IP Library › Granted Patent US 12,395,339
Granted Patent B2
US 12,395,339 · App. 18/452,276 · Granted Aug 19, 2025

Fast repowering using cryptographically protected identity

Inventors: Eric A. Voit (Bethesda, MD); Yesu Lu (San Jose, CA); Eliot Lear (Wetzikon, CH); Ashok K. Moghe (Pleasanton, CA)
Assignee: CISCO TECHNOLOGY, INC.
H04L9/3213H04L9/30H04L9/3273H04L9/3297
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,395,339
App. No.
18/452,276
Granted
Aug 19, 2025
Kind
B2
Abstract

A computing device connected to a power source via a combined power/data connection obtains an authentication request from the power source. The authentication request includes a freshness mechanism provided by the power source. The computing device signs an authentication response with a private key associated with a verified identity stored on the computing device. The authentication response includes the freshness mechanism. The computing device provides the authentication response to the power source, and receives power from the power source.

Claims (77)

1. A method comprising:

obtaining an authentication request at a computing device that is connected to a power source via a combined power/data connection, the authentication request including a freshness mechanism provided by the power source;

signing an authentication response with a private key associated with a verified identity of the computing device stored on the computing device, the authentication response including the freshness mechanism;

providing the authentication response to the power source;

receiving power at the computing device from the power source; and

obtaining a reauthentication token from the power source, the reauthentication token authenticating the computing device with the verified identity for a subsequent connection of the computing device to the power source, wherein the reauthentication token is encrypted with a public key associated with the private key.

2. The method of claim 1 , further comprising storing the reauthentication token in a nonvolatile memory of the computing device.

3. The method of claim 1 , further comprising:

detecting that the combined power/data connection between the computing device and the power source is disconnected;

providing the reauthentication token to the power source to enable the computing device to reauthenticate the verified identity to the power source after the combined power/data connection between the computing device and the power source has been reconnected; and

receiving power at the computing device from the power source over the combined power/data connection.

4. The method of claim 3 , further comprising authenticating the power source before providing the reauthentication token to the power source.

5. The method of claim 4 , wherein authenticating the power source comprises:

obtaining a timestamp signed by a private key associated with the power source; and

verifying the timestamp with a public key associated with the power source.

6. The method of claim 3 , wherein a power level received over the combined power/data connection after the combined power/data connection has been reconnected corresponds to a requested power level provided with the reauthentication token.

7. The method of claim 1 , further comprising:

establishing a mutually authenticated secure communication channel between the computing device and the power source; and

obtaining a reauthentication token from the power source.

8. The method of claim 1 , further comprising providing a requested power level from the computing device to the power source, wherein the power source provides the power to the computing device in response to the authentication response.

9. The method of claim 8 , further comprising:

receiving a default power level at the computing device before obtaining the authentication request; and

receiving the requested power level at the computing device after providing the authentication response.

10. The method of claim 1 , further comprising:

determining a first amount of power consumed by the computing device during a predetermined time period; and

providing to the power source an indication of the first amount of power.

11. The method of claim 1 , further comprising:

determining a first amount of power consumed by the computing device during a predetermined time period;

obtaining from the power source an indication of a second amount of power provided to the computing device by the power source during the predetermined time period; and

comparing the first amount of power with the second amount of power to determine a measure of power leakage over the combined power/data connection during the predetermined time period.

12. An apparatus comprising:

a combined power/data interface configured to receive power and communicate with a power source;

a hardware storage device configured to store a private key associated with a verified identity of the apparatus; and

a processor coupled to the combined power/data interface and the hardware storage device, the processor configured to:

obtain an authentication request via the combined power/data interface, the authentication request including a nonce provided by the power source;

sign the nonce with the private key to generate a signed nonce;

cause the combined power/data interface to provide an authentication response including the signed nonce to the power source;

receive power for the apparatus from the power source over the combined power/data interface; and

obtain a reauthentication token from the power source, the reauthentication token authenticating the apparatus with the verified identity for a subsequent connection of the apparatus to the power source, wherein the reauthentication token is encrypted with a public key associated with the Private key.

13. The apparatus of claim 12 , wherein the processor is further configured to:

detect that the combined power/data interface is disconnected from the power source;

determine that the combined power/data interface is reconnected to the power source;

cause the combined power/data interface to provide the reauthentication token to the power source to enable the apparatus to reauthenticate the verified identity to the power source; and

receive power for the apparatus from the power source over the combined power/data interface after it has been reconnected to the power source.

14. The apparatus of claim 13 , wherein a power level received over the combined power/data interface after the combined power/data interface has been reconnected to the power source corresponds to a requested power level indicated in the authentication response.

15. The apparatus of claim 12 , wherein the processor is further configured to:

establish a mutually authenticated secure communication channel between the apparatus and the power source; and

obtain a reauthentication token from the power source.

16. The apparatus of claim 12 , wherein the processor is further configured to cause the combined power/data interface to provide a requested power level to the power source, wherein the power source provides the power for the apparatus in response to the authentication response.

17. The apparatus of claim 16 , wherein the combined power/data interface is further configured to:

receive a default power level for the apparatus before obtaining the authentication request; and

receive the requested power level for the apparatus after providing the authentication response.

18. A system comprising:

a power source configured to provide power to devices associated with at least one of a plurality of verified identities; and

a computing device configured to:

connect to the power source via a combined power/data connection;

obtain an authentication request from the power source, the authentication request including a nonce provided by the power source;

sign the nonce with a private key stored on the computing device to generate a signed nonce, the private key associated with a verified identity of the computing device;

provide an authentication response including the signed nonce to the power source;

receive power at the computing device from the power source; and

obtain a reauthentication token from the power source, the reauthentication token authenticating the computing device with the verified identity for a subsequent connection of the computing device to the power source, wherein the reauthentication token is encrypted with a public key associated with the private key.

19. The system of claim 18 , wherein the computing device is further configured to:

detect that the combined power/data connection between the computing device and the power source is disconnected;

reconnect the combined power/data connection between the computing device and the power source;

provide the reauthentication token to the power source to enable the computing device to reauthenticate the verified identity to the power source; and

receive power at the computing device from the power source over the combined power/data connection.

20. The system of claim 19 , wherein the power source is configured to provide power to the computing device over the combined power/data connection after the combined power/data connection has been reconnected to the power source at a power level received that corresponds to a requested power level indicated in the authentication response.

21. The system of claim 19 , wherein the computing device authenticates the power source before providing the reauthentication token to the power source.

22. The system of claim 21 , wherein the computing device authenticates the power source by:

obtaining a timestamp signed by a private key associated with the power source; and

verifying the time stamp with a public key associated with the power source.

23. The system of claim 19 , wherein a power level received over the combined power/data connection after it has been reconnected corresponds to a requested power level provided with the reauthentication token.

24. The system of claim 18 , wherein the computing device is further configured to:

establish a mutually authenticated secure communication channel between the computing device and the power source; and

obtain a reauthentication token from the power source.

25. The system of claim 18 , further comprising an authentication server in communication with the power source, the authentication server configured to authorize the verified identity associated with the computing device to receive power from the power source.

26. The system of claim 18 , wherein the computing device determines a first amount of power consumed by the computing device during a predetermined time period, and provides to the power source an indication of the first amount of power.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 18, 2023
From: VOIT, ERIC A.; LU, YESU; LEAR, ELIOT; MOGHE, ASHOK K.
To: CISCO TECHNOLOGY, INC.
Reel/Frame 064638/0456 →
Continuity (2)
Provisional Application 63502957 · May 18, 2023
Related Publication 20240388435A1 · Nov 21, 2024
References Cited (51)
US 8918660B2 · Santos · 2014 [cited by examiner]
US 9860257B1 · Kumar et al. · 2018 [cited by applicant]
US 11193963B1 · Sizikov et al. · 2021 [cited by applicant]
US 11447030B1 · Palombini · 2022 [cited by examiner]
US 11977622B2 · Clish · 2024 [cited by examiner]
US 12238080B2 · Raghunath · 2025 [cited by examiner]
US 20060117176A1 · Sasaki · 2006 [cited by examiner]
US 20060143583A1 · Diab et al. · 2006 [cited by applicant]
US 20070157318A1 · Lee · 2007 [cited by examiner]
US 20080256598A1 · Diab · 2008 [cited by examiner]
US 20100017611A1 · Tsuboka · 2010 [cited by examiner]
US 20100199113A1 · Lee · 2010 [cited by applicant]
US 20110016342A1 · Rowan et al. · 2011 [cited by applicant]
US 20120131230A1 · Ady · 2012 [cited by examiner]
US 20120205990A1 · Minnoy · 2012 [cited by examiner]
US 20120310428A1 · Katagi · 2012 [cited by examiner]
US 20130262906A1 · Munjal et al. · 2013 [cited by applicant]
US 20130289789A1 · Ewing et al. · 2013 [cited by applicant]
US 20140325218A1 · Shimizu · 2014 [cited by examiner]
US 20150006395A1 · Chu · 2015 [cited by examiner]
US 20150154136A1 · Markovic · 2015 [cited by examiner]
US 20150271673A1 · Lord · 2015 [cited by examiner]
US 20170147807A1 · Rooyakkers · 2017 [cited by examiner]
US 20170169640A1 · Britt · 2017 [cited by examiner]
US 20180205414A1 · Tateishi · 2018 [cited by examiner]
US 20180359109A1 · O'Hora · 2018 [cited by applicant]
US 20190332774A1 · Nix · 2019 [cited by examiner]
US 20200014544A1 · Sela · 2020 [cited by examiner]
US 20200266675A1 · Lee · 2020 [cited by examiner]
US 20210263083A1 · Hwang · 2021 [cited by examiner]
US 20210384747A1 · Kim · 2021 [cited by examiner]
US 20220263819A1 · Kim · 2022 [cited by examiner]
CN 102647282A · 2012 [cited by applicant]
CN 102647283A · 2012 [cited by applicant]
WO WO2023192206A1 · 2023 [cited by examiner]
CISCO: “Cisco UPOE+: The Catalyst for Expanded IT-OT Convergence,” White Paper, Cisco Public, https://www.cisco.com/c/en/us/solutions/collateral/enterprise-networks/nb-06-upoe-plus-it-ot-wp-cte-en.html, Feb. 2022, 15 pa… [cited by applicant]
CISCO: “Overview of EAP-FAST,” EAP-FAST for Windows Vista Administrator Guide, Chapter 1, Jun. 2008, 4 pages. [cited by applicant]
CISCO: “What is a Smart Building?” retrieved from https://www.cisco.com/c/en/us/solutions/smart-building/what-is-a-smart-building.html, Aug. 9, 2023, 3 pages. [cited by applicant]
COOKIEPRO: “What is a Persistent Cookie?” CookiePro Knowledgebase, https://www.cookiepro.com/knowledge/what-is-a-persistent-cookie/, Aug. 5, 2022, 4 pages. [cited by applicant]
DES: “National Electrical Code (NEC) Releases New Class 4 Fault-Managed Power Category,” https://www.descomm.com/articles/National-Electrical-Code-(NEC)-Releases-Nlew-Class-4-Fault-Managed-Power-Category, Aug. 4, 2022, … [cited by applicant]
Friel O., et al., “Bootstrapped TLS Authentication with Proof of Knowledge (TLS-POK),” https://datatracker.ietf.org/doc/html/draft-ietf-emu-bootstrapped-tls, Network Working Group, Standards Track, Jun. 22, 2023, 11 Pag… [cited by applicant]
Gobok C., “Jumpstarting IEEE 802.3bt's PoE++,” https://www.arrow.com/en/research-and-events/articles/jumpstarting-IEEE, May 28, 2020, 4 pages. [cited by applicant]
NILE: “What Is MACsec?” retrieved from https://nilesecure.com/enterprise-network/security/what-is-macsec/, on Aug. 9, 2023, 12 pages. [cited by applicant]
PICA8: “PoE Over LLDP Power Negotiation,” https://docs.pica8.com/display/PICOS2111cg/PoE+over+LLDP+Power+Negotiation, Nov. 12, 2018, 4 pages. [cited by applicant]
Pritikin M., et al., “Bootstrapping Remote Secure Key Infrastructure (BRSKI),” Internet Engineering Task Force (IETF), RFC 8995, ISSN: 2070-1721, https://dl.acm.org/doi/book/10.17487/RFC8995, May 2021, 116 pages. [cited by applicant]
USB: “Universal Serial Bus Security Foundation Specification,” Revision 1.0 with ECN and Errata, https://www.usb.org/document-library/usb-authentication-specification-rev-10-ecn-and-errata-through-january-7-2019, Jan. 7… [cited by applicant]
USB: “Universal Serial Bus Type-C™ Authentication Specification,” Revision 1.0 with ECN and Errata, https://www.usb.org/document-library/usb-authentication-specification-rev-10-ecn-and-errata-through-january-7-2019, Jan… [cited by applicant]
Watsen K., et al., “A Voucher Artifact for Bootstrapping Protocols,” Internet Engineering Task Force (IETF), RFC 8366, ISSN: 2070-1721, https://datatracker.ietf.org/doc/html/rfc8366, May 9, 2018, 23 pages. [cited by applicant]
Wi-Fi Alliance: “Wi-Fi Easy Connect,” retrieved from https://www.wi-fi.org/discover-wi-fi/wi-fi-easy-connect, Aug. 9, 2023, 6 pages. [cited by applicant]
Wikipedia: “Diffie-Hellman Key Exchange,” retrieved from https://en.wikipedia.org/wiki/Diffie%E2%80% 93Hellman_key_exchange, Aug. 9, 2023, 12 pages. [cited by applicant]
Wikipedia: “Power Management Integrated Circuit,” retrieved from https://en.wikipedia.org/wiki/Power_management_integrated_circuit, Aug. 9, 2023, 2 pages. [cited by applicant]