IP Library Granted Patent US 12,580,749
Granted Patent B2
US 12,580,749 · App. 18/111,307 · Granted Mar 17, 2026

Configuration systems and methods for secure operation of networked transducers

Inventor: John A. Nix (Evanston, IL)
Assignee: Network-1 Technologies, Inc.
H04L9/0841G06F13/20H04L9/0861H04L9/3013H04L9/3247H04L9/3263H04L63/0435H04W12/03H04W12/06G16Y30/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,580,749
App. No.
18/111,307
Granted
Mar 17, 2026
Kind
B2
Abstract

A device can include an internal secure processing environment (SE) and communicate with a configuration system. The device may utilize a near field communications (NFC) radio. A mobile handset can connect with the SE in the device using NFC. The mobile handset can communicate with the configuration system and receive configuration data and a software package for the device. The SE can derive a PKI key pair and send the derived public key to the configuration system via the mobile handset. The SE and the configuration system can mutually derive an encryption key using the derived PKI key pair. The configuration data can be transmitted over the NFC radio, and the mobile handset can establish a Wi-Fi access point. The software package can be encrypted using the encryption key and transmitted to the device over the established Wi-Fi access point, thereby completing a configuration step for the device.

Claims (37)

1 . A wireless device comprising a housing which comprises within the housing:

(a) at least one radio;

(b) at least one transducer;

(c) at least one processor;

(d) a first computer-readable storage medium storing (i) an authentication token associated with the wireless device and (ii) a list of root certificates; and

(e) a second computer-readable storage medium operatively connected to the at least one processor and having stored thereon instructions that, when executed by the at least one processor, cause the wireless device to perform a method for the wireless device to securely receive, from a mobile handset, configuration data over a first wireless connection between the wireless device and the mobile handset, the method comprising:

storing a first device private key, wherein the first device private key corresponds to a first device public key;

storing a second device private key for a digital signature algorithm, the authentication token, and a first set of cryptographic parameters, wherein the second device private key corresponds to a second device public key;

establishing the first wireless connection with the mobile handset, wherein the first wireless connection is encrypted;

receiving, via the first wireless connection and from the mobile handset, (i) a first server public key for a first server (ii) a second set of cryptographic parameters, and (iii) a random number;

authenticating (i) a signature received from the mobile handset using at least the authentication token, and (ii) the wireless device using at least the received random number and the second device private key;

deriving a first symmetric ciphering key using at least (i) the first device private key and the first server public key, (ii) an elliptic curve Diffie-Hellman (ECDH) key exchange algorithm, and (iii) the first set of cryptographic parameters;

deriving a third device private key and a third device public key using the second set of cryptographic parameters;

generating a device digital signature over at least the third device public key using the second device private key;

encrypting at least the derived third device public key and the list of root certificates for the wireless device into a first ciphertext using the derived first symmetric ciphering key;

sending, via the first wireless connection and to the mobile handset, the first ciphertext and the device digital signature;

receiving, via the first wireless connection and from the mobile handset, a second ciphertext comprising (i) a device certificate for the derived third device public key and (ii) a certificate authority (CA) certificate for a second server comprising a new root certificate, wherein the wireless device decrypts the second ciphertext using at least the first symmetric ciphering key; and

establishing a second wireless connection to the second server, wherein the wireless device authenticates the second server using the new root certificate, and wherein the wireless device uses the received device certificate and the derived third device private key in order to authenticate over the second wireless connection.

2 . The wireless device of claim 1 , wherein the wireless device does not transmit the authentication token through the first wireless connection.

3 . The wireless device of claim 1 , wherein a secure element in the wireless device stores the device certificate and the CA new root certificate in the nonvolatile memory.

4 . The wireless device of claim 3 , wherein the secure element sends and receives through the wireless device using an external bus controller for the secure element, wherein the wireless device and the secure element are connected via a data bus, and wherein the wireless device communicates with the mobile handset and the second server through a radio.

5 . The wireless device of claim 3 , wherein the secure element includes a hardware random number generator, and wherein the hardware random number generator uses at least a transducer measurement in order to generate a device random number, and wherein the secure element uses the device random number to derive the third private key.

6 . The wireless device of claim 1 , further comprising in step 5), deriving the first symmetric ciphering key using a key derivation function, wherein the first symmetric ciphering key comprises data for encrypting the first ciphertext and decrypting the second ciphertext.

7 . The wireless device of claim 1 , further comprising: 12) receiving, via the second wireless connection, a second server public key for a third set of cryptographic parameters; 13) deriving a second symmetric ciphering key using (i) the derived third device private key the second server public key, (ii) the ECDH key exchange algorithm, and (iii) the third set of cryptographic parameters; and 14) receiving a third ciphertext of a device configuration, wherein the second ciphertext is decrypted by the wireless device using the derived second symmetric ciphering key.

8 . The wireless device of claim 7 , wherein the device configuration includes a set of network parameters, and wherein the wireless device authenticates with a wireless access network using the set of network parameters.

9 . The wireless device of claim 7 , wherein the device configuration includes at least one file for the wireless device, wherein the at least one file is used by the wireless device with at least one of a device operating system, a device reporting application, a secure element firmware, a secure element operating system, a transducer library, and a configuration test vector.

10 . The wireless device of claim 7 , wherein the device configuration includes at least one file for a secure element, wherein the at least one file is used by the secure element with at least one of a secure element firmware, a secure element operating system, a transducer library, and a configuration test vector.

11 . The wireless device of claim 1 , wherein the first set of cryptographic parameters specifies at least a first elliptic curve defining equation, and wherein the second set of cryptographic parameters specifies at least a second elliptic curve defining equation.

12 . The wireless device of claim 1 , wherein the authentication token comprises a random number for a QR code.

13 . The wireless device of claim 1 , wherein the wireless device receives via the first wireless connection, (i) the first server public key for the first server (ii) the second set of cryptographic parameters, and (iii) the random number with a server digital signature, and wherein the wireless device authenticates the server digital signature using at least the authentication token.

14 . The wireless device of claim 1 , wherein the wireless device authenticates the wireless device (i) using the received random number and the second device private key, and (ii) by sending the second device public key with an authenticating digital signature.

15 . The wireless device of claim 1 , wherein the first wireless connection uses one of “Near Field Communications” (NFC), Bluetooth, and Wi-Fi technology.

16 . The wireless device of claim 1 , wherein the wireless device derives the first device private key after establishing the first wireless connection, and wherein the wireless device stores the first device private key after deriving the first device private key.

17 . The wireless device of claim 1 , wherein the second set of cryptographic parameters specifies values for algorithms associated with a key encapsulation mechanism, and wherein the algorithms comprise one of lattice-based cryptography and code-based cryptography.

18 . The wireless device of claim 1 , wherein the third device public key supports at least one of lattice-based cryptography, code-based cryptography, and elliptic curve cryptography.

19 . The wireless device of claim 1 , wherein the wireless device derives the third public key before the wireless device authenticates the second server.

20 . The wireless device of claim 1 , wherein the first computer-readable storage medium and the second computer-readable storage medium are different.

Assignments (4)
CHANGE OF ADDRESS Recorded Sep 10, 2025
From: NETWORK-1 TECHNOLOGIES, INC.
To: NETWORK-1 TECHNOLOGIES, INC.
Reel/Frame 072827/0540 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 7, 2025
From: IOT AND M2M TECHNOLOGIES, LLC
To: NETWORK-1 TECHNOLOGIES, INC.
Reel/Frame 070752/0719 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 4, 2025
From: VOBAL TECHNOLOGIES, LLC
To: IOT AND M2M TECHNOLOGIES, LLC
Reel/Frame 070736/0052 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 17, 2023
From: NIX, JOHN A.
To: IOT AND M2M TECHNOLOGIES, LLC
Reel/Frame 062735/0279 →
Continuity (3)
Continuation 16980987
Provisional Application 62644195 · Mar 16, 2018
Related Publication 20230208626A1 · Jun 29, 2023
References Cited (12)
US 10204233B2 · Nix · 2019 [cited by applicant]
US 20020024419A1 · Dunn · 2002 [cited by examiner]
US 20060239459A1 · Yamamichi · 2006 [cited by examiner]
US 20120222101A1 · Iwasaki · 2012 [cited by examiner]
US 20130139198A1 · Okimoto · 2013 [cited by examiner]
US 20160234020A1 · Nix · 2016 [cited by examiner]
US 20170013022A1 · Buckley · 2017 [cited by examiner]
US 20170063810A1 · Bruce · 2017 [cited by examiner]
US 20170339120A1 · Zakaria et al. · 2017 [cited by applicant]
US 20170373845A1 · Nix · 2017 [cited by applicant]
US 20180144147A1 · Nix · 2018 [cited by applicant]
International Search Report and Written Opinion for application No. PCT/US19/22184, mailed May 27, 2019. [cited by applicant]