IP Library Granted Patent US 10,270,770
Granted Patent B1
US 10,270,770 · App. 16/110,567 · Granted Apr 23, 2019

Generic computing device attestation and enrollment

Inventors: Susanto Junaidi Irwan (San Francisco, CA); Roman M. Arutyunov (San Jose, CA); Ganesh B. Jampani (Gilroy, CA); Andy Sugiarto (Moraga, CA)
Assignee: Xage Security, Inc.
H04L63/0876H04L9/0637H04L9/085H04L9/3271
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,270,770
App. No.
16/110,567
Granted
Apr 23, 2019
Kind
B1
Abstract

Secure enrollment of devices into computer networks is improved by a method that comprises receiving a first set of security data for computing devices from a vendor computing device and a second set of security data from a partner computing device and storing the first and second set of security data in a data repository; issuing a first authentication challenge to the computing devices, wherein the challenge is based on the first set and the second set of device security data; receiving a first authentication response from the computing devices and cross-referencing the first authentication response with the first set and the second set of device security data; receiving a second authentication challenge from the computing devices, wherein the second authentication challenge is based on the first set of security data; and issuing a second authentication response to the computing devices and determining whether to enroll the computing devices.

Claims (43)

1. A computer-implemented method providing improvements in secure enrollment of computing devices in networks that use an attestation process to validate device identity, comprising:

receiving a first set of security service data and a second set of security service data for one or more Internet of Things (IoT) computing devices respectively from a vendor computing device and a partner computing device, the second set of security data comprising ownership information for the one or more IoT computing devices, and storing the first set and the second set of security service data as part of one or more IoT computing device records in a distributed blockchain data repository when an attestation timing has not been met;

when the attestation timing has been met, issuing by a security gateway device a first authentication challenge to the one or more IoT computing devices, wherein the first authentication challenge is based on the first set and the second set of device security service data;

in response to issuing the first authentication challenge, receiving a first authentication response from the one or more IoT computing devices and cross-referencing the first authentication response with the first set and the second set of device security service data;

when the attestation timing has been met, receiving a second authentication challenge from the one or more IoT computing devices, wherein the second authentication challenge is based on the first set of security service data;

in response to receiving the second authentication challenge, issuing a second authentication response to the one or more IoT computing devices; and

in response to both of receiving the first authentication response and issuing the second authentication response from and to the one or more IoT computing devices respectively, determining by the security gateway device with the attestation process whether to enroll the one or more IoT computing devices to the networks.

2. The computer-implemented method of claim 1 , wherein the first set of security service data comprises a shared secret, a gateway public key, or a device fingerprint.

3. The computer-implemented method of claim 2 , wherein the device fingerprint is generated based, at least in part, on two or more of: Central Processing Unit (CPU) data, memory data, a Media Access Control (MAC) address, a BIOS checksum, a hard drive serial number, a seed, firmware data, and a time of manufacture.

4. The computer-implemented method of claim 2 , wherein the device fingerprint was dynamically generated by the one or more computing devices.

5. The computer-implemented method of claim 2 , wherein the shared secret is based on a signed device serial number.

6. The computer-implemented method of claim 1 , wherein the second set of security service data comprises ownership data.

7. The computer-implemented method of claim 1 , further comprising:

in response to determining whether to enroll the one or more computing devices, enrolling the one or more computing devices into an owner network using Enrollment of Secure Transport (EST) protocol.

8. One or more non-transitory computer-readable storage media storing one or more instructions programmed for providing improvements in secure enrollment of computing devices in networks that use an attestation process to validate device identity and which, when executed by one or more intermediary computing devices, cause:

receiving a first set of security service data and a second set of security service data for one or more Internet of Things (IoT) computing devices respectively from a vendor computing device and a partner computing device, the second set of security data comprising ownership information for the one or more IoT computing devices, and storing the first set and the second set of security service data as part of one or more IoT computing device records in a distributed blockchain data repository when an attestation timing has not been met;

when the attestation timing has been met, issuing by a security gateway device a first authentication challenge to the one or more IoT computing devices, wherein the first authentication challenge is based on the first set and the second set of device security service data;

in response to issuing the first authentication challenge, receiving a first authentication response from the one or more IoT computing devices and cross-referencing the first authentication response with the first set and the second set of device security service data;

when the attestation timing has been met, receiving a second authentication challenge from the one or more IoT computing devices, wherein the second authentication challenge is based on the first set of security service data;

in response to receiving the second authentication challenge, issuing a second authentication response to the one or more IoT computing devices; and

in response to both of receiving the first authentication response and issuing the second authentication response from and to the one or more IoT computing devices respectively, determining by the security gateway device with the attestation process whether to enroll the one or more IoT computing devices to the networks.

9. The one or more non-transitory computer-readable storage media of claim 8 , wherein the first set of security service data comprises a shared secret, a gateway public key, or a device fingerprint.

10. The one or more non-transitory computer-readable storage media of claim 9 , wherein the device fingerprint is generated based, at least in part, on two or more of: Central Processing Unit (CPU) data, memory data, a Media Access Control (MAC) address, a BIOS checksum, a hard drive serial number, a seed, firmware data, and a time of manufacture.

11. The one or more non-transitory computer-readable storage media of claim 9 , wherein the device fingerprint was dynamically generated by the one or more computing devices.

12. The one or more non-transitory computer-readable storage media of claim 9 , wherein the shared secret is based on a signed device serial number.

13. The one or more non-transitory computer-readable storage media of claim 9 storing one or more further instructions which, when executed by the one or more intermediary computing devices, further cause:

in response to determining whether to enroll the one or more computing devices, enrolling the one or more computing devices into an owner network using Enrollment of Secure Transport (EST) protocol.

14. The one or more non-transitory computer-readable storage media of claim 8 , wherein the second set of security service data comprises ownership data.

15. A computer system providing improvements in secure enrollment of computing devices in networks that use an attestation process to validate device identity, the system comprising:

a distributed blockchain data repository;

a broker computing device that is communicatively coupled to the distributed blockchain data repository and comprising a first non-transitory data storage medium storing a first set of instructions which, when executed by the broker computing device, cause:

receiving a first set of security service data and a second set of security service data for one or more Internet of Things (IoT) computing devices respectively from a vendor computing device and a partner computing device, the second set of security data comprising ownership information for the one or more IoT computing devices, and storing the first set and the second set of security service data as part of one or more IoT computing device records in the distributed blockchain data repository when an attestation timing has not been met;

a gateway computing device that is communicatively coupled to the disturbed blockchain data repository and comprising a second non-transitory data storage medium storing a second set of instructions which, when executed by the gateway computing device, cause:

when the attestation timing has been met, issuing by a security gateway device a first authentication challenge to the one or more IoT computing devices, wherein the first authentication challenge is based on the first set and the second set of device security service data;

in response to issuing the first authentication challenge, receiving a first authentication response from the one or more IoT computing devices and cross-referencing the first authentication response with the first set and the second set of device security service data;

when the attestation timing has been met, receiving a second authentication challenge from the one or more IoT computing devices, wherein the second authentication challenge is based on the first set of security service data;

in response to receiving the second authentication challenge, issuing a second authentication response to the one or more IoT computing devices; and

in response to both of receiving the first authentication response and issuing the second authentication response from and to the one or more IoT computing devices respectively, determining by the security gateway device with the attestation process whether to enroll the one or more IoT computing devices to the networks.

16. The computer system of claim 15 , wherein the first set of security service data comprises a shared secret, a gateway public key, or a device fingerprint.

17. The computer system of claim 16 , wherein the device fingerprint is generated based, at least in part, on two or more of: Central Processing Unit (CPU) data, memory data, a Media Access Control (MAC) address, a BIOS checksum, a hard drive serial number, a seed, firmware data, and a time of manufacture.

18. The computer system of claim 16 , wherein the device fingerprint was dynamically generated by the one or more computing devices.

19. The computer system of claim 16 , wherein the shared secret is based on a signed device serial number.

20. The computer system of claim 15 , wherein the second set of security service data comprises ownership data.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 23, 2018
From: IRWAN, SUSANTO JUNAIDI; ARUTYUNOV, ROMAN M.; JAMPANI, GANESH B.; SUGIARTO, ANDY
To: XAGE SECURITY, INC.
Reel/Frame 046687/0146 →
Cited By (13)
US 12,231,586 US 12,236,435 US 12,248,577 US 12,271,479 US 12,321,951 US 12,341,890 US 12,354,079 US 12,463,693 US 12,483,419 US 12,524,755 US 12,530,698 US 12,602,697 US 12,651,268