IP Library › Granted Patent US 12,536,253
Granted Patent B2
US 12,536,253 · App. 18/625,376 · Granted Jan 27, 2026

Secure onboarding of a component in a network

Inventors: Florian Kohnhaeuser (Riedstadt, DE); Roland Braun (Niederkassel Lülsdorf, DE); Rhaban Hark (Griesheim, DE); Pablo Rodriguez (Birkenau, DE)
Assignee: ABB Schweiz AG
G06F21/1084G06F21/44G06F21/645
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,536,253
App. No.
18/625,376
Granted
Jan 27, 2026
Kind
B2
Abstract

A method for providing a secure onboarding of a component from at least one first host device into a second host device includes verifying the integrity, authenticity and/or execution environment of the first host device by an orchestrator; providing a trusted root certificate to the second host device by the orchestrator; providing an onboarding identity by the orchestrator to the first host device, when the integrity, the authenticity and/or the execution environment of the first host device has been verified; receiving the onboarding identity from the orchestrator by the first host device and assigning the onboarding identity to the component; providing the assigned onboarding identity to the second host device; and securely onboarding the component from the first host device into the second host device based on the assigned onboarding identity and the provided trusted root certificate.

Claims (25)

1 . A method for providing a secure onboarding of a component from at least one first host device into a second host device, comprising:

verifying an integrity, authenticity and/or execution environment of the at least one first host device including the component by at least one orchestrator;

providing a trusted root certificate to the second host device by the at least one orchestrator;

providing an onboarding identity by the at least one orchestrator to the at least one first host device, when the integrity, the authenticity and/or the execution environment of the at least one first host device has been verified;

receiving the onboarding identity from the orchestrator by the at least one first host device and assigning the onboarding identity to the component by the at least one orchestrator;

passing the assigned onboarding identity to the second host device by the at least one first host device; and

securely onboarding the component from the at least one first host device into the second host device by the orchestrator device based on the assigned onboarding identity and the provided trusted root certificate.

2 . The method according to claim 1 , wherein the verifying of the integrity of the at least one first host device is provided by a remote attestation technique.

3 . The method according to claim 1 , wherein the verifying of the authenticity of the at least one first host device is provided by a security certificate.

4 . The method according to claim 1 , wherein the verifying of the execution environment of the at least one first host device is provided by a remote attestation technique.

5 . The method according to claim 1 , wherein the assigned onboarding identity comprises an unique key and a digital certificate being associated with the orchestrator.

6 . The method according to claim 5 , wherein the unique key is generated from the at least one first host device, solely when the onboarding identity from the orchestrator is received.

7 . The method according to claim 5 , wherein the digital certificate associated to the orchestrator is a DevID, IDevID or a LDevID certificate fulfilling a IEEE 802.1AR standard.

8 . The method according to claim 1 , wherein the trusted root certificate is a certificate provided by an orchestrator's certificate authority.

9 . The method according to claim 1 , wherein the trusted root certificate is a certificate provided by a root certificate authority.

10 . The method according to claim 1 , wherein the onboarding is provided by Feature Data Object, FDO, protocol, by Bootstrapping Remote Secure Key infrastructure, BRSKI, protocol, by Open Platform Communications, OPC 10000-21, protocol or by Secure Zero Touch Provisioning, SZTP, protocol.

11 . The method according to claim 1 , further comprising:

identifying a shortage of resources in a first host device by the at least one orchestrator;

identifying a second host device by the at least one orchestrator;

providing a trusted root certificate to the second host device by the at least one orchestrator;

executing a migration protocol between the orchestrator, the first host device and the second host device;

wherein the migration protocol comprises:

deleting the unique key and the trusted certificate associated with the orchestrator on the first host device, and

generating a new assigned onboarding identity on the second host device; and

securely onboarding the component from the first host device into the second host device based on the assigned onboarding identity and the provided trusted root certificate.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 16, 2024
From: KOHNHAEUSER, FLORIAN; BRAUN, ROLAND; HARK, RHABAN; RODRIGUEZ, PABLO
To: ABB SCHWEIZ AG
Reel/Frame 067116/0950 →
Priority Claims (1)
EP 23166386 · Apr 3, 2023 · regional
Continuity (1)
Related Publication 20250258894A1 · Aug 14, 2025
References Cited (12)
US 10977372B2 · Sood et al. · 2021 [cited by applicant]
US 20160182499A1 · Sharaga et al. · 2016 [cited by applicant]
US 20190332421A1 · Kozlowski · 2019 [cited by examiner]
US 20190349357A1 · Shukla et al. · 2019 [cited by applicant]
US 20200193065A1 · Smith · 2020 [cited by applicant]
US 20200327231A1 · Smith · 2020 [cited by examiner]
US 20220222348A1 · Vaswani et al. · 2022 [cited by applicant]
US 20230063428A1 · Nadiminti · 2023 [cited by examiner]
US 20230353554A1 · Behera · 2023 [cited by examiner]
Paladi et al., “Trust Anchors in Software Defined Networks,” [cited by applicant]
Sudarsan et al., “Device Onboarding in Eclipse Arrowhead using Power of Attorney based Authorization,” [cited by applicant]
European Patent Office, Extended European Search Report in European Patent Application No. 23166386.5, 8 pp. (Sept. 8, 2023). [cited by applicant]