IP Library › Granted Patent US 12,381,746
Granted Patent B2
US 12,381,746 · App. 18/265,943 · Granted Aug 5, 2025

Provisioning system for cloud-connected printers

Inventors: Andrew J. Pekarske (Mundelein, IL); James P. Van Huis (Des Plaines, IL); Ryan E. Brock (Cary, IL)
Assignee: Zebra Technologies Corporation
H04L9/3268G06F3/1224G06F3/1238G06F21/608H04L9/3265H04N1/00244
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,381,746
App. No.
18/265,943
Granted
Aug 5, 2025
Kind
B2
Abstract

A method, in a provisioning server, of provisioning a printer, includes: receiving a provisioning request from the printer, the provisioning request containing (i) a printer identifier, and (ii) an account identifier associated with the printer; obtaining, from a digital certificate issuer, a unique string; sending the unique string to the printer; receiving from the printer, in response to sending the unique string, a certificate signing request containing (i) the printer identifier, (ii) the account identifier, and (iii) an authentication token including the unique string signed with a private key of the printer; validating the certificate signing request; passing the validated certificate signing request to the digital certificate issuer; receiving, from the digital certificate issuer, a digital certificate encoding the printer identifier and the account identifier; and providing the digital certificate to the printer for storage.

Claims (48)

1. A method to provision a device, the method comprising:

receiving a provisioning request from the device, the provisioning request containing (i) a device identifier, and (ii) an account identifier associated with the device;

obtaining, from a digital certificate issuer, a unique string;

sending the unique string to the device;

receiving from the device, in response to sending the unique string, a certificate signing request containing (i) the device identifier, (ii) the account identifier, and (iii) an authentication token including the unique string signed with a private key of the device;

validating the certificate signing request;

passing the validated certificate signing request to the digital certificate issuer;

receiving, from the digital certificate issuer, a digital certificate encoding the device identifier and the account identifier; and

providing the digital certificate to the device for storage.

2. The method of claim 1 , wherein the certificate signing request includes a second digital certificate corresponding to a cryptographic controller of the device.

3. The method of claim 2 , wherein validating the certificate signing request includes:

retrieving manufacturing data corresponding to the device; and

verifying that the manufacturing data indicates an association between the device identifier and the second digital certificate.

4. The method of claim 1 , wherein validating the certificate signing request includes determining whether the device identifier is present in a repository of manufacturing data.

5. The method of claim 1 , wherein providing the digital certificate to the device includes sending (i) the digital certificate, and (ii) a network identifier of a server, for use by the device to establish a secure connection with the server using the digital certificate.

6. A provisioning server, comprising:

a communications interface; and

a processor configured to:

receive a provisioning request from a device, the provisioning request containing (i) a device identifier, and (ii) an account identifier associated with the device;

obtain, from a digital certificate issuer, a unique string;

send the unique string to the device;

receive from the device, in response to sending the unique string, a certificate signing request containing (i) the device identifier, (ii) the account identifier, and (iii) an authentication token including the unique string signed with a private key of the device;

validate the certificate signing request;

pass the certificate signing request to the digital certificate issuer;

receive, from the digital certificate issuer, a digital certificate encoding the device identifier and the account identifier; and

provide the digital certificate to the device for storage.

7. The provisioning server of claim 6 , wherein the certificate signing request includes a second digital certificate corresponding to a cryptographic controller of the device.

8. The provisioning server of claim 6 , wherein the processor is configured, to validate the certificate signing request, to determine whether the device identifier is present in a repository of manufacturing data.

9. The provisioning server of claim 6 , wherein the processor is configured, to provide the digital certificate to the device, to send (i) the digital certificate, and (ii) a network identifier of a server, for use by the device to establish a secure connection with the server using the digital certificate.

10. A method comprising:

communicating with a first server by a first device, the server having a first network identifier;

receiving, from the first server by the first device, a second network identifier associated with a second server from which a second device may receive provisioning data;

transmitting the second network identifier from the first device to the second device;

issuing commands, from the first device, to the first server to communicate with the second device after the second device is provisioned based on the provisioning data.

11. The method of claim 10 , wherein the second network identifier is received from the server via a network and the second network identifier is wirelessly transmitted to the second device by the first device.

12. The method of claim 10 , wherein transmitting the second network identifier to the second device is performed in response to the first device receiving a provisioning message from the second device.

13. The method of claim 12 , wherein the provisioning message includes a serial number of the second device.

14. The method of claim 12 where the provisioning message includes an indication that the second device is un-provisioned.

15. The method of claim 10 , further comprising:

transmitting, by the first device, commands to the first server for relay to the second device.

16. The method of claim 10 , wherein the second device is a printer.

17. A method comprising:

transmitting, from a device to a server, a first message including a device identifier associated with the device;

receiving, by the device from the server, a first response including a string;

signing, by the device, the string with a private key of the device to create a signed unique string;

transmitting, from the device to the server to the server, a second message including the signed unique string;

receiving, by the device from the provisioning server, a second response including a network address of a second server for use by the device to establish a secure connection with the second server.

18. The method of claim 17 , wherein the second message includes the device identifier.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 11, 2025
From: PEKARSKE, ANDREW J.; VAN HUIS, JAMES P.; BROCK, RYAN E.; ROUNDY, JARED COY
To: ZEBRA TECHNOLOGIES CORPORATION
Reel/Frame 071684/0174 →
Continuity (2)
Continuation 17118046 · Dec 10, 2020
Related Publication 20250080361A1 · Mar 6, 2025
References Cited (15)
US 7489243B2 · Brown et al. · 2009 [cited by applicant]
US 7707405B1 · Gilman et al. · 2010 [cited by applicant]
US 10318216B2 · Anno · 2019 [cited by applicant]
US 11336466B1 · Pekarske · 2022 [cited by examiner]
US 20070150420A1 · Iwamoto et al. · 2007 [cited by applicant]
US 20080211840A1 · Zevin et al. · 2008 [cited by applicant]
US 20090031410A1 · Schneider et al. · 2009 [cited by applicant]
US 20100094979A1 · Azami · 2010 [cited by examiner]
US 20140240753A1 · Anno et al. · 2014 [cited by applicant]
US 20160371032A1 · Hill et al. · 2016 [cited by applicant]
US 20180212950A1 · Nogawa · 2018 [cited by applicant]
US 20190361632A1 · Hosoda · 2019 [cited by applicant]
US 20200076803A1 · Saito · 2020 [cited by examiner]
Novelty Search Report for Belgian Patent Application No. 2021/5971 mailed on Sep. 14, 2022. [cited by applicant]
International Search Report and Written Opinion for International Application No. PCT/US2021/058941 mailed on Jan. 11, 2022. [cited by applicant]