IP Library Granted Patent US 12,307,239
Granted Patent B2
US 12,307,239 · App. 18/391,377 · Granted May 20, 2025

Credential-changing plugin for IoT devices

Inventors: Christopher J. Rouland (Nashville, TN); Earle W. Ady (Jackson, WY); Trent Altman (Carlsbad, CA)
Assignee: PHOSPHORUS CYBERSECURITY INC.
G06F8/654G06F8/71G06F21/572G16Y30/00H04L9/0637H04L9/3236H04L67/34H04L9/50
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,307,239
App. No.
18/391,377
Granted
May 20, 2025
Kind
B2
Abstract

A process for management of Internet-of-Things (IoT) devices includes a management system for identifying, interrogating, and updating devices connected to one or more networks. The management system can include a data store for storing various data related to the devices and the various processes of the management system. The management system can include a controller for executing processes such as interrogation processes, firmware change processes, credential change processes, and other processes. The controller can determine versions of firmware and other configuration properties of a device and generate various profiles for updating the firmware and other configuration properties. The controller can determine upgrade paths for updating the firmware and other configuration properties from a first version to a second version, the upgrade paths including one or more intermediary versions for facilitating the upgrade path. The management system can update devices individually, on a device family basis, or on a system-wide basis.

Claims (56)

1. A system comprising:

a data store comprising a data mapping of a plurality of credentials to a plurality of internet of thing (IoT) devices;

a plugin configured to be installed on an external system; and

at least one computing device in communication with the data store, the at least one computing device being configured to at least:

receive, from the plugin:

a security component of a particular credential of the plurality of credentials, and

a request to change the security component, wherein the request is initiated by the external system;

identify a particular IoT device of the plurality of IoT devices corresponding to the particular credential according to the data mapping in the data store;

determine a credential change profile corresponding to the particular IoT device, wherein the credential change profile specifies at least one protocol supported by the particular IoT device;

perform an authentication with the particular IoT device using the security component;

determine that the particular IoT device is available; and

initiate changing of the particular credential for the particular IoT device over a network based on the request.

2. The system of claim 1 , wherein the external system comprises a privileged asset management (PAM) system.

3. The system of claim 1 , wherein the plurality of credentials is generated by the external system.

4. The system of claim 1 , wherein the data store further comprises credential data.

5. The system of claim 4 , wherein the credential data comprises one or more of: usernames, passwords, signatures, public-private key pairs, and default versions thereof.

6. The system of claim 4 , wherein the credential data comprises one or more identifiers associated with device-identifying information for the particular IoT device.

7. The system of claim 4 , wherein the plugin determines rules for changing the particular credential based on the credential data.

8. The system of claim 1 , wherein the plugin is configured to send the request to change the security component to the at least one computing device after the external system initiates an update of the security component.

9. The system of claim 1 , wherein the at least one computing device is further configured to register the plurality of credentials with the external system via the plugin.

10. The system of claim 1 , wherein the at least one computing device is further configured to:

determine a plurality of sets of password limitations, where each set of password limitations corresponds to a respective one of the plurality of IoT devices;

generate a plurality of password policies for the plurality of IoT devices; and

determine a respective password policy of the plurality of password policies for each of the plurality of credentials in the external system according to the data mapping.

11. The system of claim 1 , wherein the at least one computing device is further configured to:

determine that the particular IoT device is unavailable based at least in part on the changing of the particular credential failing;

store an incomplete credential change in the data store; and

in response to determining the particular IoT device is subsequently available, reinitiate changing of the credential for the particular IoT device over the network based on the credential change profile.

12. A method comprising:

receiving, via at least one computing device in communication with a data store comprising a data mapping of a plurality of credentials to a plurality of internet of thing (IoT) devices, from a plugin configured to be installed on an external system:

a security component of a particular credential of the plurality of credentials, and

a request to change the security component, wherein the request is initiated by the external system;

identifying, via the at least one computing device, a particular IoT device of the plurality of IoT devices corresponding to the particular credential according to the data mapping in the data store;

determining a credential change profile corresponding to the particular IoT device, wherein the credential change profile specifies at least one protocol supported by the particular IoT device;

performing, via the at least one computing device, an authentication with the particular IoT device using the security component;

determining, via the at least one computing device, that the particular IoT device is available; and

initiating, via the at least one computing device, changing of the particular credential for the particular IoT device over a network based on the request.

13. The method of claim 12 , further comprising: sending, via the plugin, the request to change the security component to the at least one computing device after the external system initiates an update of the security component.

14. The method of claim 12 , further comprising: registering, via the plugin, the plurality of credentials with the external system.

15. The method of claim 12 , further comprising:

determining, via the at least one computing device, a plurality of sets of password limitations, where each set of password limitations corresponds to a respective one of the plurality of IoT devices;

generating, via the at least one computing device, a plurality of password policies for the plurality of IoT devices; and

determining, via the at least one computing device, a respective password policy of the plurality of password policies for each of the plurality of credentials in the external system according to the data mapping.

16. The method of claim 12 , further comprising:

determining, via the at least one computing device, that the particular IoT device is unavailable based at least in part on the changing of the particular credential failing; store an incomplete credential change in the data store; and

in response to determining the particular IoT device is subsequently available, reinitiating, via the at least one computing device, changing of the credential for the particular IoT device over the network based on the credential change profile.

17. The method of claim 12 , wherein initiating changing of the particular credential for the particular IoT device is performed via the at least one protocol.

18. A non-transitory computer-readable medium embodying a program that, when executed by at least one computing device in communication with a data store comprising a data mapping of a plurality of credentials to a plurality of internet of thing (IT) devices, causes the at least one computing device to at least:

receive, from a plugin configured to be installed on an external system:

a security component of a particular credential of the plurality of credentials, and

a request to change the security component, wherein the request is initiated by the external system;

identify a particular IoT device of the plurality of IoT devices corresponding to the particular credential according to the data mapping in the data store;

determine a credential change profile corresponding to the particular IoT device, wherein the credential change profile specifies at least one protocol supported by the particular IoT device;

perform an authentication with the particular IoT device using the security component;

determine that the particular IT device is available; and

initiate changing of the particular credential for the particular IoT device over a network based on the request.

Assignments (2)
SECURITY INTEREST Recorded May 8, 2026
From: PHOSPHORUS SECURITY LLC
To: ACQUIOM AGENCY SERVICES LLC
Reel/Frame 074605/0236 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 12, 2024
From: ROULAND, CHRISTOPHER J.; ADY, EARLE W.; ALTMAN, TRENT
To: PHOSPHORUS CYBERSECURITY INC.
Reel/Frame 066116/0701 →
Continuity (5)
Continuation 17985662 · Nov 11, 2022
Continuation 16937739 · Jul 24, 2020
Continuation 16914851 · Jun 29, 2020
Provisional Application 62867352 · Jun 27, 2019
Related Publication 20240126539A1 · Apr 18, 2024
References Cited (73)
US 7219343B2 · Almeida et al. · 2007 [cited by applicant]
US 8214473B1 · Wexler · 2012 [cited by applicant]
US 8554883B2 · Sankaran · 2013 [cited by examiner]
US 8625802B2 · Parann-Nissany · 2014 [cited by applicant]
US 9778999B2 · Martin et al. · 2017 [cited by applicant]
US 9836296B2 · Vandikas et al. · 2017 [cited by applicant]
US 10050978B2 · Morton et al. · 2018 [cited by applicant]
US 10218780B2 · Jain et al. · 2019 [cited by applicant]
US 10541867B2 · Velupillai · 2020 [cited by applicant]
US 10594482B2 · Bender · 2020 [cited by examiner]
US 10659246B2 · Guedalia et al. · 2020 [cited by applicant]
US 10942728B2 · Rusev et al. · 2021 [cited by applicant]
US 11032293B2 · Biyani et al. · 2021 [cited by applicant]
US 11269619B2 · Rouland et al. · 2022 [cited by applicant]
US 11301240B2 · Rouland et al. · 2022 [cited by applicant]
US 11500624B2 · Rouland et al. · 2022 [cited by applicant]
US 11520577B2 · Rouland et al. · 2022 [cited by applicant]
US 11886866B2 · Rouland · 2024 [cited by applicant]
US 11941390B2 · Rouland · 2024 [cited by applicant]
US 20080126478A1 · Ferguson · 2008 [cited by examiner]
US 20090319848A1 · Thaper · 2009 [cited by applicant]
US 20100325707A1 · Iverson et al. · 2010 [cited by applicant]
US 20110055899A1 · Dollar · 2011 [cited by applicant]
US 20140123124A1 · Gray et al. · 2014 [cited by applicant]
US 20140241354A1 · Shuman · 2014 [cited by examiner]
US 20140244834A1 · Guedalia et al. · 2014 [cited by applicant]
US 20150281227A1 · Fox Ivey · 2015 [cited by examiner]
US 20160350097A1 · Mahapatra et al. · 2016 [cited by applicant]
US 20180091526A1 · Cammarota et al. · 2018 [cited by applicant]
US 20180103039A1 · Thaler et al. · 2018 [cited by applicant]
US 20180145978A1 · Kim et al. · 2018 [cited by applicant]
US 20180176229A1 · Bathen et al. · 2018 [cited by applicant]
US 20200104509A1 · Furuichi et al. · 2020 [cited by applicant]
US 20200177589A1 · Mangalvedkar · 2020 [cited by examiner]
US 20200334229A1 · Harrison et al. · 2020 [cited by applicant]
US 20200409687A1 · Rouland et al. · 2020 [cited by applicant]
US 20200409688A1 · Rouland et al. · 2020 [cited by applicant]
US 20200409689A1 · Rouland et al. · 2020 [cited by applicant]
US 20200409690A1 · Rouland et al. · 2020 [cited by applicant]
US 20210036912A1 · Madappa · 2021 [cited by applicant]
US 20210126826A1 · Nolan et al. · 2021 [cited by applicant]
US 20230236824A1 · Rouland et al. · 2023 [cited by applicant]
US 20230236825A1 · Rouland et al. · 2023 [cited by applicant]
EP 1449347B1 · 2012 [cited by applicant]
WO 2020264535A1 · 2020 [cited by applicant]
Combined Search and Abbreviated Examination Report under Sections 17 and 18(3), mailed Mar. 13, 2023, for United Kingdom Application No. GB2300910.3, 9 pages. [cited by applicant]
Combined Search and Abbreviated Examination Report under Sections 17 and 18(3), mailed Mar. 13, 2023, for United Kingdom Application No. GB2300917.8, 9 pages. [cited by applicant]
Combined Search and Abbreviated Examination Report under Sections 17 and 18(3), mailed Mar. 13, 2023, for United Kingdom Application No. GB2300920.2, 9 pages. [cited by applicant]
Examination Report under Section 18(3), mailed Jul. 8, 2022, for United Kingdom Application No. GB2118817.2, 3 pages. [cited by applicant]
Extended European Search Report for EP Application No. 20831341.1, mailed on Dec. 20, 2022, 8 pages. [cited by applicant]
Final Office Action, mailed Mar. 18, 2022, for U.S. Appl. No. 16/937,739, filed Jul. 24, 2020, 43 pages. [cited by applicant]
Final Office Action, mailed Oct. 6, 2021, for U.S. Appl. No. 16/937,738, filed Jul. 24, 2020, 37 pages. [cited by applicant]
Intention to Grant under Section 18(4), mailed Dec. 20, 2022, for United Kingdom Application No. GB2118817.2, 2 pages. [cited by applicant]
International Preliminary Report on Patentability for International Application PCT/US2020/043265, issue date of Dec. 28, 2021, filed Jul. 23, 2020, 8 pages. [cited by applicant]
International Search Report and Written Opinion for International PCT Application No. PCT/US2020/043265, mailed Oct. 29, 2020, filed Jul. 23, 2020, 9 pages. [cited by applicant]
Lee, B. et al. (Sep. 13, 2016). “Blockchain-based Secure Firmware Update for Embedded Devices in an Internet of Things Environment,” The Journal of Supercomputing 73(3):1152-1167. [cited by applicant]
Lu, C.H. et al. (Sep. 17, 2017). “A Secure Firmware Upgrade Scheme with Private-tracker-governed and Smart-contract-driven Design for Blockchain-enabled IoT Devices,” 1-6 pages. http://maselab318.nfu.edu.tw/tsong/CACS/C… [cited by applicant]
Non-Final Office Action, mailed Aug. 12, 2021, for U.S. Appl. No. 16/937,738, filed Jul. 24, 2020, 31 pages. [cited by applicant]
Non-Final Office Action, mailed Jan. 24, 2022, for U.S. Appl. No. 16/937,738, filed Jul. 24, 2020, 37 pages. [cited by applicant]
Non-Final Office Action, mailed Jun. 4, 2021, for U.S. Appl. No. 16/914,851, filed Jun. 29, 2020, 6 pages. [cited by applicant]
Non-Final Office Action, mailed on Sep. 22, 2021, for U.S. Appl. No. 16/937,744, filed Jul. 24, 2020, 39 pages. [cited by applicant]
Non-Final Office Action, mailed Sep. 1, 2021, for U.S. Appl. No. 16/937,739, filed Jul. 24, 2020, 40 pages. [cited by applicant]
Notice of Allowance and Fees Due, mailed Dec. 14, 2021, for U.S. Application No. 16/914, 851, filed Jun. 29, 2020, 7 pages. [cited by applicant]
Notice of Allowance and Fees Due, mailed Dec. 8, 2023, for U.S. Appl. No. 18/071,362, filed Nov. 29, 2022, 8 pages. [cited by applicant]
Notice of Allowance and Fees Due, mailed Feb. 8, 2022, for U.S. Appl. No. 16/937,744, filed Jul. 24, 2020, 8 pages. [cited by applicant]
Notice of Allowance and Fees Due, mailed Jul. 27, 2022, for U.S. Appl. No. 16/937,738, filed Jul. 24, 2020, 8 pages. [cited by applicant]
Notice of Allowance and Fees Due, mailed Jun. 23, 2022, for U.S. Appl. No. 16/937,739, filed Jul. 24, 2020, 7 pages. [cited by applicant]
Notice of Allowance and Fees Due, mailed Nov. 9, 2022, for U.S. Appl. No. 16/937,738, filed Jul. 24, 2020, 5 pages. [cited by applicant]
Notice of Allowance and Fees Due, mailed Oct. 20, 2022, for U.S. Appl. No. 16/937,739, filed Jul. 24, 2020, 4 pages. [cited by applicant]
Notice of Allowance and Fees Due, mailed Sep. 25, 2023, for U.S. Appl. No. 17/985,662, filed Nov. 11, 2022, 8 pages. [cited by applicant]
Preliminary Examination Report, mailed on Jan. 24, 2023, for United Kingdom Application No. GB2300920.2, 2 pages. [cited by applicant]
Written Opinion, mailed Oct. 31, 2022, for Singapore Application No. 11202113319T, filed Jul. 23, 2020, 6 pages. [cited by applicant]
Yu, M. et al. (Dec. 25, 2018). “Internet of Things Security and Privacy-Preserving Method Through Nodes Differentiation, Concrete Cluster Centers, Multi-Signature, and Blockchain,” International Journal of Distributed S… [cited by applicant]