IP Library Granted Patent US 9,363,249
Granted Patent B2
US 9,363,249 · App. 14/198,994 · Granted Jun 7, 2016

Secure simple enrollment

Inventors: Paul A. Lambert (Mountain View, CA); Josselin De La Broise (Mountain View, CA)
Assignee: MARVELL WORLD TRADE LTD.
H04L63/062H04L9/3244H04L63/0442H04W12/04H04W12/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,363,249
App. No.
14/198,994
Filed
Mar 6, 2014
Granted
Jun 7, 2016
Kind
B2
Art Unit
2492
USPC
713/170
Abstract

Methods, systems, and apparatus are disclosed for generating one or more device identifiers based on a public key associated with a respective device. Various embodiments include condensing and/or hashing a device public key to generate the corresponding device identifier. By using the relationship between a device public key and its device identifier, public key exchanges are implemented to verify this relationship and facilitate device enrollment into one or more networks. The embodiments further describe enrolling one or more devices into networks and/or authorizing devices to enroll one more devices into networks based on public key exchanges and verification that the one or more device identifiers match the respective public keys. Embodiments for authorizing other devices describe a first device enrolling a second device in a first network and authorizing a third device to enroll the second device in a second network using an exchange of public keys and/or messages.

Claims (43)

1. A method, comprising:

receiving, at a first device having a first public key, an identifier associated with the first device, the identifier received from a second device;

receiving, at the first device, a second public key associated with the second device;

generating, at the first device, a session key based on a combination of the first public key and the second public key;

authenticating, at the first device, the second device using the session key;

determining, at the first device, whether the identifier received from the second device corresponds to the first public key; and

enrolling, using the first device, the second device in a network including the first device based on determining that the identifier received from the second device corresponds to the first public key.

2. The method of claim 1 , wherein authenticating the second device comprises:

sending, by the first device, a first message encrypted with the session key to the second device; and

receiving, at the first device, a second message sent from the second device in response to the first message being successfully decrypted at the second device with the session key.

3. The method of claim 2 , wherein authenticating the second device further comprises:

decrypting the second message; and

verifying that the decrypted message conforms to a predetermined message format.

4. The method of claim 1 , wherein determining whether the identifier received from the second device corresponds to the first public key comprises:

applying, at the first device, a hash function to the first public key to provide a regenerated identifier; and

comparing, at the first device, the regenerated identifier with the identifier received from the second device.

5. The method of claim 1 , further comprising:

capturing, at the second device, an image representative of the identifier, and wherein the act of receiving the identifier comprises:

receiving, at the first device, the identifier from the second device based on the image.

6. The method of claim 1 , wherein determining whether the identifier received from the second device corresponds to the first public key comprises:

rehashing the first public key to provide a rehashed first public key; and

determining whether the identifier maps to the rehashed first public key.

7. The method of claim 1 , further comprising:

sending, by the first device, security information to the second device to facilitate the enrollment of the second device in the network based on determining that the identifier received from the second device corresponds to the first public key.

8. The method of claim 1 , further comprising:

updating, by the first device, the identifier after the second device is enrolled in the network to facilitate subsequent enrollment of a third device.

9. A first device, comprising:

a network interface configured to receive (i) an identifier associated with the first device, the identifier received from a second device, and (ii) a second public key associated with the second device; and

a controller configured to:

(i) generate a session key based on a combination of a first public key associated with the first device and the second public key,

(ii) authenticate the second device using the session key;

(iii) determine whether the identifier received from the second device corresponds to the first public key, and

(iv) enroll the second device in a network including the first device based on based on determining that the identifier received from the second device corresponds to the first public key.

10. The first device of claim 9 , wherein:

the network interface is further configured to (i) send a first message encrypted with the session key to the second device, and (ii) receive a second message, sent from the second device, in response to the first message being successfully decrypted at the second device with the session key.

11. The first device of claim 9 , wherein the controller is further configured to (i) decrypt the second message, and (ii) verify that the decrypted message conforms to a predetermined message format.

12. The first device of claim 9 , wherein the controller is further configured to:

apply a hash function to the first public key to provide a regenerated identifier; and

compare the regenerated identifier with the identifier received from the second device.

13. The first device of claim 9 , wherein the second device includes an image capture device configured to capture an image representative of the identifier, and wherein the network interface is further configured to receive the identifier based on the image.

14. The first device of claim 9 , wherein the controller is further configured to (i) rehash the first public key to provide a rehashed first public key, and (ii) determine whether the identifier maps to the rehashed first public key.

15. The first device of claim 9 , wherein the network interface is further configured to send network security information to the second device to facilitate the enrollment of the second device in the network based on determining that the identifier corresponds to the first public key.

16. The first device of claim 9 , wherein the controller is further configured to update the identifier with another value after the second device is enrolled in the network to facilitate subsequent enrollment of a third device.

Assignments (7)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2020
From: CAVIUM INTERNATIONAL
To: MARVELL ASIA PTE, LTD.
Reel/Frame 053475/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 20, 2020
From: MARVELL INTERNATIONAL LTD.
To: CAVIUM INTERNATIONAL
Reel/Frame 052918/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 29, 2020
From: MARVELL WORLD TRADE LTD.
To: MARVELL INTERNATIONAL LTD.
Reel/Frame 051778/0537 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 23, 2016
From: LAMBERT, PAUL A; DE LA BROISE, JOSSELIN
To: MARVELL SEMICONDUCTOR, INC.
Reel/Frame 038083/0272 →
LICENSE Recorded Mar 23, 2016
From: MARVELL WORLD TRADE LTD.
To: MARVELL INTERNATIONAL LTD.
Reel/Frame 038083/0376 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 23, 2016
From: MARVELL SEMICONDUCTOR, INC.
To: MARVELL INTERNATIONAL LTD.
Reel/Frame 038083/0309 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 23, 2016
From: MARVELL INTERNATIONAL LTD.
To: MARVELL WORLD TRADE LTD.
Reel/Frame 038083/0340 →
Continuity (3)
Provisional Application 61842613 · Jul 3, 2013
Provisional Application 61773317 · Mar 6, 2013
Related Publication 20140258724A1 · Sep 11, 2014