IP Library Granted Patent US 11,425,124
Granted Patent B2
US 11,425,124 · App. 16/915,821 · Granted Aug 23, 2022

Method for cloud assisted authorization of IoT identity bootstrapping

Inventors: Bogdan Chifor (Nojorid, RO); George-Andrei Stanescu (Ilfov, RO); Radu Iorga (Bucharest, RO); Corneliu-Ilie Calciu (Bucharest, RO)
Assignee: LENOVO Enterprise Solutions (Singapore) PTE. LTD.
H04L63/0876H04L63/0823H04L63/0884H04L63/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,425,124
App. No.
16/915,821
Granted
Aug 23, 2022
Kind
B2
Abstract

A method for authorization of internet of things (“IoT”) identity bootstrapping includes receiving from a device, at a network access server (“NAS”) of a user and in response to an attestation request sent to the device, a vendor network address of a vendor server of a vendor and a device identifier for the device. The method includes authenticating the vendor using the vendor network address and, in response to authenticating the vendor, sending the device identifier to the vendor server. The method includes communicating device attestation packets between the vendor server and the device. The device attestation packets validate the device to the vendor server. The method includes receiving device attestation from the vendor server. The device attestation indicating validity status of the device to the NAS. The method includes, in response to the device attestation indicating validity of the device, transmitting a new device identity to the device.

Claims (35)

1. A method comprising:

receiving from a device, at a network access server (“NAS”) of a user and in response to an attestation request sent from the NAS to the device, a vendor network address of a vendor server of a vendor and a device identifier for the device, the device capable of connection to a computer network accessible by the NAS;

authenticating the vendor using the vendor network address;

in response to authenticating the vendor, sending the device identifier to the vendor server;

communicating device attestation packets between the vendor server and the device, contents of a payload of the device attestation packets are inaccessible to the NAS, the device attestation packets validating the device to the vendor server;

receiving device attestation from the vendor server, the device attestation indicating validity status of the device to the NAS; and

in response to the device attestation indicating validity of the device, transmitting a new device identity to the device,

wherein authenticating the vendor using the vendor network address comprises the NAS communicating with the vendor server using a security protocol and/or verifying a digital certificate of the vendor.

2. The method of claim 1 , wherein the device and the NAS communicate over a link layer and wherein the NAS and the vendor server communicate using an Internet protocol over a computer network.

3. The method of claim 1 , wherein the device is in a locked state and does not accept a new device identity prior to the vendor server validating the user to the device.

4. The method of claim 3 , wherein validating the user to the device comprises:

communicating user authorization packets between the vendor server and the device, contents of a payload of each user authorization packet are inaccessible to the NAS;

receiving notification from the device that the new device identity has been accepted by the device; and

proceeding with a network identity bootstrap process for the device.

5. The method of claim 4 , further comprising, in response to the vendor server communicating user non-authorization to the device, receiving notification from the device that the new device identity has not been accepted by the device, wherein the network identity bootstrap process for the device is halted.

6. The method of claim 1 , in response to the device attestation including an indication of invalidity of the device, preventing transmission of the new device identity to the device.

7. The method of claim 1 , wherein validating the device to the vendor server comprises the vendor server verifying that the device has a device identity known to the vendor server as a valid device identity.

8. The method of claim 1 , wherein the NAS comprises a network communication device connected to the Internet and a communication port connected to the device using a link layer protocol.

9. The method of claim 1 , wherein the vendor network address of the vendor server comprises a uniform resource identifier (“URI”).

10. A program product comprising a non-transitory computer readable storage medium with program code, the program code being configured to be executable by a processor to perform operations comprising:

receiving from a device, at a network access server (“NAS”) of a user and in response to an attestation request sent from the NAS to the device, a vendor network address of a vendor server of a vendor and a device identifier for the device, the device capable of connection to a computer network accessible by the NAS;

authenticating the vendor using the vendor network address;

in response to authenticating the vendor, sending the device identifier to the vendor server;

communicating device attestation packets between the vendor server and the device, contents of a payload of the device attestation packets are inaccessible to the NAS, the device attestation packets validating the device to the vendor server;

receiving device attestation from the vendor server, the device attestation indicating validity status of the device to the NAS; and

in response to the device attestation indicating validity of the device, transmitting a new device identity to the device,

wherein authenticating the vendor using the vendor network address comprises the NAS communicating with the vendor server using a security protocol and/or verifying a digital certificate of the vendor.

11. The program product of claim 10 , wherein the device is in a locked state and does not accept a new device identity prior to the vendor server validating the NAS to the device and wherein validating the NAS to the device comprises:

communicating user authorization packets between the vendor server and the device, contents of a payload of each user authorization packet are inaccessible to the NAS;

receiving notification from the device that the new device identity has been accepted by the device; and

proceeding with a network identity bootstrap process for the device.

12. The program product of claim 11 , wherein the program code being further configured to be executable by a processor to perform operations comprising:

in response to the vendor server communicating user non-authorization to the device, receiving notification from the device that the new device identity has not been accepted by the device, wherein the network identity bootstrap process for the device is halted; and

in response to the device attestation including an indication of invalidity of the device, preventing transmitting the new device identity to the device.

13. The program product of claim 10 , wherein the device and the NAS communicate over a link layer and wherein the NAS and the vendor server communicate using an Internet protocol over a computer network.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 20, 2025
From: LENOVO ENTERPRISE SOLUTIONS (SINGAPORE) PTE LTD.
To: LENOVO GLOBAL TECHNOLOGIES INTERNATIONAL LTD.
Reel/Frame 070267/0092 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 20, 2025
From: LENOVO GLOBAL TECHNOLOGIES INTERNATIONAL LIMITED
To: LENOVO GLOBAL TECHNOLOGIES SWITZERLAND INTERNATIONAL GMBH
Reel/Frame 070269/0207 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 9, 2020
From: CHIFOR, BOGDAN; STANESCU, GEORGE-ANDREI; IORGA, RADU; CALCIU, CORNELIU-ILIE
To: LENOVO ENTERPRISE SOLUTIONS (SINGAPORE) PTE. LTD.
Reel/Frame 053168/0408 →