IP Library Granted Patent US 12,132,842
Granted Patent B2
US 12,132,842 · App. 18/111,646 · Granted Oct 29, 2024

System and method for zero touch provisioning of IoT devices

Inventors: Srinivas Kumar (Cupertino, CA); Atul Gupta (Sunnyvale, CA); Shreya Uchil (Millbrae, CA); Ruslan Ulanov (Dublin, CA); Srikesh Amrutur Srinivas (Cupertino, CA)
Assignee: DigiCert, Inc.
H04L9/3263H04L9/3247
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,132,842
App. No.
18/111,646
Granted
Oct 29, 2024
Kind
B2
Abstract

An Internet of Things (IoT) device with zero touch provisioning includes one or more processing devices; a secure element; and memory storing software that, when executed in the one or more processing devices, cause the one or more processing devices to: install one or more clients on the IoT device for provisioning, enrollment, and updating, based on a device configuration; store an immutable device identity and a signing certificate in the secure element; and responsive to the IoT device being powered-on, cause the one or more clients and the secure element to perform the zero touch provisioning of the IoT device. The one or more clients on the IoT device for provisioning, enrollment, and updating operate with corresponding services with all communicating being encrypted, thereby protecting against cloning and counterfeiting of IoT devices.

Claims (37)

1. An Internet of Things (IoT) device with zero touch provisioning, the IoT device comprises:

one or more processing devices;

a secure element; and

memory storing software that, when executed in the one or more processing devices, cause the one or more processing devices to:

install, by an IoT device manufacturer, one or more clients on the IoT device for provisioning, enrollment, and updating, based on a device type-based device configuration template generated by a device owner, wherein the one or more clients on the IoT device for provisioning, enrollment, and updating operate with corresponding services with all communicating being encrypted;

store an immutable device identity and a signing certificate in the secure element; and

responsive to the IoT device being powered-on, cause the one or more clients and the secure element to perform the zero touch provisioning of the IoT device, wherein the zero touch provisioning includes

sending the signing certificate from the secure element to an enrollment service for receiving encrypted device configuration therefrom, and

provisioning cryptographic artifacts based on at least the immutable device identifier in the secure element, and storing the cryptographic artifacts in the secure element without a need to manually distribute the cryptographic artifacts thereto.

2. The IoT device of claim 1 , wherein the secure element includes one of hardware, firmware, and software.

3. The IoT device of claim 1 , wherein the secure element is a trusted platform module.

4. The IoT device of claim 1 , wherein the memory storing software that, when executed in the one or more processing devices, further cause the one or more processing devices to:

receive one or more device configuration templates for one or more IoT devices signed by a device owner with a device owner signing certificate; and

install the device configuration on the IoT device based on an associated device configuration template encrypted with the device owner signing certificate, wherein the device configuration is decryptable by an enrollment service having a device owner private key, during zero touch provisioning.

5. The IoT device of claim 1 , wherein the signing certificate is utilized at enrollment for obtaining a device certificate, used for updates and obtaining device attributes.

6. The IoT device of claim 1 , wherein the one or more clients on the IoT device for provisioning, enrollment, and updating operate with corresponding services with all communicating being encrypted.

7. The IoT device of claim 1 , wherein the one or more clients on the Iot device for provisioning, enrollment, and updating are configured to interact automatically with the corresponding services at power-on.

8. The IoT device of claim 1 , wherein the memory storing software that, when executed in the one or more processing devices, further cause the one or more processing devices to:

install bootstrap metadata on the IoT device with the bootstrap metadata including at least an enrollment service network address.

9. The IoT device of claim 1 , wherein the device configuration includes a plurality of a device enrollment service network address, a device authentication profile, and a label for tenant and certificate authority attribution.

10. A method of configuring an Internet of Things (IoT) device for zero touch provisioning, the method comprising steps of:

installing, by an IoT device manufacturer, one or more clients on the IoT device for provisioning, enrollment, and updating, based on a device typed-based device configuration template generated by a device owner, wherein the one or more clients on the IoT device for provisioning, enrollment, and updating operate with corresponding services with all communicating being encrypted;

providing an immutable device identity and a signing certificate to a secure element of the IoT device; and

providing the IoT device with the one or more clients and the secure element, wherein the one or more clients and the secure element are configured to provide the zero touch provisioning of the IoT device, wherein the zero touch provisioning includes

sending the signing certificate from the secure element to an enrollment service for receiving encrypted device configuration therefrom, and

provisioning cryptographic artifacts based on at least the immutable device identifier in the secure element, and storing the cryptographic artifacts in the secure element without a need to manually distribute the cryptographic artifacts thereto.

11. The method of claim 10 , wherein the secure element includes one of hardware, firmware, and software.

12. The method of claim 10 , wherein the secure element is a trusted platform module.

13. The method of claim 10 , wherein the steps further include:

receiving one or more device configuration templates for one or more IoT devices signed by a device owner with a device owner signing certificate; and

installing the device configuration on the IoT device based on an associated device configuration template encrypted with the device owner signing certificate, wherein the device configuration is decryptable by an enrollment service having a device owner private key, during zero touch provisioning.

14. The method of claim 10 , wherein the signing certificate is utilized at enrollment for obtaining a device certificate, used for updates and obtaining device attributes.

15. The method of claim 10 , wherein the one or more clients on the IoT device for provisioning, enrollment, and updating operate with corresponding services with all communicating being encrypted.

16. The method of claim 10 , wherein the one or more clients on the IoT device for provisioning, enrollment, and updating are configured to interact automatically with the corresponding services at power-on.

17. The method of claim 10 , wherein the steps further include:

installing bootstrap metadata on the IoT device with the bootstrap metadata including at least an enrollment service network address.

18. The method of claim 10 , wherein the device configuration includes a plurality of a device enrollment service network address, a device authentication profile, and a label for tenant and certificate authority attribution.

Assignments (4)
FIRST LIEN INTELLECTUAL PROPERTY AGREEMENT SUPPLEMENT Recorded Sep 24, 2025
From: DIGICERT, INC.
To: HPS INVESTMENT PARTNERS, LLC, AS COLLATERAL AGENT
Reel/Frame 072947/0203 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT SUPPLEMENT Recorded Jul 30, 2025
From: DIGICERT, INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 072295/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 20, 2023
From: KUMAR, SRINIVAS; GUPTA, ATUL; UCHIL, SHREYA; ULANOV, RUSLAN; SRINIVAS, SRIKESH AMRUTUR
To: MOCANA CORPORATION
Reel/Frame 062741/0768 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 20, 2023
From: MOCANA CORPORATION
To: DIGICERT, INC.
Reel/Frame 062812/0756 →
Continuity (3)
Continuation 16696034 · Nov 26, 2019
Provisional Application 62775949 · Dec 6, 2018
Related Publication 20230208652A1 · Jun 29, 2023
Cited By (1)
US 12,388,667