IP Library Granted Patent US 11,606,210
Granted Patent B1
US 11,606,210 · App. 17/124,982 · Granted Mar 14, 2023

Secure activation, service mode access and usage control of IOT devices using bearer tokens

Inventor: Neil Edward Madden (Stroud, GB)
Assignee: ForgeRock, Inc.
H04L9/3213H04L9/0891H04L9/3242H04L9/50H04L2209/84
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,606,210
App. No.
17/124,982
Granted
Mar 14, 2023
Kind
B1
Abstract

The disclosed technology teaches providing limited usage of a first device that includes local resources for verifying authenticity of a Macaroon access token with caveats (MATwC), a unique key and a local proximity interface. A second device used by the service technician receives the MATwC, establishes a connection with the first device over the local proximity interface using the MATwC, and sends a request to enter limited usage mode. The MATwC originated with an authentication server as a MAT, using the unique key of the first device and modified by appending caveats that narrowed authorization provided by the MAT with the limited usage mode, and applied a message authentication code chaining algorithm to sign a resulting the MATwC. The first device performs local authentication of the MATwC, evaluating the appended caveats and enters the limited usage mode consistent with the appended caveats, without requiring connected resources to authenticate the MATwC.

Claims (87)

1. A method of activating a service mode of a first device, wherein:

the first device includes local resources for verifying authenticity of a Macaroon access token with caveats (MATwC), including a unique key stored in memory of the first device and a local proximity interface for receiving the MATwC;

the method including:

the first device accepting a connection with a second device over the local proximity interface and receiving from the second device a request to enter the service mode, the request including a MATwC;

wherein the MATwC

originated with an authorization server (AS) as a Macaroon access token (MAT) using the unique key of the first device; and

the MAT was modified by appending one or more caveats that narrowed authorization provided by the MAT with at least an expiration time and date, and applied a message authentication code (MAC) chaining algorithm to sign a resulting MAT with caveats (MATwC); and

the first device performing local authentication of the MATwC, evaluating the appended caveats and determining that the expiration time and date have not passed, and entering the service mode as requested and consistent with the appended caveats, without requiring connected resources to authenticate the MATwC.

2. The method of claim 1 , further including the Macaroon access token being compatible with OAuth 2.0 or OAuth 2.1.

3. The method of claim 1 , further including evaluating the appended caveats and determining that limited service is authorized and entering the service mode with limited service availability.

4. A tangible non-transitory computer readable storage media, including program instructions loaded into memory that, when executed on processors cause the processors to implement a method of activating a service mode of a first device, the method including:

the first device includes local resources for verifying authenticity of a Macaroon access token with caveats (MATwC), including a unique key stored in memory of the first device and a local proximity interface for receiving the MATwC;

the method including:

the first device accepting a connection with a second device over the local proximity interface and receiving from the second device a request to enter the service mode, the request including a MATwC;

wherein the MATwC

originated with an authorization server (AS) as a Macaroon access token (MAT) using the unique key of the first device; and

the MAT was modified by appending one or more caveats that narrowed authorization provided by the MAT with at least an expiration time and date, and applied a message authentication code (MAC) chaining algorithm to sign a resulting MAT with caveats (MATwC); and

the first device performing local authentication of the MATwC, evaluating the appended caveats and determining that the expiration time and date have not passed, and entering the service mode as requested and consistent with the appended caveats, without requiring connected resources to authenticate the MATwC.

5. The tangible non-transitory computer readable storage media of claim 4 , wherein the first device is a vehicle, further including evaluating the appended caveats, determining that authority to drive the vehicle while in the service mode is restricted to limited travel area, and entering the service mode with the limited travel area.

6. A system for activating a service mode of a first device, the system including a processor, memory coupled to the processor and program instructions from the non-transitory computer readable storage media of claim 4 loaded into the memory.

7. A method of activating a service mode of a first device, wherein:

the first device includes local resources for verifying authenticity of a Macaroon access token with caveats (MATwC), including a unique key stored in memory of the first device and a local proximity interface for receiving the MATwC;

the method including:

a second device used by a service technician receiving the MATwC;

the second device establishing a connection with the first device over the local proximity interface and sending a request to enter the service mode, the request including the MATwC;

wherein the MATwC

originated with an authorization server (AS) as a Macaroon access token (MAT) using the unique key of the first device; and

the MAT was modified by appending one or more caveats that narrowed authorization provided by the MAT with at least an expiration time and date, and applied a message authentication code (MAC) chaining algorithm to sign a resulting the MATwC; and

the first device performing local authentication of the MATwC, evaluating the appended caveats and determining that the expiration time and date have not passed, and entering the service mode as requested and consistent with the appended caveats, without requiring connected resources to authenticate the MATwC.

8. The method of claim 7 , wherein the first device is a vehicle, wherein the caveats provide a limited travel area, whereby the authority to enter the service mode is restricted to limited travel area.

9. The method of claim 7 , further including a third device, positioned before the second device and the first device, receiving the MATwC, delegating service of the first device to the service technician from among a pool of technicians, and participating in forwarding of the MATwC to the second device.

10. A tangible non-transitory computer readable storage media, including program instructions loaded into memory that, when executed on processors cause the processors to implement a method of activating a service mode of a first device, the method including:

the first device includes local resources for verifying authenticity of a Macaroon access token with caveats (MATwC), including a unique key stored in memory of the first device and a local proximity interface for receiving the MATwC;

the method including:

a second device used by a service technician receiving the MATwC;

the second device establishing a connection with the first device over the local proximity interface and sending a request to enter the service mode, the request including the MATwC;

wherein the MATwC

originated with an authorization server (AS) as a Macaroon access token (MAT) using the unique key of the first device; and

the MAT was modified by appending one or more caveats that narrowed authorization provided by the MAT with at least an expiration time and date, and applied a message authentication code (MAC) chaining algorithm to sign a resulting the MATwC; and

the first device performing local authentication of the MATwC, evaluating the appended caveats and determining that the expiration time and date have not passed, and entering the service mode as requested and consistent with the appended caveats, without requiring connected resources to authenticate the MATwC.

11. The tangible non-transitory computer readable storage media of claim 10 , further including evaluating the appended caveats and determining that limited service is authorized and entering the service mode with limited service availability.

12. A system for activating a service mode of a first device, the system including a processor, memory coupled to the processor and program instructions from the non-transitory computer readable storage media of claim 10 loaded into the memory.

13. The system of claim 12 , wherein the first device is a vehicle, wherein the caveats provide a limited travel area, whereby the authority to enter the service mode is restricted to limited travel area.

14. A method of providing limited usage of a first device, wherein:

the first device includes local resources for verifying authenticity of a Macaroon access token with caveats (MATwC), including a unique key stored in memory of the first device and a local proximity interface for receiving the MATwC;

the method including:

the first device accepting a connection with a second device over the local proximity interface and receiving from the second device a request to enter a limited usage mode, the request including a Macaroon access token with caveats (MATwC);

wherein the MATwC

originated with an authorization server (AS) as a Macaroon access token (MAT) using the unique key of the first device; and

the MAT was modified by appending one or more caveats that narrowed authorization provided by the MAT with the limited usage mode, and applied a message authentication code (MAC) chaining algorithm to sign a resulting MAT with caveats (MATwC); and

the first device performing local authentication of the MATwC, evaluating the appended caveats and entering the limited usage mode as requested and consistent with the appended caveats, without requiring connected resources to authenticate the MATwC.

15. The method of claim 14 , wherein the first device is a vehicle, further including evaluating the caveats as providing one or more of a limited travel distance authorization and a limited maximum speed authorization, and entering one or more of the limited usage mode restricted to the limited travel distance and the limited usage mode restricted to the limited maximum speed.

16. A tangible non-transitory computer readable storage media, including program instructions loaded into memory that, when executed on processors cause the processors to implement a method of providing limited usage of a first device, the method including:

the first device includes local resources for verifying authenticity of a Macaroon access token with caveats (MATwC), including a unique key stored in memory of the first device and a local proximity interface for receiving the MATwC;

the method including:

the first device accepting a connection with a second device over the local proximity interface and receiving from the second device a request to enter a limited usage mode, the request including a Macaroon access token with caveats (MATwC);

wherein the MATwC

originated with an authorization server (AS) as a Macaroon access token (MAT) using the unique key of the first device; and

the MAT was modified by appending one or more caveats that narrowed authorization provided by the MAT with the limited usage mode, and applied a message authentication code (MAC) chaining algorithm to sign a resulting MAT with caveats (MATwC); and

the first device performing local authentication of the MATwC, evaluating the appended caveats and entering the limited usage mode as requested and consistent with the appended caveats, without requiring connected resources to authenticate the MATwC.

17. The tangible non-transitory computer readable storage media of claim 16 , wherein the first device is a vehicle, further including evaluating the caveats as providing one or more of a limited travel distance authorization and a limited maximum speed authorization, and entering one or more of the limited usage mode restricted to the limited travel distance and the limited usage mode restricted to the limited maximum speed.

18. A system for providing limited usage of a first device, the system including a processor, memory coupled to the processor and program instructions from the non-transitory computer readable storage media of claim 16 loaded into the memory.

19. The system of claim 18 , wherein the first device is a vehicle, further including evaluating the caveats as providing one or more of a limited travel distance authorization and a limited maximum speed authorization, and entering one or more of the limited usage mode restricted to the limited travel distance and the limited usage mode restricted to the limited maximum speed.

20. A method of providing limited usage of a first device, wherein:

the first device includes local resources for verifying authenticity of a Macaroon access token with caveats (MATwC), including a unique key stored in memory of the first device and a local proximity interface for receiving the MATwC;

the method including:

a second device used by a service technician receiving the MATwC;

the second device establishing a connection with the first device over the local proximity interface and sending a request to enter a limited usage mode, the request including the MATwC;

wherein the MATwC

originated with an authorization server (AS) as a Macaroon access token (MAT) using the unique key of the first device; and

the MAT was modified by appending one or more caveats that narrowed authorization provided by the MAT with the limited usage mode, and applied a message authentication code (MAC) chaining algorithm to sign a resulting the MATwC; and

the first device performing local authentication of the MATwC, evaluating the appended caveats and entering the limited usage mode as requested and consistent with the appended caveats, without requiring connected resources to authenticate the MATwC.

21. The method of claim 20 , further including evaluating the appended caveats and determining that limited service is authorized and entering a service mode with limited service availability.

22. A tangible non-transitory computer readable storage media, including program instructions loaded into memory that, when executed on processors cause the processors to implement a method of providing limited usage of a first device, the method including:

the first device includes local resources for verifying authenticity of a Macaroon access token with caveats (MATwC), including a unique key stored in memory of the first device and a local proximity interface for receiving the MATwC;

the method including:

a second device used by a service technician receiving the MATwC;

the second device establishing a connection with the first device over the local proximity interface and sending a request to enter a limited usage mode, the request including the MATwC;

wherein the MATwC

originated with an authorization server (AS) as a Macaroon access token (MAT) using the unique key of the first device; and

the MAT was modified by appending one or more caveats that narrowed authorization provided by the MAT with the limited usage mode, and applied a message authentication code (MAC) chaining algorithm to sign a resulting the MATwC; and

the first device performing local authentication of the MATwC, evaluating the appended caveats and entering the limited usage mode as requested and consistent with the appended caveats, without requiring connected resources to authenticate the MATwC.

23. The tangible non-transitory computer readable storage media of claim 22 further including:

the second device connecting to the local proximity interface of the first device and presenting the MATwC to the first device for local authentication; and

the first device performing local authentication of the MATwC, evaluating the appended caveats, and entering a limited usage mode consistent with the appended caveats, without requiring connected resources to evaluate the MATwC.

24. A system for providing limited usage of a first device, the system including a processor, memory coupled to the processor and program instructions from the non-transitory computer readable storage media of claim 22 loaded into the memory.

25. The system of claim 24 , wherein the first device is a vehicle, further including appending in the caveats a limited travel area authorization, whereby the authority to drive the vehicle while in the limited usage mode is restricted to a limited travel area.

Assignments (5)
RELEASE OF SECURITY INTEREST AT R/F 65335/0890 Recorded Nov 14, 2025
From: BLUE OWL CAPITAL CORPORATION
To: PING IDENTITY CORPORATION (FORMERLY KNOWN AS FORGEROCK INC.)
Reel/Frame 073564/0791 →
SECURITY INTEREST Recorded Nov 13, 2025
From: PING IDENTITY CORPORATION; PING IDENTITY INTERNATIONAL, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 073557/0093 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 6, 2024
From: FORGEROCK, INC.
To: PING IDENTITY INTERNATIONAL, INC.
Reel/Frame 066358/0483 →
GRANT OF SECURITY INTEREST IN PATENT RIGHTS Recorded Oct 24, 2023
From: FORGEROCK, INC.
To: BLUE OWL CAPITAL CORPORATION (FORMERLY KNOWN AS OWL ROCK CAPITAL CORPORATION), AS COLLATERAL AGENT
Reel/Frame 065335/0890 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 17, 2020
From: MADDEN, NEIL EDWARD
To: FORGEROCK, INC.
Reel/Frame 054682/0294 →
Cited By (4)
US 12,301,575 US 12,316,762 US 12,470,398 US 12,701,142