IP Library › Granted Patent US 12,483,410
Granted Patent B2
US 12,483,410 · App. 18/592,226 · Granted Nov 25, 2025

Token node locking with fingerprints authenticated by digital certificates

Inventors: Jason A. Pasion (San Diego, CA); John Okimoto (San Diego, CA); Xin Qiu (San Diego, CA); Alexander Medvinsky (San Diego, CA); Ting Yao (San Diego, CA); Jinsong Zheng (San Diego, CA); Oscar Jiang (West Covina, CA)
Assignee: ARRIS Enterprises LLC
H04L9/3213H04L9/3247H04L9/3263H04L9/3268H04L9/3297H04L63/166H04L2463/121
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,483,410
App. No.
18/592,226
Filed
Feb 29, 2024
Granted
Nov 25, 2025
Kind
B2
Art Unit
2439
USPC
713/156
Abstract

A system and method for receiving secure data in a client device. In one embodiment, the method comprises (a) receiving a token having a token ID and a digital certificate generated by a certificate authority (CA) having client device fingerprint data generated from client device parameters, (b) accepting a request in the client device to provide secure data to the client device, (c) regenerating the client device fingerprint data from the client device parameters, (d) determining, in the client device, differences between the client device fingerprint data of the digital certificate from the regenerated client device fingerprint data, and (e) transmitting a request to a secure data service to provide secure data based upon the determination.

Claims (57)

1 . A method of receiving secure data in a client device, comprising:

(a) receiving in the client device a token having both a token ID and a digital certificate generated by a certificate authority (CA), the certificate having client device fingerprint data generated from client device parameters;

(b) accepting a request in the client device to provide secure data to the client device;

(c) regenerating in the client device the client device fingerprint data from the client device parameters;

(d) determining, in the client device, differences between the client device fingerprint data of the digital certificate and the regenerated client device fingerprint data;

(e) selectively transmitting a request to a secure data service to provide secure data based upon the determination, comprising:

if the client device fingerprint data of the digital certificate matches the regenerated client device fingerprint data, transmitting the request to a secure data service to provide secure data to the client device;

if the client device fingerprint data of the digital certificate does not match the regenerated client device fingerprint data, determining if differences between the client device fingerprint data of the digital certificate and the regenerated client device fingerprint data are acceptable;

if differences between the client device fingerprint data of the digital certificate and the regenerated client device fingerprint data are acceptable:

transmitting the request to a secure data service to provide secure data to the client device; and

receiving the secure data;

(f) transmitting a request from an administrator of the client device to unbind the token from the client device and rebind the token to a second client device having second client device fingerprint data; and

(g) receiving a further digital certificate generated by the CA having the second client device fingerprint data.

2 . The method of claim 1 , wherein if the differences between the client device fingerprint data of the digital certificate and the regenerated client device fingerprint data are acceptable, the method further comprises:

transmitting the client device regenerated fingerprint data and token ID to the CA;

receiving a further digital certificate generated by the CA having the client device regenerated fingerprint data; and

storing the further digital certificate in the token.

3 . The method of claim 2 , wherein if the differences between the client device fingerprint data of the digital certificate and the regenerated client device fingerprint data are not acceptable, the method further comprises:

returning an error to the client device; and

logging the error to the secure data service.

4 . The method of claim 3 , further comprising:

compiling the logged error in a token report; and

providing the token report to an administrator of the client device.

5 . The method of claim 2 , wherein (b)-(e) are performed by a secure software development kit (SDK) executing on the client device.

6 . The method of claim 1 , wherein receiving a token having a digital certificate generated by the CA having the client device fingerprint data comprises:

generating first client device fingerprint data from client device parameters;

transmitting the first client device fingerprint data to a certificate authority (CA), the CA generating the digital certificate; and

receiving the token.

7 . The method of claim 1 , wherein the token comprises a hardware token communicatively coupleable to the client device.

8 . The method of claim 1 , wherein:

the token further comprises a secure private key;

the request is signed by a private key of the digital certificate; and

the secure data is received from the secure data service only after verification of the signature of the request.

9 . A client device for receiving secure data, comprising:

a processor;

a memory, communicatively coupled to the processor, the memory storing processor instructions comprising processor instructions for:

(a) accepting a request in the client device to provide secure data to the client device, the client device having a communicatively coupled token having both a token ID and a digital certificate generated by a certificate authority (CA), the certificate having client device fingerprint data generated from client device parameters;

(b) regenerating the client device fingerprint data from the client device parameters;

(c) determining, in the client device, differences between the client device fingerprint data of the digital certificate from the regenerated client device fingerprint data;

(d) selectively transmitting a request to a secure data service to provide secure data based upon the determination, comprising:

if the client device fingerprint data of the digital certificate matches the regenerated client device fingerprint data, transmitting the request to a secure data service to provide secure data to the client device;

if the client device fingerprint data of the digital certificate does not match the regenerated client device fingerprint data, determining if differences between the client device fingerprint data of the digital certificate and the regenerated client device fingerprint data are acceptable;

if differences between the client device fingerprint data of the digital certificate and the regenerated client device fingerprint data are acceptable:

transmitting the request to a secure data service to provide secure data to the client device; and

receiving the secure data;

(e) transmitting a request from an administrator of the client device to unbind the token from the client device and rebind the token to a second client device having second client device fingerprint data; and

(f) receiving a further digital certificate generated by the CA having the second client device fingerprint data.

10 . The client device of claim 9 , wherein the processor instructions further comprise instructions for transmitting the client device regenerated fingerprint data and token ID to the CA, receiving a further digital certificate generated by the CA having the client device regenerated fingerprint data, and storing the further digital certificate in the token if the differences between the client device fingerprint data of the digital certificate and the regenerated client device fingerprint data are acceptable.

11 . The client device of claim 10 , wherein the processor instructions further comprise processor instructions for returning an error to the client device and logging the error to the secure data service if the differences between the client device fingerprint data of the digital certificate and the regenerated client device fingerprint data are not acceptable.

12 . The client device of claim 11 , wherein the processor instructions further comprise processor instructions for:

compiling the logged error in a token report; and

providing the token report to an administrator of the client device.

13 . The client device of claim 10 , wherein (a)-(d) are performed by a secure software development kit (SDK) executing on the client device.

14 . The client device of claim 9 , wherein:

the token further comprises a secure private key;

the request is signed by a private key of the digital certificate; and

the secure data is received from the secure data service only after verification of the signature of the request.

Assignments (2)
SECURITY INTEREST Recorded Apr 8, 2026
From: ARRIS ENTERPRISES LLC; RUCKUS IP HOLDINGS LLC
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 075476/0814 →
SECURITY INTEREST Recorded Dec 17, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE INC., OF NORTH CAROLINA; OUTDOOR WIRELESS NETWORKS LLC; RUCKUS IP HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC
Reel/Frame 069889/0114 →
Continuity (3)
Continuation 17204660 · Mar 17, 2021
Provisional Application 62990448 · Mar 17, 2020
Related Publication 20240205008A1 · Jun 20, 2024
References Cited (27)
US 8613067B2 · Lambiase et al. · 2013 [cited by applicant]
US 9332433B1 · Dotan et al. · 2016 [cited by applicant]
US 9425958B2 · Vennelakanti et al. · 2016 [cited by applicant]
US 11122035B2 · Smolny · 2021 [cited by applicant]
US 11245484B2 · Bhandari et al. · 2022 [cited by applicant]
US 20120117351A1 · Motwani · 2012 [cited by examiner]
US 20120311686A1 · Medina et al. · 2012 [cited by applicant]
US 20150019443A1 · Sheets · 2015 [cited by examiner]
US 20150150110A1 · Canning et al. · 2015 [cited by applicant]
US 20150237049A1 · Grajek · 2015 [cited by examiner]
US 20160156598A1 · Alonso Cebrian · 2016 [cited by examiner]
US 20160241532A1 · Loughlin-Mchugh et al. · 2016 [cited by applicant]
US 20160267284A1 · Willis · 2016 [cited by examiner]
US 20170289139A1 · Guo · 2017 [cited by examiner]
US 20190200218A1 · Redberg · 2019 [cited by applicant]
US 20190334884A1 · Ross et al. · 2019 [cited by applicant]
US 20200322075A1 · Bhandari et al. · 2020 [cited by applicant]
US 20210297254A1 · Pasion et al. · 2021 [cited by applicant]
US 20210297269A1 · Pasion et al. · 2021 [cited by applicant]
US 20210297449A1 · Pasion · 2021 [cited by applicant]
US 20210349986A1 · Jiang et al. · 2021 [cited by applicant]
GB 2434724A · 2007 [cited by applicant]
Hesse, J., Singh, N. and Sorniotti, A., 2023. How to bind anonymous credentials to humans. In 32nd USENIX Security Symposium (USENIX Security 23) (pp. 3047-3064). (Year: 2023). [cited by examiner]
Xiao, Y., He, Y., Zhang, X., Wang, Q., Xie, R., Sun, K., Xu, K. and Li, Q., 2024. From hardware fingerprint to access token: Enhancing the authentication on IoT devices. arXiv preprint arXiv:2403.15271. (Year: 2024). [cited by examiner]
International Search Report and Written Opinion Re: Application No. PCT/US2021/022810 (dated Jun. 8, 2021). [cited by applicant]
Naor, M. and Nissim, K., 2000. Certificate revocation and certificate update. IEEE Journal on selected areas in communications, 18 (4), pp. 561-570. (Year: 2000). [cited by applicant]
Brecht, B. Therriault, D., Weimerskirch, A., Whyte, W., Kumar, V., Hehn, T. and Goudy, R., 2018. A security credential management system for V2X communications. IEEE Transactions on Intelligent Transportation Systems, 1… [cited by applicant]