateway device is authorized to connect to the first wireless sensing device, transmit through the communication interface to the first wireless sensing device the first certificate, and

receive, through the communication interface, data from the first wireless sensing device, upon confirmation at the first wireless sensing device that the first wireless sensing device is authorized to connect with the gateway device based on the first certificate, wherein the data is indicative of a plurality of sensor measurements taken over time and is to be transmitted to the management server, wherein the plurality of sensor measurements are representative of physical events detected at the wireless sensing device.

7. The gateway device of claim 6 , wherein the first certificate is transmitted over a secure communication channel between the gateway device and the first wireless sensing device.

8. The gateway device of claim 7 , wherein the secure communication channel between the gateway device and the first wireless sensing device is established using a shared secret stored in both the first wireless sensing device and the gateway device at the time of manufacture.

9. The gateway device of claim 6 , wherein the determination that the gateway device and the first wireless sensing device are associated includes a determination that the gateway device and the first wireless sensing device are associated with a same organization identifier from a plurality of organization identifiers as a result of being claimed by a same organization from a plurality of organizations.

10. The gateway device of claim 6 , wherein data of the first certificate further includes a public key of the gateway device, and the processor is further to, prior to transmit to the first wireless sensing device the first certificate, generate a second digital signature based upon the first certificate with a private key of the gateway device and to transmit the certificate with the second digital signature to be used by the wireless sensing device for the confirmation at the first wireless sensing device that the first wireless sensing device is authorized to upload data to the gateway device and to cause the receiving of the data from the first wireless sensing device.

Assignments (2)
CHANGE OF NAME Recorded Jul 15, 2022
From: SAMSARA NETWORKS INC.
To: SAMSARA INC.
Reel/Frame 060679/0009 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 21, 2018
From: BICKET, JOHN; ROWSON, JAMES MICHAEL; PHILLIPS, CHASE
To: SAMSARA NETWORKS INC.
Reel/Frame 046655/0074 →
Continuity (4)
Division 15243676 · Aug 22, 2016
Continuation 14960866 · Dec 7, 2015
Provisional Application 62263563 · Dec 4, 2015
Related Publication 20190075459A1 · Mar 7, 2019
Cited By (37)
US 12,197,610 US 12,213,090 US 12,228,944 US 12,253,617 US 12,256,021 US 12,260,616 US 12,269,498 US 12,289,181 US 12,306,010 US 12,327,445 US 12,328,639 US 12,344,168 US 12,346,712 US 12,367,718 US 12,368,903 US 12,426,007 US 12,445,285 US 12,450,329 US 12,479,446 US 12,488,635 US 12,501,178 US 12,511,947 US 12,524,314 US 12,534,097 US 12,561,624 US 12,565,143 US 12,568,348 US 12,581,415 US 12,626,200 US 12,630,050 US 12,646,402 US 12,651,529 US 12,662,152 US 12,665,989 US 12,671,464 US 12,675,419 US 12,701,004