IP Library Granted Patent US 10,657,261
Granted Patent B2
US 10,657,261 · App. 16/180,200 · Granted May 19, 2020

System and method for recording device lifecycle transactions as versioned blocks in a blockchain network using a transaction connector and broker service

Inventors: Srinivas Kumar (Cupertino, CA); Atul Gupta (Sunnyvale, CA); Ruslan Ulanov (Dublin, CA); Shreya Uchil (Millbrae, CA)
Assignee: MOCANA CORPORATION
G06F21/575G06F8/65G06F9/4401G06F9/445G06F16/1834G06F16/27H04L9/0643H04L9/0825H04L9/0877H04L9/0891H04L9/3239H04L9/3247H04L9/3263H04L9/3297H04L12/66H04L41/08H04L63/0823H04L63/12H04L2209/38
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,657,261
App. No.
16/180,200
Granted
May 19, 2020
Kind
B2
Abstract

A method of building a device historian, across a supply chain of device manufactures and managers, by a plurality of device management services comprising an enrollment service, an update service, a policy service, and an analytics service, a transaction connector, a blockchain broker service participating as a node in a blockchain network, and transaction filters. The method comprises sending, by the plurality of device management services a transaction record over the transaction connector to the blockchain broker service, receiving, by the blockchain broker service, the transaction record, filtering, by the blockchain broker service, information in the transaction record based on the transaction filters, preparing, by the blockchain broker service, a versioned block based on the filtered information from the transaction record, and adding, by the blockchain broker service, the versioned block to the blockchain network.

Claims (28)

1. A method of updating a device, that has been authenticated with an immutable device unique identifier generated using device attributes discovered by an update client on the device, an update service in a supply chain network of providers and publishers, orchestration rules, a local ledger, and a blockchain broker service, the method comprising:

authenticating, by the update service, the device using a device unique registration issued by the update service associated with the immutable device unique identifier;

sending, by the update client on the device, a device request for an update package for the device from the update service in the supply chain network, wherein the device request from the authenticated device includes a device manifest and discovered device attributes, and wherein the discovered device attributes comprises of static factory configured settings and dynamically configured properties;

receiving, by the update service, the device request;

processing, by the update service, the received device request using the orchestration rules to prepare update packages, initially signed and encrypted by providers in the supply chain, for the device based on the device manifest and device attributes;

preparing, by the update service, by re-signing and re-encrypting the update package, as the publisher in the supply chain, based on the orchestration rules established for a network service of the supply chain network;

sending, by the update service, the doubly signed and reencrypted update package to the device; and

recording, by the update service, a request log for the device as an entry in the local ledger, and distributing blocks of transaction records to the blockchain broker service to maintain a distributed ledger to reproduce history of update packages sent to a plurality of devices by a plurality of publishers in the supply chain.

2. The method of claim 1 , wherein the request log for the device is doubly signed and reencrypted and includes at least a request counter, request operation data, a request nonce, a device request signature, a request hash, a device signature, a device certificate identifier, a publisher signature, a publisher certificate identifier, a publisher package identifier, a device identifier based on the discovered dynamic device attributes and a publisher identifier.

3. The method of claim 2 , wherein the distributed ledger in the blockchain broker service has adequate transaction records to reproduce a history of device updates and service transactions for cross domain traceability to the supply chain network of providers and publishers.

4. A method of updating a device, that has been authenticated with an immutable device unique identifier generated using dynamic device attributes discovered by an update client on the device, a plurality of providers of update packages, an update service of a plurality of publishers in a supply chain network of providers and publishers, orchestration rules, a local ledger, and a blockchain broker service, the method comprising:

authenticating, by the update service, the device using a device unique registration issued by the update service associated with the immutable device unique identifier;

sending, by the update client on the device, a device request for an update package for the device from the update service in the supply chain network, wherein the device request from the authenticated device includes a device manifest and discovered device attributes, and wherein the discovered device attributes comprises of static factory configured settings and dynamically configured properties;

receiving, by the update service, the device request;

processing, by the update service, the received device request using the orchestration rules to prepare update packages, initially signed and encrypted by providers in the supply chain, for the device based on the device manifest and device attributes;

preparing, by the update service, by re-signing and re-encrypting the update package, as the publisher in the supply chain, based on the orchestration rules established for a network service of the supply chain network;

sending, by the update service, the doubly signed and reencrypted update package to the device; and

recording, by the update service, a request log for the device as an entry in the local ledger, and distributing blocks of transaction records to the blockchain broker service to maintain a distributed ledger to reproduce history of provider packages sent to a plurality of authenticated devices by a plurality of providers and publishers in the supply chain.

5. The method of claim 4 , wherein the request log for the device is doubly signed and reencrypted and includes at least a request counter, request operation data, a request nonce, a device request signature, a request hash, a device signature, a device certificate identifier, a publisher signature, a publisher certificate identifier, a publisher package identifier, a device identifier based on the discovered dynamic device attributes, a publisher identifier, and a provider package identifier.

6. The method of claim 5 , wherein the distributed ledger in the blockchain broker service has adequate transaction records to reproduce a history of device updates and service transactions for cross domain traceability to a supply chain of update package providers.

7. A method of updating a device, that has been authenticated with an immutable device unique identifier generating using device attributes discovered by an update client on the device, an update service in a supply chain network of providers and publishers, orchestration rules, a local ledger, and a blockchain broker service, the method comprising:

authenticating, by the update service, the device using a device unique registration issued by the update service associated with the immutable device unique identifier;

sending, by the update client, a device request for an update package for the device from the update service in the supply chain network, wherein the device request from the authenticated device includes a device manifest and discovered device attributes comprising static factory configured settings and dynamically configured properties;

receiving, by the update service, the device request and authenticating the device;

processing, by the update service, the received device request using the orchestration rules to prepare update packages, initially signed and encrypted by providers in the supply chain, for the device based on the device manifest and device attributes;

preparing, by the update service, by re-signing and re-encrypting the update package, as the publisher in the supply chain, based on the orchestration rules established for a network service of the supply chain network;

sending, by the update service, the doubly signed and reencrypted update package to the device; and

recording, by the update service, a request log for the device as an entry in the local ledger, and distributing blocks of transaction records to the blockchain broker service to maintain a distributed ledger to reproduce history of the device, wherein the request log includes a publisher identifier or a provider identifier.

Assignments (4)
FIRST LIEN INTELLECTUAL PROPERTY AGREEMENT SUPPLEMENT Recorded Sep 24, 2025
From: DIGICERT, INC.
To: HPS INVESTMENT PARTNERS, LLC, AS COLLATERAL AGENT
Reel/Frame 072947/0203 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT SUPPLEMENT Recorded Jul 30, 2025
From: DIGICERT, INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 072295/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 2, 2022
From: MOCANA CORPORATION
To: DIGICERT, INC.
Reel/Frame 058946/0369 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 5, 2018
From: KUMAR, SRINIVAS; GUPTA, ATUL; ULANOV, RUSLAN; UCHIL, SHREYA
To: MOCANA CORPORATION
Reel/Frame 047409/0209 →
Cited By (10)
US 12,221,068 US 12,254,435 US 12,261,838 US 12,301,563 US 12,309,262 US 12,368,580 US 12,463,802 US 12,470,372 US 12,476,793 US 12,684,000