IP Library Granted Patent US 10,291,595
Granted Patent B2
US 10,291,595 · App. 15/824,173 · Granted May 14, 2019

System and method for securely connecting network devices

Inventors: Joe Britt (Los Altos, CA); Shin Matsumura (Los Altos, CA); Houman Forood (San Francisco, CA); Scott Zimmerman (Mountain View, CA); Phillip Myles (Los Altos, CA); Sean Zawicki (Mountain View, CA); Daisuke Kutami (San Francisco, CA); Shannon Holland (Los Gatos, CA)
Assignee: Afero, Inc.
H04L63/0428H04L9/0897H04L12/2854H04L63/0478H04L63/062H04L67/12H04L67/141H04W12/04H04L63/061H04L63/18H04L2209/805H04W4/70H04W12/02H04W84/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,291,595
App. No.
15/824,173
Granted
May 14, 2019
Kind
B2
Abstract

A platform, apparatus and method for Internet of Things Implementations. For example, one embodiment of a system comprises: an Internet of Things (IoT) hub comprising a network interface to couple the IoT hub to an IoT service over a wide area network (WAN), and programming logic to program an identification device with one or more encryption keys usable to establish encrypted communication with an IoT device; and at least one IoT device interfacing with the identification device following programming of the identification device by the IoT hub; wherein once the identification device is programmed and interfaced with the IoT device, the IoT device uses the one or more keys to establish a secure communication channel with the IoT hub and/or the IoT service.

Claims (24)

1. An internet of things (IoT) hub comprising:

programming logic to generate an IoT device public/private key pair for an IoT device and to store the IoT device private key on an identification device of the IoT device, the IoT device public/private key pair usable for secure communication with the IoT device;

a secure hardware storage to store the IoT device public key and an IoT hub private key of an IoT hub public/private key pair; and

a network interface to communicatively couple the IoT hub to an IoT service over a wide area network (WAN), the IoT hub securely forwarding the IoT device public key and the IoT hub public key to the IoT service over the network interface;

wherein the IoT hub receives a first network packet from the IoT service, the first network packet comprising an IoT hub packet encrypted with the IoT hub public key;

wherein the IoT hub decrypts the first network packet using the IoT hub private key to generate an IoT device packet, the IoT device packet comprising a command/data encrypted with the IoT device public key; and

wherein the IoT hub forwards the IoT device packet to the IoT device, the IoT device packet to be decrypted by the IoT device using the IoT device private key.

2. The IoT hub of claim 1 , wherein the programming logic is further to store the IoT hub public key on the identification device of the IoT device.

3. The IoT hub of claim 1 , wherein the identification device is a subscriber identity module (SIM).

4. The IoT hub of claim 1 , wherein the identification device comprises a secure key storage for storing a private key provided by the programming logic.

5. The IoT hub of claim 1 , wherein the identification device is attached to the IoT device.

6. A method implemented in an IoT hub, the method comprising:

generating an IoT device public/private key pair usable for secure communication with an IoT device;

generating an IoT hub public/private key pair usable for secure communication with the IoT hub;

storing the IoT device private key on an identification device of the IoT device;

storing the IoT device public key and the IoT hub private key in a secure hardware storage;

forwarding the IoT device public key and the IoT hub public key to an IoT service over a wide area network (WAN);

receiving a first network packet from the IoT service, the first network packet comprising an IoT hub packet encrypted with the IoT hub public key;

decrypting the first network packet using the IoT hub private key to generate an IoT device packet, the IoT device packet comprising a command/data encrypted with the IoT device public key; and

forwarding the IoT device packet to the IoT device, the IoT device packet to be decrypted by the IoT device using the IoT device private key.

7. The method of claim 6 , further comprising storing the IoT hub public key on the identification device of the IoT device.

8. The method of claim 6 , wherein the identification device is a subscriber identity module (SIM).

9. The method of claim 6 , wherein the identification device comprises a secure key storage for storing a private key.

10. The method of claim 6 , wherein the identification device is attached to the IoT device.

Continuity (2)
Continuation 14575463 · Dec 18, 2014
Related Publication 20180152420A1 · May 31, 2018
Cited By (2)
US 12,294,629 US 12,520,141