IP Library Granted Patent US 12,470,539
Granted Patent B2
US 12,470,539 · App. 18/158,197 · Granted Nov 11, 2025

Authenticating a networked camera using a certificate having device binding information

Inventor: Youngsam Kim (Seongnam-si, KR)
Assignee: Hanwha Vision Co., Ltd.
H04L63/0823H04L9/3268H04L63/0876H04L63/105H04L63/126H04N7/18
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,470,539
App. No.
18/158,197
Granted
Nov 11, 2025
Kind
B2
Abstract

A device authentication method includes: connecting to a device such as a camera through a network; receiving, from the device, a certificate of the device including device binding information about the device; sending, to the device, a device management message for administration level authentication; receiving, from the device, device information about the device in response to the administration level authentication being successful; determining whether the certificate is valid based on the device binding information and the device information; and establishing a protected communication session with the device in response to the certificate being determined to be valid.

Claims (54)

1 . A device authentication method comprising:

connecting to a device through a network;

receiving, from the device, a certificate of the device comprising device binding information about the device, the device binding information comprising first device information associated with the device binding information;

transmitting, to the device, a request message for requesting second device information about the device when a management device does not store the second device information in a storage of the management device;

receiving, from the device, the second device information in response to the request message;

determining, by the management device, whether device binding information included in the certificate is generated based on the second device information; and

determining, by the management device, whether the certificate is valid by comparing first hash data related to pre-stored certificate information with second hash data related to the certificate; and

establishing a protected communication session with the device in response to the certificate being determined to be valid,

wherein based on at least a portion of the second device information being included in the device binding information, the device binding information is generated based on the second device information,

wherein based on the first hash data matching the second hash data, the certificate is determined as valid and

wherein the first device information is generated based on at least a part of a medium access control (MAC) address and at least a portion of a controller, a storage and an image sensor included in the device.

2 . The device authentication method of claim 1 , wherein the first device information and the second device information represent identification information about the device for identifying the device from other devices.

3 . The device authentication method of claim 2 , wherein the device binding information represents that the certificate has been issued for the device identified by the first device information.

4 . The device authentication method of claim 3 , wherein the second device information comprises at least a part of a Medium Access Control (MAC) address of a communication interface included in the device.

5 . The device authentication method of claim 4 , wherein the second device information comprises information about a component constituting the device.

6 . A camera authentication method comprising:

connecting to a management device through a network;

transmitting, to the management device, a certificate of a device comprising device binding information about the device, the device binding information comprising first device information associated with the device binding information;

receiving, from the management device, a request message for requesting second device information about the device when a management device does not store the second device information in a storage of the management device; and

transmitting, to the management device, second device information in response to the request message,

wherein based on at least a portion of the second device information being included in the device binding information, the device binding information is generated based on the second device information, and

wherein the first device information is generated based on at least a part of a medium access control (MAC) address and at least a portion of a controller, a storage and an image sensor included in the device.

7 . A management device for a camera comprising:

a communication interface configured to communicate with the camera;

a storage configured to store device information about the camera; and

a controller operatively coupled to the communication interface and the storage, and configured to:

connect to the camera through a network;

receive, from the camera, a certificate of the camera comprising device binding information about the camera, the device binding information comprising first device information associated with the device binding information;

transmit, to the camera, a request message for requesting second device information about the camera when the management device does not store the second device information in a storage of the management device;

receive, from the camera, the second device information in response to the request message;

determine whether the device binding information included in the certificate is generated based on the second device information;

determine whether the certificate is valid by comparing a first hash data related to pre-stored certificate information with a second hash data related to the certificate; and

establish a protected communication session with the camera in response to the certificate being determined to be valid,

wherein based on at least a portion of the second device information being included in the device binding information, the device binding information is generated based on the second device information,

wherein based on the first hash data matching the second hash data, the certificate is determined as valid, and

wherein the first device information is generated based on at least a part of a medium access control (MAC) address and at least a portion of a controller, a storage and an image sensor included in the device.

8 . The management device of claim 7 , wherein the second device information comprises at least a part of a Medium Access Control (MAC) address of a communication interface included in the camera.

9 . The management device of claim 8 , wherein the certificate is expressed in a form of X.509v3, and

wherein the device binding information is included in a SubjectPublickeyInfo field or an extension field.

10 . The management device of claim 7 , wherein the controller is further configured to control the communication interface to establish the protected communication session via SSL (Secure Socket Layer) protocols in response to validating the certificate.

11 . A camera comprising:

a communication interface configured to communicate with a management device;

an image sensor configured to capture image data;

a storage configured to store a certificate of the camera, and store a public key included in the certificate and a private key generated to have a cryptographic relation with the public key; and

a controller operatively coupled to the image sensor and the storage, and configured to:

connect, to a management device through a network;

transmit, to the management device, the certificate comprising device binding information about the camera, the device binding information comprising first device information associated with the device binding information;

receive, from the management device, a request message for requesting second device information about the camera when the management device does not store the second device information in a storage of the management device;

transmit, to the management device, second device information in response to the request message; and

establish a protected communication session with the management device based on a result of determining whether the certificate is valid at the management device,

wherein based on at least a portion of the second device information being included in the device binding information the device binding information is generated based on the second device information, and

wherein the first device information is generated based on at least a part of a medium access control (MAC) address and at least a portion of a controller, a storage and an image sensor included in the device.

12 . The camera of claim 11 , wherein the first device information and the second device information represent identification information about the camera for identifying the camera from other devices.

13 . The camera of claim 12 , wherein the first device information comprises at least a part of a Medium Access Control (MAC) address of the communication interface.

Assignments (1)
CHANGE OF NAME Recorded Aug 10, 2023
From: HANWHA TECHWIN CO., LTD.
To: HANWHA VISION CO., LTD.
Reel/Frame 064549/0075 →
Priority Claims (1)
KR 10-2017-0122089 · Sep 21, 2017 · national
Continuity (2)
Continuation 16137961 · Sep 21, 2018
Related Publication 20230164136A1 · May 25, 2023
References Cited (12)
US 9641344B1 · Kim · 2017 [cited by applicant]
US 10511448B1 · Brinskelle · 2019 [cited by examiner]
US 20110252227A1 · Strong · 2011 [cited by examiner]
US 20170034700A1 · Cohen · 2017 [cited by examiner]
US 20170201383A1 · Kim · 2017 [cited by examiner]
US 20190104251A1 · Otsuki · 2019 [cited by examiner]
US 20230164136A1 · Kim · 2023 [cited by examiner]
KR 1020090071307A · 2009 [cited by applicant]
WO 2012046907A1 · 2012 [cited by applicant]
Communication dated Jan. 31, 2019, issued by the European Patent Office in counterpart European Application No. 18195937.0. [cited by applicant]
Dierks, T. et al., “The TLS Protocol”, Version 1.0, RFC 2246, Jan. 1999, The Internet Society. (80 pages total). [cited by applicant]
Cooper et al., rfc5280—Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile (IETF May 2008 (Year: 2008). [cited by applicant]