IP Library Granted Patent US 12,645,784
Granted Patent B2
US 12,645,784 · App. 19/259,531 · Granted Jun 2, 2026

Offline digital asset generation and provisioning

Inventors: Brian Romansky (Monroe, CT); Alan T. Meyer (Anaheim, CA)
Assignee: INTEGRITY SECURITY SERVICES LLC
G06F21/45G06F21/57
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,645,784
App. No.
19/259,531
Granted
Jun 2, 2026
Kind
B2
Abstract

A system for offline generation of digital assets includes: a security credential management system (SCMS) that is operable to generate and conditionally transmit digital assets; and a certificate authority communicatively connected to the SCMS by a communication network, the certificate authority being operable to receive the digital assets from the SCMS. The certificate authority is operable to securely provision a plurality of computerized devices based on the received digital assets, the certificate authority intermittently connects to the SCMS to receive the digital assets, the certificate authority is operable to securely provision the plurality of computerized devices while disconnected from the SCMS, and the provisioning by the certificate authority while disconnected from the SCMS is limited by a policy associated with the certificate authority.

Claims (47)

1 . A system for offline generation of digital assets, the system comprising:

a security credential management system (SCMS) comprising an electronic processor, wherein the SCMS is operable to generate and conditionally transmit digital assets comprising a certificate authority signing key; and

a certificate authority comprising an electronic processor and communicatively connected to the SCMS by a communication network, the certificate authority being operable to receive the digital assets from the SCMS;

wherein the certificate authority is operable to securely provision a plurality of computerized devices based on the received digital assets by producing signed enrollment certificates using the certificate authority signing key,

wherein the certificate authority intermittently connects to the SCMS to receive the digital assets,

wherein the certificate authority is operable to securely provision the plurality of computerized devices while disconnected from the SCMS, and

wherein the provisioning by the certificate authority while disconnected from the SCMS is limited by a policy associated with the certificate authority.

2 . The system of claim 1 , wherein the certificate authority is a distribution appliance located remotely from the SCMS.

3 . The system of claim 1 , wherein the SCMS comprises a provisioning controller.

4 . The system of claim 1 , wherein the certificate authority is located at the site of a device manufacturer, and

wherein the SCMS is remote from the device manufacturer.

5 . The system of claim 1 , wherein the policy limits the provisioning by the certificate authority while disconnected from the SCMS according to a time of disconnection from the SCMS.

6 . The system of claim 1 , wherein the policy limits the provisioning by the certificate authority while disconnected from the SCMS according to a number of the computerized devices provisioned.

7 . The system of claim 1 , wherein the certificate authority logs information regarding the computerized devices provisioned while disconnected from the SCMS.

8 . The system of claim 7 , wherein the certificate authority transmits the logged information to the SCMS after reconnecting to the SCMS after being disconnected from the SCMS.

9 . The system of claim 8 , wherein the SCMS is operable to determine from the logged information whether the certificate authority performed an unauthorized provisioning while disconnected from the SCMS.

10 . The system of claim 1 , wherein the SCMS is operable to connect to a plurality of certificate authorities.

11 . A method for securely providing certificates, the method comprising:

generating, by a security credential management system (SCMS), digital assets comprising a certificate authority signing key;

conditionally transmitting, by the SCMS, the digital assets;

receiving, by a certificate authority communicatively connected to the SCMS by a communication network, the digital assets from the SCMS; and

securely provisioning, by the certificate authority, a plurality of computerized devices based on the received digital assets, wherein the securely provisioning comprises producing signed enrollment certificates using the certificate authority signing key;

wherein the certificate authority intermittently connects to the SCMS to receive the digital assets,

wherein the certificate authority is operable to securely provision the plurality of computerized devices while disconnected from the SCMS, and

wherein the provisioning by the certificate authority while disconnected from the SCMS is limited by a policy associated with the certificate authority.

12 . The method of claim 11 , wherein the certificate authority is located at the site of a device manufacturer; and

wherein the SCMS is remote from the device manufacturer.

13 . The method of claim 11 , wherein the policy limits the provisioning by the certificate authority while disconnected from the SCMS according to a time of disconnection from the SCMS.

14 . The method of claim 11 , wherein the policy limits the provisioning by the certificate authority while disconnected from the SCMS according to a number of the computerized devices provisioned.

15 . The method of claim 11 , wherein the certificate authority logs information regarding the computerized devices provisioned while disconnected from the SCMS, and

wherein the certificate authority transmits the logged information to the SCMS after reconnecting to the SCMS after being disconnected from the SCMS.

16 . The method of claim 15 , wherein the SCMS is operable to determine from the logged information whether the certificate authority performed an unauthorized provisioning while disconnected from the SCMS.

17 . The method of claim 11 , wherein the SCMS is operable to connect to a plurality of certificate authorities.

18 . A non-transitory computer-readable medium for securely providing certificates, the non-transitory computer-readable medium comprising a plurality of instructions that, in response to execution by a processor, cause the processor to perform operations comprising:

generating, by a security credential management system (SCMS), digital assets comprising a certificate authority signing key;

conditionally transmitting, by the SCMS, the digital assets;

receiving, by a certificate authority communicatively connected to the SCMS by a communication network, the digital assets from the SCMS; and

securely provisioning, by the certificate authority, a plurality of computerized devices based on the received digital assets, wherein the securely provisioning comprises producing signed enrollment certificates using the certificate authority signing key;

wherein the certificate authority intermittently connects to the SCMS to receive the digital assets,

wherein the certificate authority is operable to securely provision the plurality of computerized devices while disconnected from the SCMS, and

wherein the provisioning by the certificate authority while disconnected from the SCMS is limited by a policy associated with the certificate authority.

19 . The non-transitory computer-readable medium of claim 18 , wherein the certificate authority is located at the site of a device manufacturer; and

wherein the SCMS is remote from the device manufacturer.

20 . The non-transitory computer-readable medium of claim 18 , wherein the policy limits the provisioning by the certificate authority while disconnected from the SCMS according to a time of disconnection from the SCMS and/or a number of the computerized devices provisioned.

21 . The non-transitory computer-readable medium of claim 18 , wherein the certificate authority logs information regarding the computerized devices provisioned while disconnected from the SCMS, and

wherein the certificate authority transmits the logged information to the SCMS after reconnecting to the SCMS after being disconnected from the SCMS.

22 . The non-transitory computer-readable medium of claim 21 , wherein the SCMS is operable to determine from the logged information whether the certificate authority performed an unauthorized provisioning while disconnected from the SCMS.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 3, 2025
From: ROMANSKY, BRIAN; MEYER, ALAN T.
To: INTEGRITY SECURITY SERVICES LLC
Reel/Frame 071604/0770 →
Continuity (2)
Provisional Application 63668045 · Jul 5, 2024
Related Publication 20260010614A1 · Jan 8, 2026
References Cited (13)
US 10599819B2 · Lattin · 2020 [cited by examiner]
US 11695574B2 · Barrett et al. · 2023 [cited by applicant]
US 20020065780A1 · Barritz · 2002 [cited by examiner]
US 20040185842A1 · Spaur · 2004 [cited by examiner]
US 20120143766A1 · Zheng · 2012 [cited by examiner]
US 20140380499A1 · Pruss · 2014 [cited by examiner]
US 20160173286A1 · Gallagher · 2016 [cited by examiner]
US 20210288821A1 · Young · 2021 [cited by examiner]
US 20210306161A1 · Medvinsky · 2021 [cited by examiner]
US 20220158854A1 · Simplicio et al. · 2022 [cited by applicant]
US 20240214807A1 · Rivera · 2024 [cited by examiner]
WO 2020014024A1 · 2020 [cited by applicant]
International Search Report and Written Opinion dated Sep. 10, 2025, PCT Application No. PCT/US2025/036439, 9 pages. [cited by applicant]