IP Library › Granted Patent US 12,542,709
Granted Patent B2
US 12,542,709 · App. 17/728,539 · Granted Feb 3, 2026

Device provisioning using a supplemental cryptographic identity

Inventors: Mounica Arroju (Redmond, WA); Alexander I. Tolpin (Redmond, WA); Nicole Elaine Berdy (Kirkland, WA); Anush Prabhu Ramachandran (Woodinville, WA); Timothy James Larden (Kirkland, WA); Mengxi Chi (Bellevue, WA); Mahesh Sham Rohera (Sammamish, WA); Rajeev Mandayam Vokkarne (Sammamish, WA)
Assignee: Microsoft Technology Licensing, LLC
H04L41/0806H04L9/3247H04L9/3271H04L63/0876
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,542,709
App. No.
17/728,539
Granted
Feb 3, 2026
Kind
B2
Abstract

A device provisioning service provisions a network-connected device to access one or more service systems using a supplemental cryptographic identity of the network-connected device. An initial enrollment record (associated with an initial cryptographic identity) and a supplemental enrollment record are stored in a device provisioning service. An identity issuance request is received from the network-connected device at the device provisioning service. The identity issuance request includes the initial cryptographic identity. The supplemental cryptographic identity is requested from a supplemental cryptographic identity issuer identified in the initial enrollment record based on the identity issuance request. The requested supplemental cryptographic identity is received at the device provisioning service from the supplemental cryptographic identity issuer. The network-connected device is provisioned to access the one or more service systems according to the supplemental enrollment record. The supplemental cryptographic identity is communicated to the network-connected device.

Claims (53)

1 . A method of provisioning a network-connected device to access a service system using a supplemental cryptographic identity of the network-connected device, the method comprising:

storing, using a device provisioning system, an initial enrollment record associated with an initial cryptographic identity and a supplemental enrollment record;

receiving, using the device provisioning system, to an identity issuance request from the network-connected device at the device provisioning system, the supplemental cryptographic identity being received at the device provisioning system from a supplemental cryptographic identity issuer identified in the initial enrollment record, the identity issuance request including the initial cryptographic identity; and

provisioning, using the device provisioning system, the network-connected device to access the service system according to the supplemental enrollment record.

2 . The method of claim 1 , further comprising:

requesting, using the device provisioning system based on the identity issuance request, the supplemental cryptographic identity from the supplemental cryptographic identity issuer identified in the initial enrollment record; and

determining using the device provisioning system the supplemental cryptographic identity issuer from the initial enrollment record before requesting the supplemental cryptographic identity from the supplemental cryptographic identity issuer.

3 . The method of claim 1 further comprising:

requesting, using the device provisioning system based on the identity issuance request, the supplemental cryptographic identity from the supplemental cryptographic identity issuer identified in the initial enrollment record; and

associating, using the device provisioning system, the supplemental enrollment record with the supplemental cryptographic identity issuer at the device provisioning system, service, responsive to receiving the supplemental cryptographic identity.

4 . The method of claim 1 further comprising:

cryptographically challenging, using the device provisioning system, the network-connected device to prove the initial cryptographic identity included in the identity issuance request; and

determining, using the device provisioning system, that the network-connected device has successfully proven the initial cryptographic identity, responsive to the cryptographic challenging and before requesting the supplemental cryptographic identity.

5 . The method of claim 1 , further comprising:

determining, using the device provisioning system, that the identity issuance request was validly signed by the network-connected device, before requesting the supplemental cryptographic identity.

6 . The method of claim 1 , wherein the identity issuance request includes an identifier of the device provisioning system.

7 . The method of claim 1 , wherein the provisioning comprises:

registering, using the device provisioning system, the network-connected device with the service system based on the supplemental cryptographic identity.

8 . A device provisioning system for provisioning a network- connected device to access a service system using a supplemental cryptographic identity of the network-connected device, the device provisioning system comprising:

one or more hardware processors;

one or more tangible data storage media configured to store an initial enrollment record associated with an initial cryptographic identity and a supplemental enrollment record;

device communications interface hardware configured for communications with the network-connected device;

registration interface hardware configured for communication with the service system;

identity provider interface hardware configured to communicate with one or more supplemental cryptographic identity issuers;

an identity processor subsystem executed by the one or more hardware processors and coupled to the device communications interface hardware to receive an identity issuance request from the network-connected device at the device provisioning system, the supplemental cryptographic identity being received at the device provisioning system from a supplemental cryptographic identity issuer identified in the initial enrollment record, the identity issuance request including the initial cryptographic identity; and

a provisioning subsystem executed by the one or more hardware processors and coupled to the one or more tangible data storage media and the registration interface hardware to provision the network-connected device to access the service system according to the supplemental enrollment record.

9 . The device provisioning system of claim 8 wherein the initial enrollment record identifies the supplemental cryptographic identity issuer, and the identity processor subsystem is configured to determine the supplemental cryptographic identity issuer from the initial enrollment record before requesting the supplemental cryptographic identity from the supplemental cryptographic identity issuer.

10 . The device provisioning system of claim 8 wherein the provisioning subsystem is configured to associate the supplemental enrollment record with the supplemental cryptographic identity issuer at the device provisioning system, responsive to receipt of the supplemental cryptographic identity by the identity processor subsystem.

11 . The device provisioning system of claim 8 wherein the identity processor subsystem is configured to cryptographically challenge the network-connected device to prove the initial cryptographic identity included in the identity issuance request and determining, using the initial enrollment record, that the network-connected device has successfully proven the initial cryptographic identity, responsive to the cryptographic challenge and before requesting the supplemental cryptographic identity.

12 . The device provisioning system of claim 8 wherein the identity processor subsystem is configured to determine that the identity issuance request was validly signed by the network-connected device, before requesting the supplemental cryptographic identity.

13 . The device provisioning system of claim 8 , wherein the identity issuance request includes an identifier of the device provisioning system.

14 . The device provisioning system of claim 8 wherein the provisioning subsystem is further configured to register the network-connected device with the service system based on the supplemental cryptographic identity.

15 . One or more tangible processor-readable storage media of a tangible article of manufacture encoding processor-executable instructions for executing on an electronic computing device of a device provisioning system a process of provisioning a network-connected device to access a service system using a supplemental cryptographic identity of the network-connected device, the process comprising:

storing an initial enrollment record associated with an initial cryptographic identity and a supplemental enrollment record;

receiving an identity issuance request from the network-connected device at the device provisioning system, the supplemental cryptographic identity being received at the device provisioning system from a supplemental cryptographic identity issuer identified in the initial enrollment record, the identity issuance request including the initial cryptographic identity; and

provisioning the network-connected device to access the service system according to the supplemental enrollment record.

16 . The one or more tangible processor-readable storage media of claim 15 , wherein the process further comprises:

requesting, based on the identity issuance request, the supplemental cryptographic identity from the supplemental cryptographic identity issuer identified in the initial enrollment record; and

determining the supplemental cryptographic identity issuer from the initial enrollment record before requesting the supplemental cryptographic identity from the supplemental cryptographic identity issuer.

17 . The one or more tangible processor-readable storage media of claim 15 , wherein the process further comprises:

requesting, based on the identity issuance request, the supplemental cryptographic identity from the supplemental cryptographic identity issuer identified in the initial enrollment record; and

associating the supplemental enrollment record with the supplemental cryptographic identity issuer at the device provisioning system, responsive to receiving the supplemental cryptographic identity.

18 . The one or more tangible processor-readable storage media of claim 15 , wherein the process further comprises:

cryptographically challenging the network-connected device to prove the initial cryptographic identity included in the identity issuance request; and

determining that the network-connected device has successfully proven the initial cryptographic identity, responsive to the cryptographic challenging, and before requesting the supplemental cryptographic identity.

19 . The one or more tangible processor-readable storage media of claim 15 , wherein the process further comprises:

determining that the identity issuance request was validly signed by the network-connected device, before requesting the supplemental cryptographic identity.

20 . The one or more tangible processor-readable storage media of claim 15 , wherein the provisioning comprises:

registering the network-connected device with the service system based on the supplemental cryptographic identity.

21 . The method of claim 1 , wherein provisioning comprises:

transmitting, using the device provisioning system, the supplemental cryptographic identity to the network-connected device.

22 . The method of claim 1 , wherein the initial cryptographic identity includes a first certificate specific to the network-connected device, wherein the supplemental cryptographic identity includes a second certificate specific to the network-connected device.

23 . The one or more tangible processor-readable storage media of claim 15 , wherein the initial cryptographic identity includes a first certificate specific to the network-connected device, wherein the supplemental cryptographic identity includes a second certificate specific to the network-connected device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 25, 2022
From: ARROJU, MOUNICA; TOLPIN, ALEXANDER I.; BERDY, NICOLE ELAINE; RAMACHANDRAN, ANUSH PRABHU; LARDEN, TIMOTHY JAMES; CHI, MENGXI; ROHERA, MAHESH SHAM; VOKKARNE, RAJEEV MANDAYAM
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 059700/0968 →
Continuity (2)
Continuation 16827148 · Mar 23, 2020
Related Publication 20220263712A1 · Aug 18, 2022
References Cited (44)
US 10169587B1 · Nix · 2019 [cited by applicant]
US 10348720B2 · Jakobsson · 2019 [cited by applicant]
US 10375177B1 · Bretan · 2019 [cited by examiner]
US 10447683B1 · Loladia · 2019 [cited by examiner]
US 10547613B1 · Roths et al. · 2020 [cited by applicant]
US 10621352B2 · Nix · 2020 [cited by applicant]
US 11258598B2 · Yang · 2022 [cited by examiner]
US 11343139B2 · Arroju et al. · 2022 [cited by applicant]
US 20080260149A1 · Gehrmann · 2008 [cited by applicant]
US 20100242038A1 · Berrange · 2010 [cited by applicant]
US 20100299530A1 · Bell · 2010 [cited by examiner]
US 20140122873A1 · Deutsch et al. · 2014 [cited by applicant]
US 20140130145A1 · Yeleswarapu et al. · 2014 [cited by applicant]
US 20140317413A1 · Deutsch et al. · 2014 [cited by applicant]
US 20160105420A1 · Engan · 2016 [cited by examiner]
US 20160180343A1 · Poon · 2016 [cited by examiner]
US 20160285628A1 · Carrer · 2016 [cited by applicant]
US 20190188684A1 · Bettesworth · 2019 [cited by examiner]
US 20200014538A1 · Liu · 2020 [cited by examiner]
US 20200065473A1 · Berdy · 2020 [cited by applicant]
US 20200162255A1 · Hunt · 2020 [cited by examiner]
US 20200221296A1 · Jiang et al. · 2020 [cited by applicant]
US 20200313911A1 · Mondello et al. · 2020 [cited by applicant]
US 20210297311A1 · Arroju et al. · 2021 [cited by applicant]
CN 102067145A · 2011 [cited by applicant]
CN 102859929A · 2013 [cited by applicant]
CN 104486314A · 2015 [cited by applicant]
CN 109076075A · 2018 [cited by applicant]
CN 110651458A · 2020 [cited by applicant]
WO 2014113948A1 · 2014 [cited by applicant]
First Office Action Received for Chinese Application No. 202180023231.2, mailed on Mar. 25, 2024, 21 pages (English Translation Provided). [cited by applicant]
Communication under Rule 71(3) EPC Received for European Application No. 21709271.7, mailed on Oct. 31, 2024, 08 pages. [cited by applicant]
Notification on Grant Received for Chinese Application No. 202180023231.2, mailed on Nov. 29, 2024, 4 pages. (English Translation Provided). [cited by applicant]
Li, et al., “Light-Weight Detection of Spoofing Attacks in Wireless Networks,” Wireless Information Network Laboratory (WINLAB), IEEE, 2006, pp. 845-851. [cited by applicant]
Second Office Action Received for Chinese Application No. 202180023231.2, mailed on Aug. 27, 2024, 17 pages. (English Translation Provided). [cited by applicant]
Decision to grant a European patent pursuant to Article 97(1) EPC, Received for European Application No. 21709271.7, mailed on Jul. 17, 2025, 02 pages. [cited by applicant]
“International Search Report and Written Opinion Issued in PCT Application No. PCT/US21/016985”, Mailed Date: Mar. 30, 2021, 13 Pages. [cited by applicant]
Shailesh, Mota, “Secure Certificate Management and Device Enrollment at IoT Scale”, Retrieved from: https://aaltodoc.aalto.fi/bitstream/handle/123456789/23159/master_Mota_Shailesh_2016.pdf?sequence=1&isAllowed=y, Jun. 3… [cited by applicant]
“Authorizing Direct Calls to AWS Services”, Retrieved from: https://web.archive.org/web/20191028185105/https:/docs.aws.amazon.com/iot/latest/developerguide/authorizing-direct-aws.html, Oct. 28, 2019, 7 Pages. [cited by applicant]
“Certificate Issuance & Provisioning for Connected Devices”, Retrieved from: https://www.digicert.com/resources/fact-sheet/certificate-issuance-provisioning-for-connected-healthcare-devices.pdf, Retrieved Date: Dec. 6, … [cited by applicant]
Bedekar, et al., “Managed Rooms Backbone”, Application as Filed in U.S. Appl. No. 62/929,573, filed Nov. 1, 2019, 32 Pages. [cited by applicant]
Lamos, et al., “How to use different attestation mechanisms with Device Provisioning Service Client SDK for C”, Retrieved from: https://docs.microsoft.com/bs-latn-ba/azure/iot-dps/use-hsm-with-sdk, Mar. 30, 2018, 9 Page… [cited by applicant]
Sareen, et al., “Provisioning with a bootstrap certificate in AWS IoT Core”, Retrieved from: https://aws.amazon.com/blogs/iot/provisioning-with-a-bootstrap-certificate-in-aws-iot-core/, Jun. 13, 2019, 11 Pages. [cited by applicant]
Communication under Rule 71(3) EPC Received for European Application No. 21709271.7, mailed on Mar. 7, 2025, 08 pages. [cited by applicant]