IP Library Granted Patent US 12,580,775
Granted Patent B2
US 12,580,775 · App. 18/210,694 · Granted Mar 17, 2026

Connection authorization from a communication device to an application

Inventors: Ramses Alexander Escobar Ariza (Villeneuve-Loubet, FR); Matthieu Adam (Juan-les-Pins, FR)
Assignee: Schneider Electric Industries SAS
H04L9/3263H04L9/0877H04L9/3247
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,580,775
App. No.
18/210,694
Granted
Mar 17, 2026
Kind
B2
Abstract

Connection authorization from a communication device (CD) to an application server (AS) uses an electronic device (ED) to provide a first dataset to a security server (SS) in response to a first request, the first dataset related to a certificate of the ED. The ED retrieves an intermediary certificate generated by the SS based on the first dataset and signed by the SS. When the ED is connected to a CD intended to be introduced in a secured network, the ED receives a second request from the CD including a second dataset related to a certificate of the CD. The ED then generates a third dataset related to a signature of certificate of the CD and to the intermediary certificate. The ED thereafter sends the third dataset to the CD to obtain authorization to access to the secure network from the AS by using the third dataset.

Claims (28)

1 . A method for connection authorization from a communication device to an application server, comprising in an electronic device:

providing a first dataset to a security server in response to a first request, wherein the first dataset is related to a certificate of the electronic device,

retrieving an intermediary certificate from the security server, wherein the intermediary certificate is generated by the security server based on the first dataset and signed by the security server,

when connecting the electronic device to a communication device intended to be introduced in a secured network for the first time, receiving by the electronic device a second request from the communication device, the second request comprising a second dataset related to a certificate of the communication device,

generating a third dataset related to a signature of certificate of the communication device by the electronic device and to the intermediary certificate, and

sending the third dataset to the communication device, wherein the communication device is able to obtain authorization to access to the secure network from the application server by sending the third dataset to the application server;

wherein the electronic device is independent from the communication device and may be used with a plurality of communication devices.

2 . The method according to claim 1 , wherein the first dataset contains the certificate of the electronic device.

3 . The method according to claim 1 , wherein the second dataset contains the certificate of the communication device.

4 . The method according to claim 1 , wherein the first request inquires information about the certificate of the electronic device.

5 . The method according to claim 1 , wherein the electronic device communicates with the security server through an access device that is separate from the electronic device.

6 . The method according to claim 1 , wherein the third dataset contains the certificate of the communication device signed by the electronic device.

7 . The method according to claim 1 , wherein the signature of certificate of the communication device corresponds to a signature of a hash of the certificate of the communication device by the electronic device.

8 . The method according to claim 1 , wherein the secure network relies on a public key infrastructure.

9 . The method according to claim 1 , wherein the third dataset allows the application server to verify the intermediate certificate using a root certificate and to further verify the signature of the certificate of the communication device using the intermediate certificate.

10 . The method according to claim 1 , wherein the electronic device interacts with a hardware security module to compute and store a secret related to a certificate.

11 . The method according to claim 1 , wherein the application server is another communication device.

12 . An electronic device for connection authorization from a communication device to an application server, comprising:

one or more interfaces to communicate with at least a communication device;

a processor coupled to the interfaces and configured to execute one or more processes; and

a memory configured to store a process executable by the processor, the process when executed operable to:

provide a first dataset to a security server in response to a first request, wherein the first dataset is related to a certificate of the electronic device,

retrieve an intermediary certificate from the security server, wherein the intermediary certificate is generated by the security server based on the first dataset and signed by the security server,

when connecting the electronic device to the communication device intended to be introduced in a secured network for the first time, receive a second request from the communication device, the second request comprising a second dataset related to a certificate of the communication device,

generate a third dataset related to a signature of certificate of the communication device by the electronic device and to the intermediary certificate, and

send the third dataset to the communication device, wherein the communication device is able to obtain authorization to access the secure network from the application server by using the third dataset to the application server;

wherein the electronic device is independent from the communication device and may be used with a plurality of communication devices.

13 . A non-transitory computer-readable medium having embodied thereon a computer program for executing the method according to claim 1 .

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2023
From: ESCOBAR ARIZA, RAMSES ALEXANDER; ADAM, MATTHIEU
To: SCHNEIDER ELECTRIC INDUSTRIES SAS
Reel/Frame 063970/0034 →
Priority Claims (1)
EP 22305910 · Jun 23, 2022 · regional
Continuity (1)
Related Publication 20230421390A1 · Dec 28, 2023
References Cited (7)
US 11552803B1 · Simkhada · 2023 [cited by examiner]
US 11601288B1 · Bacon · 2023 [cited by examiner]
WO 2014127373A1 · 2014 [cited by applicant]
WO 2020154159A1 · 2020 [cited by applicant]
WO WO2022116734A1 · 2022 [cited by examiner]
Maksuti, Silia et al., “Automated and Secure Onboarding for System of Systems”, IEEE Access, vol. 9, Aug. 3, 2021, pp. 111095-111113. [cited by applicant]
European Search Report and Search Opinion dated Dec. 8, 2022 for corresponding European Patent Application No. EP22305910.6, 9 pages. [cited by applicant]