IP Library Granted Patent US 11,626,975
Granted Patent B2
US 11,626,975 · App. 17/150,470 · Granted Apr 11, 2023

Secure online issuance of customer-specific certificates with offline key generation

Inventors: Alexander Medvinsky (San Diego, CA); Tat Keung Chan (San Diego, CA); Xin Qiu (San Diego, CA); Jason A. Pasion (San Diego, CA); Ting Yao (San Diego, CA); Shanthakumar Ramakrishnan (Westford, MA)
Assignee: ARRIS Enterprises LLC
H04L9/0822E02B3/106E02B3/122H04L9/3247H04L9/3268
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,626,975
App. No.
17/150,470
Filed
Jan 15, 2021
Granted
Apr 11, 2023
Kind
B2
Examiner
KHAN, SHER A
Art Unit
2497
USPC
713/156
Abstract

In a system comprising an customer providing a service to a plurality of client devices, a method and system for providing an customer-specific digital certificate to a client device of the plurality of client devices is disclosed. The method comprises receiving, in an intermediate certificate authority, a pre-generated digital certificate and an encrypted client device private key encrypted according to a private key encryption key PrKEK, receiving, from the client device, a request for the customer-specific digital certificate, the request comprising at least one of client device identifying information and information identifying the customer, the request signed according to a pre-provisioned client device digital certificate, and transmitting the customer-specific digital certificate and the encrypted client device private key to the client device.

Claims (73)

1. A method of providing a customer-specific digital certificate to a client device of a plurality of client devices, the method comprising:

receiving, in an online certificate authority, a pre-generated digital certificate and an encrypted client device private key encrypted according to a private key encryption key PrKEK;

receiving, from the client device, a request for the customer-specific digital certificate, the request comprising at least one of client device identifying information and information identifying the customer, the request signed according to a pre-provisioned client device digital certificate;

building the customer-specific digital certificate from the pre-generated digital certificate, a selected target digital certificate template, the client device identifying information, and the customer identifying information, comprising:

identifying the client device from the client device identifying information;

identifying the customer;

retrieving the pre-generated digital certificate;

selecting the target digital certificate template for the client device based at least in part upon the information identifying the customer, the target digital certificate template having attributes that vary according to the customer;

generating the customer-specific digital certificate according to the retrieved pre-generated digital certificate, the target digital certificate template and the client device identifying information;

accessing a customer-specific digital certificate signing key from a certificate authority associated with the identified customer;

re-signing the customer specific digital certificate with the customer specific digital certificate signing key; and

transmitting the customer-specific digital certificate and the encrypted client device private key to the client device; wherein

the customer-specific digital certificate is the pre-generated digital certificate uniquely associated with the client device identifying information; and

the pre-generated digital certificate is one of a batch of pre-generated digital certificates for a group of the plurality of client devices of which the client device is a member, and is provided to an online certificate authority before receiving the request for the customer-specific digital certificate.

2. The method of claim 1 , wherein:

the pre-provisioned client device digital certificate is a global digital certificate; and

the client device identifying information is explicitly provided in the request for the customer-specific digital certificate.

3. The method of claim 1 , wherein:

the pre-provisioned client device digital certificate is unique to the client device; and

the client device identifying information is determined from the pre-provisioned client device digital certificate.

4. The method of claim 1 , wherein:

the system comprises a plurality of customers providing services to the plurality of client devices; and

the private key encryption key PrKEK is a common encryption key shared among all devices for all customers.

5. The method of claim 1 , wherein:

the system comprises a plurality of customers providing services to the plurality of client devices, and the private key encryption key PrKEK is different for each of the plurality of customers.

6. The method of claim 5 , wherein:

the private key encryption key PrKEK is different for each of the plurality of client devices.

7. The method of claim 1 , wherein the client device identifying information is a MAC address of the client device.

8. The method of claim 7 , wherein the information identifying the customer includes one or more of:

a customer identifier;

a device credential profile identifier of the client device; and

a MAC address of the client device.

9. The method of claim 1 , wherein:

identifying the client device from the client device identifying information comprises:

extracting the client device identifying information from the pre-provisioned client device digital certificate; and

identifying the customer comprises:

identifying the customer according to a comparison between the client device identifying information and a pre-determined mapping of the client device identifying information and the customer provided to an online certificate authority.

10. The method of claim 1 , wherein:

identifying the client device from the client device identifying information comprises:

extracting the client device identifying information from the request for the customer-specific digital certificate; and

identifying the customer comprises:

extract the customer identifying information from the request.

11. The method of claim 1 , wherein:

the client device pre-provisioned digital certificate comprises a MAC address of the client device; and

the customer is identified according to a comparison of the MAC address of the client device and whitelist of MAC addresses for each of the plurality of customers.

12. The method of claim 1 , wherein each pre-provisioned client device digital certificate is pre-installed in the associated client device at a factory producing the client device.

13. In a system comprising a plurality of customers providing services to a plurality of client devices, an apparatus for providing an customer-specific digital certificate to a client device of the plurality of client devices, comprising:

a processor;

a memory, communicatively coupled to the processor, the memory storing processor instructions comprising processor instructions for:

receiving, in an on line certificate authority, a pre-generated digital certificate and an encrypted client device private key encrypted according to a private key encryption key PrKEK;

receiving, from the client device, a request for the customer-specific digital certificate, the request comprising at least one of client device identifying information and information identifying the customer, the request signed according to a pre-provisioned client device digital certificate; and

building the customer-specific digital certificate from the pre-generated digital certificate, a selected target digital certificate template, the client device identifying information, and the customer identifying information, comprising:

identifying the client device from the client device identifying information;

identifying the customer;

retrieving the pre-generated digital certificate;

selecting the target digital certificate template for the client device based at least in part upon the information identifying the customer, the target digital certificate template having attributes that vary according to the customer;

generating the customer specific digital certificate according to the retrieved pre-generated digital certificate, the target digital certificate template and the client device identifying information;

accessing an customer-specific digital certificate signing key from a certificate authority associated with the identified customer;

re-signing the customer specific digital certificate with the customer specific digital certificate signing key; and

transmitting the customer-specific digital certificate and the encrypted client device private key to the client device; wherein

the customer-specific digital certificate is the pre-generated digital certificate uniquely associated with the client device identifying information; and

the pre-generated digital certificate is one of a batch of pre-generated digital certificates for a group of the plurality of client devices of which the client device is a member, and is provided to an online certificate authority before receiving the request for the customer-specific digital certificate.

14. The apparatus of claim 13 , wherein:

the pre-provisioned client device digital certificate is a global digital certificate; and

the client device identifying information is explicitly provided in the request for the customer-specific digital certificate.

15. The apparatus of claim 13 , wherein:

the pre-provisioned client device digital certificate is unique to the client device; and

the client device identifying information is determined from the pre-provisioned client device digital certificate.

16. The apparatus of claim 13 , wherein:

the system comprises a plurality of customers providing services to the plurality of client devices; and

the private key encryption key PrKEK is a common encryption key shared among all devices for all customers.

17. The apparatus of claim 13 , wherein:

the system comprises a plurality of customers providing services to the plurality of client devices, and the private key encryption key PrKEK is different for each of the plurality of customers.

Assignments (8)
SECURITY INTEREST Recorded Apr 8, 2026
From: ARRIS ENTERPRISES LLC; RUCKUS IP HOLDINGS LLC
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 075476/0814 →
RELEASE OF SECURITY INTEREST AT REEL/FRAME 058843/0712 Recorded Jan 12, 2026
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: ARRIS ENTERPRISES LLC; COMMSCOPE NORTH CAROLINA, LLC (F/K/A COMMSCOPE, INC. OF NORTH CAROLINA); COMMSCOPE TECHNOLOGIES LLC
Reel/Frame 074591/0389 →
RELEASE OF SECURITY INTEREST AT REEL/FRAME 058875/0449 Recorded Dec 19, 2024
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: ARRIS ENTERPRISES LLC (F/K/A ARRIS ENTERPRISES, INC.); COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC
Reel/Frame 069743/0057 →
SECURITY INTEREST Recorded Dec 17, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE INC., OF NORTH CAROLINA; OUTDOOR WIRELESS NETWORKS LLC; RUCKUS IP HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC
Reel/Frame 069889/0114 →
SECURITY INTEREST Recorded Nov 19, 2021
From: ARRIS SOLUTIONS, INC.; ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA; RUCKUS WIRELESS, INC.
To: WILMINGTON TRUST
Reel/Frame 060752/0001 →
ABL SECURITY AGREEMENT Recorded Nov 15, 2021
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 058843/0712 →
TERM LOAN SECURITY AGREEMENT Recorded Nov 15, 2021
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 058875/0449 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 15, 2021
From: MEDVINSKY, ALEXANDER; CHAN, TAT KEUNG; QIU, XIN; PASION, JASON A.; YAO, TING; RAMAKRISHNAN, SHANTHAKUMAR
To: ARRIS ENTERPRISES LLC
Reel/Frame 054935/0661 →
Continuity (2)
Provisional Application 62994996 · Mar 26, 2020
Related Publication 20210306161A1 · Sep 30, 2021