IP Library Granted Patent US 11,616,654
Granted Patent B2
US 11,616,654 · App. 16/392,816 · Granted Mar 28, 2023

Secure provisioning of internet of things devices, including electronic locks

Inventor: James Creighton Hart (Huntington Beach, CA)
Assignee: Spectrum Brands, Inc.
H04L9/3268E05B45/06E05B47/0001H04L9/3073E05Y2900/132
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,616,654
App. No.
16/392,816
Granted
Mar 28, 2023
Kind
B2
Abstract

Methods and systems for configuring a security device, such as an electronic lock, are disclosed. In particular, the present disclosure describes methods and systems for provisioning a lock with a certificate such that any change to the lock, or changes to lock-server communication characteristics, can be detected and (optionally) prevented. As such, security of such devices is improved.

Claims (47)

1. A method of configuring an electronic lock comprising:

generating a public-private key pair at a cryptographic circuit included in the electronic lock;

transmitting a certificate signing request to a certificate signer, the certificate signing request including a plurality of attributes of the electronic lock;

receiving a signed certificate from the certificate signer, the signed certificate including cryptographic data reflecting the plurality of attributes in the certificate signing request and being signed using a certificate affiliated with a manufacturer of the electronic lock;

configuring the signed certificate with a target server endpoint;

connecting the electronic lock to a server at the target server endpoint; and

after receiving acknowledgement from the server, storing, in the cryptographic circuit, the cryptographic data received from the certificate signer and the target server endpoint, using a one-time write command, wherein the one-time write command locks the cryptographic circuit after storing the cryptographic data and affixes, at the electronic lock, an association between the electronic lock, the manufacturer of the electronic lock, and the target server endpoint, thereby preventing the cryptographic circuit from overwriting the cryptographic data and wherein the cryptographic data includes a certificate signing request of the electronic lock, a certificate of the manufacturer of the electronic lock, and data identifying the target server endpoint.

2. The method of claim 1 , wherein connecting the electronic lock to the server includes transmitting the signed certificate to the server.

3. The method of claim 2 , further comprising:

after storing the cryptographic data in the cryptographic circuit, transmitting a connection request from the electronic lock to the server, the connection request including a recalculated version of the signed certificate generated by the cryptographic circuit; and

based on the recalculated version of the signed certificate corresponding to the signed certificate at the server, authenticating the electronic lock at the server.

4. The method of claim 2 , further comprising storing the signed certificate in a secure storage of the electronic lock.

5. The method of claim 1 , further comprising, at the certificate signer, signing the certificate with a signature of the manufacturer of the electronic lock.

6. The method of claim 1 , wherein connecting to the server at the target server endpoint comprises:

forming a secured connection to the server at the target server endpoint;

based on the server determining that the electronic lock was not previously registered at the server, performing a device registration process, the device registration process including creation of a plurality of server objects defining a virtual electronic lock record associated with the electronic lock.

7. The method of claim 6 , wherein the plurality of server objects includes a virtual device and a policy, and wherein the signed certificate is stored in association with the virtual device and the policy at the server.

8. The method of claim 6 , wherein the device registration process further includes determining whether the electronic lock is authorized to be registered at the server.

9. The method of claim 1 , wherein receiving the signed certificate includes a certificate name, an issuer identifier associated with a manufacturer of the electronic lock, a serial number of the electronic lock, and validity data.

10. An electronic lock comprising:

a processing unit;

a locking bolt movable between a locked and unlocked position;

a motor actuatable by the processing unit to move the locking bolt between the locked and unlocked positions;

a wireless communication interface operatively connected to the processing unit; and

a cryptographic circuit having a one-time write function to store cryptographic information that is generated based on a plurality of attributes of the electronic lock and information identifying a target server endpoint, the one-time write function locking the cryptographic circuit after storing the cryptographic information and affixing, at the electronic lock, an association between the electronic lock, a manufacturer of the electronic lock, and the target server endpoint, thereby preventing the cryptographic circuit from overwriting the cryptographic data and wherein the cryptographic data includes a certificate signing request of the electronic lock, a certificate of the manufacturer of the electronic lock, and data identifying the target server endpoint; and

a memory operatively connected to the processing unit and storing computer-executable instructions which, when executed by the processing unit, cause the processing unit to:

upon initiating communication with a server identified by the cryptographic information, transmitting, via the wireless communication interface, a certificate to the server that is generated based on the cryptographic information.

11. The electronic lock of claim 10 , wherein the certificate comprises a signed certificate received from a certificate signer associated with a manufacturer of the electronic lock.

12. The electronic lock of claim 11 , wherein the certificate signer comprises a cloud provisioning server.

13. The electronic lock of claim 10 , wherein transmitting the certificate to the server validates that, prior to communication with the server, the electronic lock is authorized to communicate with the server and has not been tampered with.

14. A method of configuring a server account associated with an electronic lock, the method comprising:

receiving a first secure connection request from an electronic lock, the first secure connection request including a certificate generated by the electronic lock and including a plurality of attributes of the electronic lock;

based on the server determining, from the certificate information, that the electronic lock is authorized to communicate with the server but has no corresponding server record:

determining whether the electronic lock is an authorized electronic lock by comparing an identifier of the electronic lock received in the certificate to a permission list;

establishing a virtual device and a policy at the server;

associating the policy with the virtual device;

associating the certificate with the policy;

activating the certificate; and

transmitting an acknowledgement of activation of the certificate to the electronic lock;

receiving a second secure connection request from the electronic lock after a connection to the electronic lock based on the first secure connection request is terminated, the second secure connection request including an instance of the certificate generated at the time of the second secure connection request; and

confirming that the electronic lock is authorized to communicate with the server, thereby causing the electronic lock to store cryptographic data used to create the certificate and target server information identifying the server into a cryptographic circuit of the electronic lock using a one-time write command, the one-time write command locking the cryptographic circuit of the electronic lock after storing the cryptographic data and affixing, at the electronic lock, an association between the electronic lock, a manufacturer of the electronic lock, and the server.

15. The method of claim 14 , further comprising:

based on the server determining, from the certificate information, that the electronic lock is authorized to communicate with the server and has been registered at the server, authorizing communication with the electronic lock.

16. The method of claim 14 , further comprising:

based on the server determining, from the certificate information, that the electronic lock is not authorized to communicate with the server and has not been registered at the server, generating a tamper alarm.

17. The method of claim 16 , wherein the tamper alarm is addressed to an owner user of the electronic lock and comprises at least one of an email, a text message, an automated voice message, or an application notification.

18. The method of claim 16 , wherein the tamper alarm is addressed to an administrator of the server.

Assignments (6)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2023
From: SPECTRUM BRANDS, INC.
To: ASSA ABLOY AMERICAS RESIDENTIAL INC.
Reel/Frame 065658/0105 →
RELEASE OF SECURITY INTEREST Recorded Jun 20, 2023
From: ROYAL BANK OF CANADA
To: SPECTRUM BRANDS, INC.
Reel/Frame 064029/0313 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 12, 2022
From: HART, JAMES CREIGHTON
To: SPECTRUM BRANDS, INC.
Reel/Frame 061390/0841 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 6, 2021
From: HART, JAMES CREIGHTON
To: SPECTRUM BRANDS, INC.
Reel/Frame 054826/0601 →
NOTICE OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Jul 31, 2020
From: GLOFISH LLC; SPECTRUM BRANDS, INC.; SPECTRUM BRANDS PET GROUP INC.; SPECTRUM BRANDS PET LLC
To: ROYAL BANK OF CANADA
Reel/Frame 053375/0416 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 24, 2019
From: HART, CREIGHTON
To: SPECTRUM BRANDS, INC.
Reel/Frame 048979/0170 →
Cited By (1)
US 12,567,295