IP Library Granted Patent US 12,316,785
Granted Patent B2
US 12,316,785 · App. 18/760,297 · Granted May 27, 2025

Systems, methods, and devices for multi-stage provisioning and multi-tenant operation for a security credential management system

Inventors: Daniel R. Fynaardt (Capistrano Beach, CA); William L. Lattin (Los Altos, CA); Gregory Powell (Ladera Ranch, CA)
Assignee: INTEGRITY SECURITY SERVICES LLC.
H04L9/3268H04L41/0806H04L41/5041H04L63/00H04L63/0823H04L63/20H04W12/06H04W12/35G06F16/22H04L63/166H04L67/02H04L67/12H04L67/306H04L2209/80H04L2209/84H04W4/44
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,316,785
App. No.
18/760,297
Granted
May 27, 2025
Kind
B2
Abstract

The system for provisioning computerized devices of a tenant includes an enrollment certificate authority generating enrollment certificates in response to first provisioning requests for the enrollment certificates, a second certificate authority generating digital assets for onboard units and roadside units of the tenant in response to second provisioning requests from the computerized devices. A security credential management system platform, connected to the enrollment certificate authority and to the second certificate authority, receiving the first provisioning requests for enrollment certificates for the computerized devices, routing the first provisioning requests to the enrollment certificate authority based on the tenant identification (ID), receiving the second provisioning requests for digital assets for the computerized devices, and routing the second provisioning requests to the second certificate authority based on the device identifier. Each first provisioning request includes the tenant ID, and each second provisioning request includes a device identifier.

Claims (52)

1. A system for securely provisioning a plurality of computerized devices of a tenant, the tenant having a tenant identifier (ID) that identifies the tenant, the system comprising:

an enrollment certificate authority operable to generate enrollment certificates in response to first provisioning requests for the enrollment certificates;

a second certificate authority operable to generate digital assets for onboard units and roadside units of the tenant in response to second provisioning requests from the plurality of computerized devices, wherein each of the second provisioning requests includes a device identifier; and

a Security Credential Management System (SCMS) host platform, operably connected to the enrollment certificate authority and to the second certificate authority, wherein the SCMS host platform is configured to perform operations comprising:

receiving the first provisioning requests for enrollment certificates for the plurality of computerized devices, each first provisioning request including a tenant identification (ID);

routing at least some of the first provisioning requests to the enrollment certificate authority based on the tenant ID;

receiving the second provisioning requests for digital assets for the plurality of computerized devices, each second provisioning request including a device identifier; and

routing at least some of the second provisioning requests to the second certificate authority based on the device identifier.

2. The system of claim 1 , wherein the operations further comprise:

identifying one or more of a device type and a device configuration of a computerized device associated with a provisioning request.

3. The system of claim 2 , wherein the operations further comprise:

determining a compatibility of the enrollment certificates and the digital assets based on the identifying.

4. The system of claim 2 , wherein the operations further comprise:

obtaining installation data related to an initial installation of the computerized device associated with a provisioning request,

wherein the enrollment certificate authority and the second certificate authority are configured to provide a respective enrollment certificate and a respective digital asset based on the installation data.

5. The system of claim 1 , wherein the operations further comprise:

verifying, based on at least one of the tenant ID or an enrollment certificate, that the second provisioning requests are authorized.

6. The system of claim 1 , further comprising:

a first linkage authority and a second linkage authority operable to generate linkage values for the tenant in response to receiving requests for the linkage values.

7. The system of claim 1 , wherein the tenant ID is a null value.

8. The system of claim 1 , further comprising:

a virtual registration authority executed by the host platform, the virtual registration authority operable to transmit the first provisioning requests to the SCMS, based on the tenant ID.

9. The system according to claim 8 , further comprising:

an abstraction layer executed by the host platform, the abstraction layer operable to receive the first provisioning requests for the enrollment certificates for the plurality of computerized devices, each of the first provisioning requests indicating a tenant ID identifying the tenant,

wherein the abstraction layer is executed at a level above the virtual registration authority.

10. The system of claim 1 , wherein the SCMS host platform executes a plurality of virtual registration authorities, each virtual registration authority of the plurality of virtual registration authorities being associated with the tenant ID.

11. A method for securely provisioning a plurality of computerized devices of a tenant, the method comprising:

generating, by an enrollment certificate authority, enrollment certificates in response to first provisioning requests for the enrollment certificates;

generating, by a second certificate authority, digital assets for onboard units and roadside units of the tenant in response to second provisioning requests from the plurality of computerized devices, wherein each of the second provisioning requests includes a device identifier; and

receiving, by a Security Credential Management System (SCMS) host platform, the first provisioning requests for enrollment certificates for the plurality of computerized devices, each first provisioning request including a tenant identification (ID);

routing, by the SCMS host platform, at least some of the first provisioning requests to the enrollment certificate authority based on the tenant ID;

receiving, by the SCMS host platform, the second provisioning requests for digital assets for the plurality of computerized devices, each second provisioning request including a device identifier; and

routing, by the SCMS host platform, at least some of the second provisioning requests to the second certificate authority based on the device identifier,

wherein the SCMS host platform is operably connected to the enrollment certificate authority and to the second certificate authority.

12. The method of claim 11 , further comprising:

identifying one or more of a device type and a device configuration of a computerized device associated with a provisioning request.

13. The method of claim 12 , further comprising:

determining a compatibility of the enrollment certificates and the digital assets based on the identifying.

14. The method of claim 11 , further comprising:

obtaining installation data related to an initial installation of a computerized device associated with a provisioning request, and wherein the enrollment certificate authority and the second certificate authority are configured to provide a respective enrollment certificate and a respective digital asset based on the installation data.

15. The method of claim 11 , wherein the SCMS host platform comprises:

a first linkage authority and a second linkage authority operable to generate linkage values for the tenant in response to receiving requests for the linkage values.

16. The method of claim 11 , wherein the tenant ID is a null value.

17. The method of claim 11 , further comprising:

verifying, based on at least one of the tenant ID or an enrollment certificate, that the second provisioning requests are authorized.

18. The method of claim 11 , further comprising:

transmitting, by a virtual registration authority, the first provisioning requests to the SCMS host platform based on the tenant ID.

19. The method according to claim 18 , further comprising:

executing, by the SCMS host platform, an abstraction layer operable to receive the first provisioning requests for the enrollment certificates for the plurality of computerized devices, each of the first provisioning requests indicating a tenant ID identifying the tenant,

wherein the abstraction layer is executed at a level above the virtual registration authority.

20. The method of claim 11 , wherein further comprising:

executing, by the SCMS host platform, a plurality of virtual registration authorities, each virtual registration authority of the plurality of virtual registration authorities being associated with the tenant ID.

Assignments (2)
ENTITY CONVERSION Recorded Jul 1, 2024
From: INTEGRITY SECURITY SERVICES, INC.
To: INTEGRITY SECURITY SERVICES LLC
Reel/Frame 068094/0719 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 1, 2024
From: FYNAARDT, DANIEL R.; LATTIN, WILLIAM L.; POWELL, GREGORY
To: INTEGRITY SECURITY SERVICES, INC.
Reel/Frame 068097/0578 →
Continuity (7)
Continuation 18226351 · Jul 26, 2023
Continuation 17503784 · Oct 18, 2021
Continuation 17097148 · Nov 13, 2020
Continuation 16591093 · Oct 2, 2019
Continuation 16191030 · Nov 14, 2018
Provisional Application 62585756 · Nov 14, 2017
Related Publication 20240356765A1 · Oct 24, 2024
References Cited (36)
US 8010786B1 · Ward · 2011 [cited by applicant]
US 8073442B2 · Frank et al. · 2011 [cited by applicant]
US 10154061B1 · Schetina · 2018 [cited by applicant]
US 10476679B2 · Fynaardt et al. · 2019 [cited by applicant]
US 20120089734A1 · Mercuri · 2012 [cited by applicant]
US 20140007178A1 · Gillum · 2014 [cited by applicant]
US 20140331337A1 · Factor et al. · 2014 [cited by applicant]
US 20160134472A1 · Guan et al. · 2016 [cited by applicant]
US 20170222990A1 · Romansky · 2017 [cited by applicant]
US 20170279619A1 · Yang · 2017 [cited by applicant]
US 20170280320A1 · Caceres et al. · 2017 [cited by applicant]
US 20180004933A1 · Nathanson · 2018 [cited by applicant]
US 20180137261A1 · Lattin · 2018 [cited by applicant]
US 20180159935A1 · Cavalcanti · 2018 [cited by applicant]
US 20180275966A1 · Linton · 2018 [cited by applicant]
US 20180316511A1 · Meyer · 2018 [cited by applicant]
US 20190089547A1 · Simplicio, Jr. · 2019 [cited by applicant]
US 20190098471A1 · Rech · 2019 [cited by applicant]
US 20190116048A1 · Chen · 2019 [cited by applicant]
US 20200008027A1 · Yabuuchi · 2020 [cited by examiner]
US 20200045552A1 · Kim · 2020 [cited by applicant]
FR 3006836A1 · 2014 [cited by applicant]
J. Petit, F. Schaub, M. Feiri and F. Kargl, “Pseudonym Schemes in Vehicular Networks: A Survey,” in IEEE Communications Surveys & Tutorials, vol. 17, No. 1, pp. 228-255, First quarter 2015 (Year: 2015). [cited by examiner]
Khodaei, Mohammad, and Panos Papadimitratos. “The key to intelligent transportation: Identity and credential management in vehicular communication systems.” IEEE Vehicular Technology Magazine 10.4 (2015): 63-69. (Year: … [cited by examiner]
Non-Final Office Action dated Apr. 18, 2019, U.S. Appl. No. 16/191,030, 15 pages. [cited by applicant]
Notice of Allowance dated Jul. 3, 2019, U.S. Appl. No. 16/191,030, 9 pages. [cited by applicant]
Non-Final Office Action dated Dec. 30, 2019, U.S. Appl. No. 16/591,093, 31 pages. [cited by applicant]
Final Office Action dated Jun. 18, 2020, U.S. Appl. No. 16/591,093, 19 pages. [cited by applicant]
Notice of Allowance dated Oct. 2, 2020, U.S. Appl. No. 16/591,093, 9 pages. [cited by applicant]
Corrected Notice of Allowance dated Oct. 6, 2020, U.S. Appl. No. 16/591,093, 4 pages. [cited by applicant]
Non-Final Office Action dated Dec. 23, 2020, U.S. Appl. No. 17/097,148, 22 pages. [cited by applicant]
Final Office Action dated Apr. 14, 2021, U.S. Appl. No. 17/097,148, 19 pages. [cited by applicant]
Notice of Allowance dated Jun. 24, 2021, U.S. Appl. No. 17/097,148, 8 pages. [cited by applicant]
Non-Final Office Action dated Oct. 14, 2022, U.S. Appl. No. 17/503,784, 20 pages. [cited by applicant]
Notice of Allowance dated Apr. 27, 2023, U.S. Appl. No. 17/503,784, 9 pages. [cited by applicant]
Notice of Allowance dated Mar. 13, 2024, U.S. Appl. No. 18/226,351, 15 pages. [cited by applicant]