IP Library Granted Patent US 12,464,355
Granted Patent B2
US 12,464,355 · App. 17/870,998 · Granted Nov 4, 2025

Secure device onboarding techniques

Inventors: Ned M. Smith (Beaverton, OR); Mats Gustav Agerstam (Portland, OR); Nathan Heldt-Sheller (Portland, OR); Abhilasha Bhargav-Spantzel (Santa Clara, CA)
Assignee: Intel Corporation
H04W12/08H04L63/1458H04W8/005H04W12/35H04W12/50
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,464,355
App. No.
17/870,998
Granted
Nov 4, 2025
Kind
B2
Abstract

Various systems and methods for establishing network connectivity and onboarding for Internet of Things (IoT) devices and trusted platforms, including in Open Connectivity Foundation (OCF) specification device deployments, are discussed. In an example, a zero touch owner transfer method includes operations of: receiving a first request from a new device for network access to begin an onboarding procedure with a network platform; transmitting credentials of a first network to the new device, the first network used to access a rendezvous server and obtain onboarding information associated with the network platform; receiving a second request from the new device for network access to continue the onboarding procedure; and transmitting credentials of a second network to the new device, as the new device uses the second network to access the onboarding server of the network platform and perform or complete the onboarding procedure with the network platform.

Claims (38)

1 . A device, comprising:

processing circuitry; and

a storage device including instructions embodied thereon, wherein the instructions, which when executed by the processing circuitry, cause the device to perform operations to:

invoke an onboarding procedure to enable the device to join a network platform;

transmit a unique identifier of the device from the device to a rendezvous service associated with the network platform;

receive onboarding information from the rendezvous service, based on the unique identifier, wherein the rendezvous service verifies the unique identifier before providing the onboarding information to the device;

transmit a first set of credentials to an onboarding service, wherein the onboarding service is identified by using the onboarding information, wherein the onboarding service enables the device to connect to the network platform based on the first set of credentials, and wherein the first set of credentials includes the unique identifier and a value based on a cryptographic key embedded in the device by a manufacturer of the device;

receive a second set of credentials based on accessing the onboarding service; and

perform secure communications with the network platform, based on use of the second set of credentials.

2 . The device of claim 1 , wherein the onboarding information includes an address of the onboarding service.

3 . The device of claim 1 , wherein messages exchanged between the device and the onboarding service are encrypted.

4 . The device of claim 1 , wherein the operations to transmit and receive occur via one or more wireless networks operating according to an IEEE 802.11 standards family.

5 . The device of claim 1 , wherein the onboarding procedure is autonomously invoked by the device based on a network access attempt.

6 . The device of claim 1 , further comprising a battery to provide a power source of the device.

7 . The device of claim 1 , wherein the device is an Internet of Things (IoT) device that includes one or more: accelerometers, level sensors, flow sensors, optical light sensors, camera sensors, temperature sensors, a global positioning system (GPS) sensors, or pressure sensors.

8 . A method performed by a device, comprising:

invoking an onboarding procedure to enable the device to join a network platform;

transmitting a unique identifier of the device from the device to a rendezvous service associated with the network platform;

receiving onboarding information from the rendezvous service, based on the unique identifier, wherein the rendezvous service verifies the unique identifier before providing the onboarding information to the device;

transmitting a first set of credentials to an onboarding service, wherein the onboarding service is identified by using the onboarding information, wherein the onboarding service enables the device to connect to the network platform based on the first set of credentials, and wherein the first set of credentials includes the unique identifier and a value based on a cryptographic key embedded in the device by a manufacturer of the device;

receiving a second set of credentials based on accessing the onboarding service; and

performing secure communications with the network platform, based on use of the second set of credentials.

9 . The method of claim 8 , wherein the onboarding information includes an address of the onboarding service.

10 . The method of claim 8 , wherein messages exchanged between the device and the onboarding service are encrypted.

11 . The method of claim 8 , wherein the transmitting and the receiving occurs via one or more wireless networks operating according to an IEEE 802.11 standards family.

12 . The method of claim 8 , wherein the onboarding procedure is autonomously invoked by the device.

13 . The method of claim 8 , wherein the device is an Internet of Things (IoT) device, and wherein the method further comprises performing sensing operations with one or more: accelerometers, level sensors, flow sensors, optical light sensors, camera sensors, temperature sensors, a global positioning system (GPS) sensors, or pressure sensors.

14 . A device, comprising:

means for invoking an onboarding procedure to enable the device to join a network platform;

communication means for:

transmitting a unique identifier of the device from the device to a rendezvous service associated with the network platform;

receiving onboarding information from the rendezvous service, based on the unique identifier, wherein the rendezvous service verifies the unique identifier before providing the onboarding information to the device;

transmitting a first set of credentials to an onboarding service, wherein the onboarding service is identified by using the onboarding information, wherein the onboarding service enables the device to connect to the network platform based on the first set of credentials, and wherein the first set of credentials includes the unique identifier and a value based on a cryptographic key embedded in the device by a manufacturer of the device; and

receiving a second set of credentials based on accessing the onboarding service; and

processing means for coordinating operations with the network platform, based on secure communications established by using the second set of credentials.

15 . The device of claim 14 , wherein the onboarding information includes an address of the onboarding service.

16 . The device of claim 14 , wherein messages exchanged between the device and the onboarding service are encrypted.

17 . The device of claim 14 , wherein the transmitting and the receiving occurs via one or more wireless networks operating according to an IEEE 802.11 standards family.

Continuity (4)
Continuation 16647403
Provisional Application 62625184 · Feb 1, 2018
Provisional Application 62582134 · Nov 6, 2017
Related Publication 20230009787A1 · Jan 12, 2023
References Cited (32)
US 9686238B1 · Row, II · 2017 [cited by applicant]
US 9749958B1 · Segev · 2017 [cited by examiner]
US 10469262B1 · Schroeder · 2019 [cited by examiner]
US 11102239B1 · Sareshwala · 2021 [cited by examiner]
US 11399285B2 · Smith et al. · 2022 [cited by applicant]
US 20130039275A1 · Patil et al. · 2013 [cited by applicant]
US 20140115676A1 · Coghlan et al. · 2014 [cited by applicant]
US 20160100022A1 · Kim · 2016 [cited by applicant]
US 20160105424A1 · Logue et al. · 2016 [cited by applicant]
US 20160174111A1 · Zhu et al. · 2016 [cited by applicant]
US 20170195930A1 · Tomici et al. · 2017 [cited by applicant]
US 20170364908A1 · Smith et al. · 2017 [cited by applicant]
US 20180145953A1 · Swahn · 2018 [cited by examiner]
US 20180227128A1 · Church · 2018 [cited by examiner]
US 20200008007A1 · Belghoul et al. · 2020 [cited by applicant]
US 20200275273A1 · Smith et al. · 2020 [cited by applicant]
CA 3225597A1 · 2023 [cited by examiner]
CN 108429726A · 2018 [cited by examiner]
DE 112018005260 · 2020 [cited by applicant]
EP 2934039 · 2015 [cited by applicant]
WO 2009092115 · 2009 [cited by applicant]
WO 2017171925 · 2017 [cited by applicant]
WO 2019089164 · 2019 [cited by applicant]
“How Interworking Works”, Commscope White Paper, (2020), 14 pgs. [cited by applicant]
“OCF Security Specification V1.0.0”, Open Connectivity Foundation (OCF), [Online] Retrieved from the internet:https: openconnectivity.org draftspecs OCF_Securi ty_Speci fi cati on_vl.0.0.pdf, (Mar. 22, 2017), 104 pgs. [cited by applicant]
“International Application Serial No. PCT US2018 053486, International Search Report mailed Nov. 30, 2018”, 5 pgs. [cited by applicant]
“International Application Serial No. PCT US2018 053486, Written Opinion mailed Nov. 30, 2018”, 6 pgs. [cited by applicant]
“U.S. Appl. No. 16/647,403, Preliminary Amendment filed Mar. 13, 2020”, 9 pgs. [cited by applicant]
“International Application Serial No. PCT US2018 053486, International Preliminary Report on Patentability mailed May 22, 2020”, 8 pgs. [cited by applicant]
“U.S. Appl. No. 16/647,403, Non Final Office Action mailed Sep. 14, 2021”, 11 pgs. [cited by applicant]
“U.S. Appl. No. 16/647,403, Response filed Jan. 14, 2022 to Non Final Office Action mailed Sep. 14, 2021”, 13 pgs. [cited by applicant]
“U.S. Appl. No. 16/647,403, Notice of Allowance mailed Mar. 23, 2022”, 9 pgs. [cited by applicant]