IP Library Granted Patent US 11,621,832
Granted Patent B2
US 11,621,832 · App. 16/980,987 · Granted Apr 4, 2023

Configuration systems and methods for secure operation of networked transducers

Inventor: John A. Nix (Evanston, IL)
Assignee: IOT AND M2M TECHNOLOGIES, LLC
H04L9/0841G06F13/20H04L9/0861H04L9/3013H04L9/3247H04L9/3263H04L63/0435H04W12/03H04W12/06G16Y30/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,621,832
App. No.
16/980,987
Granted
Apr 4, 2023
Kind
B2
Abstract

A device can include an internal secure processing environment (SE) and communicate with a configuration system. The device may utilize a near field communications (NFC) radio. A mobile handset can connect with the SE in the device using NFC. The mobile handset can communicate with the configuration system and receive configuration data and a software package for the device. The SE can derive a PKI key pair and send the derived public key to the configuration system via the mobile handset. The SE and the configuration system can mutually derive an encryption key using the derived PKI key pair. The configuration data can be transmitted over the NFC radio, and the mobile handset can establish a Wi-Fi access point. The software package can be encrypted using the encryption key and transmitted to the device over the established Wi-Fi access point, thereby completing a configuration step for the device.

Claims (35)

1. A method for a device to securely receive, from a mobile handset, configuration data over a first wireless connection between the device and the mobile handset, the method performed by the device, the method comprising:

a) storing a first device private key for an elliptic curve Diffie-Hellman (ECDH) key exchange algorithm, a second device private key for a digital signature algorithm, an authentication token, and a first set of cryptographic parameters, wherein the first device private key corresponds to a first device public key, and wherein the second device private key corresponds to a second device public key;

b) recording on the device a QR code for reading by the mobile handset, the QR code comprising the authentication token;

c) establishing the first wireless connection with the mobile handset, wherein the first wireless connection is encrypted;

d) receiving via the first wireless connection and from the mobile handset, (i) a first server public key for a first server (ii) a second set of cryptographic parameters, and (iii) a random number;

e) authenticating (i) a signature received from the mobile handset using at least the authentication token, and (ii) the device using at least the received random number and the second device private key;

f) deriving a first symmetric ciphering key using at least (i) the first device private key and the first server public key, (ii) the ECDH key exchange algorithm, and (iii) the first set of cryptographic parameters;

g) deriving a third device private key and a third device public key using the second set of cryptographic parameters;

h) generating a device digital signature over at least the third device public key using the second device private key;

i) encrypting at least the derived third device public key and a list of root certificates for the device into a first ciphertext using the derived first symmetric ciphering key;

j) sending, via the first wireless connection and to the mobile handset, the first ciphertext and the device digital signature;

k) receiving, via the first wireless connection and from the mobile handset, a second ciphertext comprising (i) a device certificate for the derived third device public key and (ii) a certificate authority (CA) certificate for a second server, wherein the device decrypts the second ciphertext using at least the first symmetric ciphering key; and

l) establishing a second wireless connection to the second server, wherein the device authenticates the second server using the CA certificate, and wherein the device uses the received device certificate and the derived third device private key in order to authenticate over the second wireless connection.

2. The method of claim 1 , wherein the device does not transmit the authentication token through the first wireless Connection.

3. The method of claim 1 , wherein a secure element in the device stores the device certificate and the CA certificate in nonvolatile memory.

4. The method of claim 1 , wherein the device uses the first device private key for the ECDH key exchange algorithm and the second device private key for the digital signature algorithm.

5. The method of claim 1 , further comprising in step f), deriving the first symmetric ciphering key using a key derivation function, wherein the first symmetric ciphering key comprises data for encrypting the first ciphertext and decrypting the second ciphertext.

6. The method of claim 1 , further comprising:

m) receiving, from the second wireless connection, a second server public key for a third set of cryptographic parameters;

n) deriving a second symmetric ciphering key using (i) the derived third device private key the second server public key, (ii) the ECDH key exchange algorithm, and (iii) the third set of cryptographic parameters; and

o) receiving a third ciphertext of a device configuration, wherein the second ciphertext is decrypted by the device using the derived second symmetric ciphering key.

7. The method of claim 6 , wherein the device configuration includes a set of network parameters, and wherein the device authenticates with a wireless access network using the set of network parameters.

8. The method of claim 6 , wherein the device configuration includes at least one file for the device, wherein the at least one file is used by the device with at least one of a device operating system, a device reporting application, a secure element firmware, a secure element operating system, a transducer library, and a configuration test vector.

9. The method of claim 3 , wherein the secure element sends and receives through the device using an external bus controller for the secure element, wherein the device and the secure element are connected via a data bus, and wherein the device communicates with the mobile handset and the second server through a radio.

10. The method of claim 1 , wherein the first set of cryptographic parameters specifies at least a first elliptic curve defining equation, and wherein the second set of cryptographic parameters specifies at least a second elliptic curve defining equation.

11. The method of claim 1 , wherein the authentication token comprises a random number for the QR code.

12. The method of claim 3 , wherein the secure element includes a hardware random number generator, and wherein the hardware random number generator uses at least a transducer measurement in order to generate a device random number, and wherein the secure element uses the device random number to derive the third private key.

13. The method of claim 1 , wherein the device receives via the first wireless connection, (i) the first server public key for the first server (ii) the second set of cryptographic parameters, and (iii) the random number with a server digital signature, and wherein the device authenticates the server digital signature using at least the authentication token.

14. The method of claim 1 , wherein the device authenticates the device (i) using the received random number and the second device private key, and (ii) sending the second device public key with an authenticating digital signature.

15. The method of claim 1 , wherein the first wireless connection uses one of “Near Field Communications” (NFC) Bluetooth, and Wi-Fi technology.

16. The method of claim 1 , wherein the device derives the first device private key after establishing the first wireless connection, and wherein the device stores the first device private key after deriving the first device private key.

17. The method of claim 1 , wherein the second set of cryptographic parameters specifies values for algorithms associated with a key encapsulation mechanism, and wherein the algorithms comprise one of lattice-based cryptography, code-based cryptography, and supersingular elliptic curve isogeny cryptography.

18. The method of claim 1 , wherein the third device public key supports at least one of lattice-based cryptography, code-based cryptography, supersingular elliptic curve isogeny cryptography, and elliptic curve cryptography.

19. The method of claim 6 , wherein the device configuration includes at least one file for secure element, wherein the at least one file is used by the secure element with at least one of a secure element firmware, a secure element operating system, a transducer library, and a configuration test vector.

20. The method of claim 1 , wherein the device derives the third public key before the device authenticates the second server.

Assignments (4)
CHANGE OF ADDRESS Recorded Sep 10, 2025
From: NETWORK-1 TECHNOLOGIES, INC.
To: NETWORK-1 TECHNOLOGIES, INC.
Reel/Frame 072827/0540 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 7, 2025
From: IOT AND M2M TECHNOLOGIES, LLC
To: NETWORK-1 TECHNOLOGIES, INC.
Reel/Frame 070752/0719 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 4, 2025
From: VOBAL TECHNOLOGIES, LLC
To: IOT AND M2M TECHNOLOGIES, LLC
Reel/Frame 070736/0052 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 15, 2020
From: NIX, JOHN A.
To: IOT AND M2M TECHNOLOGIES, LLC
Reel/Frame 053774/0022 →
Continuity (2)
Provisional Application 62644195 · Mar 16, 2018
Related Publication 20210211279A1 · Jul 8, 2021
Cited By (2)
US 12,562,924 US 12,689,510