IP Library Granted Patent US 10,341,360
Granted Patent B2
US 10,341,360 · App. 15/450,424 · Granted Jul 2, 2019

Method and apparatus for user and entity access management for code signing one or more of a plurality of devices

Inventors: Ting Yao (San Diego, CA); Xin Qiu (San Diego, CA); Jinsong Zheng (San Diego, CA); Patrick Dizon (San Diego, CA); Aye Myint (San Diego, CA); Annie C. Kuramoto (San Diego, CA); Reshma Shahabuddin (Poway, CA); Thomas J. Barbour (San Diego, CA)
Assignee: ARRIS Enterprises LLC
H04L63/126G06F8/61G06F21/602H04L9/3247H04L63/10G06F21/645H04L63/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,341,360
App. No.
15/450,424
Granted
Jul 2, 2019
Kind
B2
Abstract

A method and apparatus is provided for managing the eligibility of data signing in an online code signing system. The method is used by a plurality of data publishers in an online code signing system. The method includes defining, by an administrator of the system, a hierarchy of a plurality of entities, and managing, by an administrator of the system, eligibility to designate at least one of a plurality of users to access the at least one configuration entity to sign the data via a plurality of accounts and eligibility to designate at least one of a plurality of managers via owner account to manage user access to sign data for at least one model entity.

Claims (123)

1. A method of managing the signing of data for use with one or more of an plurality of devices of an application platform, each device a member of a device family of the application platform, the data to be installed on the one or more of the plurality of devices according to a management model of the device family, the method comprising:

defining, by an administrator of the system, a hierarchy of a plurality of entities, the plurality entities comprising, in decreasing hierarchical order:

an application platform entity that produces the plurality of devices, having a sole owner;

at least one project entity for each application platform entity, the project entity comprising the device family;

at least one model entity for each project entity, the model entity defining the installation of the data on devices associated with the model entity; and

at least one configuration entity for each model entity, the configuration entity defining the data to be installed on devices associated with the configuration entity;

managing, by an administrator of the system, eligibility to designate at least one of a plurality of users to access the at least one configuration entity to sign the data via a plurality of accounts, the plurality of accounts comprising:

an owner account of the application platform entity, the owner account issued only to the sole owner of the application platform entity, the owner account providing:

sole eligibility to authorize access the application platform entity;

eligibility to permit authorization of access to any of the plurality of entities hierarchically below the application platform entity; and

eligibility to authorize users associated with the owner account to access at least one configuration entity hierarchically below the application platform entity to sign the data to be installed on the devices associated with the at least one configuration entity;

at least one participant account of the application platform entity or the at least one project entity, providing:

eligibility to authorize users associated with the participant account and no other participant account to access at least one configuration entity hierarchically below the application platform entity or the at least one project entity, respectively, to sign the data to be installed on the devices associated with the at least one configuration entity,

wherein managing eligibility to designate at least one of the plurality of users to access the at least one configuration entity to sign the data via the plurality of accounts comprises:

creating the owner account associated with the application platform entity for the sole owner of the application platform entity, and

wherein creating the owner account associated with the application platform entity for the sole owner of the application platform entity comprises:

assigning the at least one manager of the at least one model entity hierarchically below the application platform entity;

assigning another manager of another model entity hierarchically below the platform entity;

the method further comprises:

creating the at least one participant account, wherein the at least one participant account is associated with the at least one project entity;

creating another participant account, wherein the another participant account is associated with another project entity;

authorizing, by the assigned at least one manager, users associated with the at least one participant account and no other participant account to sign the data to be installed on the devices associated with the configuration entities hierarchically below the at least one model entity;

authorizing, by the assigned another manager, users associated with the another participant account and no other participant account to sign the data to be installed on the devices associated with the configuration entities hierarchically below the another model entity;

wherein:

the sole owner of the owner account is a first business organization;

the at least one participant account is associated with a second business organization independent from the first business organization;

the another participant account is associated with a third business organization independent from the first business organization and the second business organization.

2. The method of claim 1 , wherein:

the owner account further provides sole eligibility to designate at least one manager of the at least one model entity hierarchically below the application platform entity to authorize access to all configuration entities hierarchically below the at least one model entity to sign the data to be installed on the devices associated with the configuration entities hierarchically below the at least one model entity; and

wherein the at least one manager can authorize access to all of the configuration entities hierarchically below the at least one model entity to only users of the plurality of users that are associated with the owner account of the application platform entity hierarchically above the model entity or the participant account of the application platform entity hierarchically above the model entity.

3. The method of claim 1 , wherein:

creating the owner account associated with the application platform entity for the sole owner of the application platform entity comprises:

assigning, by an assigned administrator of the system, the at least one manager of the at least one model entity of hierarchically below the application platform entity; and

authorizing, by the assigned at least one manager, users associated with the owner account to sign the data to be installed on the devices associated with the configuration entities hierarchically below the model entity.

4. The method of claim 3 , wherein managing eligibility to designate at least one of a plurality of users to access the at least one configuration entity to sign the data via a plurality of accounts, further comprises:

creating, by the system administrator, the at least one participant account wherein the participant account is associated with at least one of:

the application platform entity; and

the at least one project entity;

authorizing, by the assigned manager, users associated with the participant account to sign the data to be installed on the devices associated with the configuration entities hierarchically below the model entity;

wherein:

the sole owner of the owner account is a first business organization;

the at least one participant account is associated with a second business organization independent from the first organization.

5. The method of claim 1 , wherein:

the system comprises a back end server communicatively coupled to a front end server for controlling access to the back end server;

the defining the hierarchy of the plurality of entities is performed using the back end server accessed by the front end server; and

managing eligibility to designate at least one of a plurality of users to access the at least one configuration entity to sign the data via a plurality of accounts is performed using the backend server accessed by the front end server.

6. The method of claim 1 , further comprising:

enforcing, using the backend server, the:

sole eligibility to authorize access the application platform entity; and

eligibility to permit authorization of access to any of the plurality of entities hierarchically below the application platform entity;

eligibility to authorize users associated with the owner account to access at least one configuration entity hierarchically below the application platform entity to sign the data to be installed on the devices associated with the at least one configuration entity;

eligibility to authorize users associated with the participant account to access at least one configuration entity hierarchically below the application platform entity or the at least one project entity, respectively, to sign the data to be installed on the devices associated with the at least one configuration entity;

performing, using the backend server, cryptographic operations to sign the data; and

executing, using the front end server, a presentation layer, the presentation layer controlling user access to the backend server.

7. A system managing the signing of data for use with one or more of an plurality of devices of an application platform, each device a member of a device family of the application platform, the data to be installed on the one or more of the plurality of devices according to a management model of the device family, comprising:

a processor; and

a memory, communicatively coupled to the processor, the memory storing instructions comprising instructions for:

defining, by an administrator of the system, a hierarchy of a plurality of entities, the plurality entities comprising, in decreasing hierarchical order:

an application platform entity that produces the plurality of devices, having a sole owner;

at least one project entity for each application platform entity, the project entity comprising the device family;

at least one model entity for each project entity, the model entity defining the installation of the data on devices associated with the model entity; and

at least one configuration entity for each model entity, the configuration entity defining the data to be installed on devices associated with the configuration entity;

managing, by an administrator of the system, eligibility to designate at least one of a plurality of users to access the at least one configuration entity to sign the data via a plurality of accounts, the plurality of accounts comprising:

an owner account of the application platform entity, the owner account issued only to the sole owner of the application platform entity, the owner account providing:

sole eligibility to authorize access the application platform entity; and

eligibility to permit authorization of access to any of the plurality of entities hierarchically below the application platform entity;

eligibility to authorize users associated with the owner account to access at least one configuration entity hierarchically below the application platform entity to sign the data to be installed on the devices associated with the at least one configuration entity;

at least one participant account of the application platform entity or the at least one project entity, providing:

eligibility to authorize users associated with the participant account and no other participant account to access at least one configuration entity hierarchically below the application platform entity or the at least one project entity, respectively, to sign the data to be installed on the devices associated with the at least one configuration entity,

wherein the instructions for managing eligibility to designate at least one of the plurality of users to access the at least one configuration entity to sign the data via the plurality of accounts comprises instructions for:

creating the owner account associated with the application platform entity for the sole owner of the application platform entity, and

wherein the instructions for creating the owner account associated with the application platform entity for the sole owner of the application platform entity comprises:

instructions for assigning, by an assigned administrator of the system, the at least one manager of the at least one model entity of hierarchically below the application platform entity; and

instructions for authorizing, by the assigned at least one manager, users associated with the owner account to sign the data to be installed on the devices associated with the configuration entities hierarchically below the model entity, and

wherein the instructions for managing eligibility to designate at least one of a plurality of users to access the at least one configuration entity to sign the data via a plurality of accounts, further comprises instructions for:

creating, by the system administrator, the at least one participant account wherein the participant account is associated with at least one of:

the application platform entity; and

the at least one project entity;

authorizing, by the assigned manager, users associated with the participant account to sign the data to be installed on the devices associated with the configuration entities hierarchically below the model entity;

wherein:

the sole owner of the owner account is a first business organization;

the at least one participant account is associated with a second business organization independent from the first organization.

8. The system of claim 7 , wherein:

the owner account further provides sole eligibility to designate at least one manager of the at least one model entity hierarchically below the application platform entity to authorize access to all configuration entities hierarchically below the at least one model entity to sign the data to be installed on the devices associated with the configuration entities hierarchically below the at least one model entity; and

wherein the at least one manager can authorize access to all of the configuration entities hierarchically below the at least one model entity to only users of the plurality of users that are associated with the owner account of the application platform entity hierarchically above the model entity or the participant account of the application platform entity hierarchically above the model entity.

9. A system managing the signing of data for use with one or more of an plurality of devices of an application platform, each device a member of a device family of the application platform, the data to be installed on the one or more of the plurality of devices according to a management model of the device family, comprising:

a processor; and

a memory, communicatively coupled to the processor, the memory storing instructions comprising instructions for:

defining, by an administrator of the system, a hierarchy of a plurality of entities, the plurality entities comprising, in decreasing hierarchical order:

an application platform entity that produces the plurality of devices, having a sole owner;

at least one project entity for each application platform entity, the project entity comprising the device family;

at least one model entity for each project entity, the model entity defining the installation of the data on devices associated with the model entity; and

at least one configuration entity for each model entity, the configuration entity defining the data to be installed on devices associated with the configuration entity;

managing, by an administrator of the system, eligibility to designate at least one of a plurality of users to access the at least one configuration entity to sign the data via a plurality of accounts, the plurality of accounts comprising:

an owner account of the application platform entity, the owner account issued only to the sole owner of the application platform entity, the owner account providing:

sole eligibility to authorize access the application platform entity; and

eligibility to permit authorization of access to any of the plurality of entities hierarchically below the application platform entity;

eligibility to authorize users associated with the owner account to access at least one configuration entity hierarchically below the application platform entity to sign the data to be installed on the devices associated with the at least one configuration entity;

at least one participant account of the application platform entity or the at least one project entity, providing:

eligibility to authorize users associated with the participant account and no other participant account to access at least one configuration entity hierarchically below the application platform entity or the at least one project entity, respectively, to sign the data to be installed on the devices associated with the at least one configuration entity,

wherein the instructions for creating the owner account associated with the application platform entity for the sole owner of the application platform entity comprises instructions for:

assigning the at least one manager of the at least one model entity hierarchically below the application platform entity;

assigning another manager of another model entity hierarchically below the platform entity;

creating the at least one participant account, wherein the at least one participant account is associated with the at least one project entity;

creating another participant account, wherein the another participant account is associated with another project entity;

authorizing, by the assigned at least one manager, users associated with the at least one participant account and no other participant account to sign the data to be installed on the devices associated with the configuration entities hierarchically below the at least one model entity;

authorizing, by the assigned another manager, users associated with the another participant account and no other participant account to sign the data to be installed on the devices associated with the configuration entities hierarchically below the another model entity;

wherein:

the sole owner of the owner account is a first business organization;

the at least one participant account is associated with a second business organization independent from the first business organization;

the another participant account is associated with a third business organization independent from the first business organization and the second business organization.

10. The system of claim 7 , wherein:

the system comprises a back end server communicatively coupled to a front end server for controlling access to the back end server;

the instructions for defining the hierarchy of the plurality of entities is performed using the back end server accessed by the front end server; and

the instructions for managing eligibility to designate at least one of a plurality of users to access the at least one configuration entity to sign the data via a plurality of accounts is performed using the backend server accessed by the front end server.

11. The system of claim 7 , wherein the instructions further comprise instructions for:

enforcing, using the backend server, the:

sole eligibility to authorize access the application platform entity; and

eligibility to permit authorization of access to any of the plurality of entities hierarchically below the application platform entity;

eligibility to authorize users associated with the owner account to access at least one configuration entity hierarchically below the application platform entity to sign the data to be installed on the devices associated with the at least one configuration entity;

eligibility to authorize users associated with the participant account to access at least one configuration entity hierarchically below the application platform entity or the at least one project entity, respectively, to sign the data to be installed on the devices associated with the at least one configuration entity;

performing, using the backend server, cryptographic operations to sign the data; and

executing, using the front end server, a presentation layer, the presentation layer controlling user access to the backend server.

Assignments (9)
SECURITY INTEREST Recorded Apr 8, 2026
From: ARRIS ENTERPRISES LLC; RUCKUS IP HOLDINGS LLC
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 075476/0814 →
RELEASE OF SECURITY INTEREST AT REEL/FRAME 049905/0504 Recorded Dec 19, 2024
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: ARRIS ENTERPRISES LLC (F/K/A ARRIS ENTERPRISES, INC.); ARRIS TECHNOLOGY, INC.; ARRIS SOLUTIONS, INC.; COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; RUCKUS WIRELESS, LLC (F/K/A RUCKUS WIRELESS, INC.)
Reel/Frame 071477/0255 →
SECURITY INTEREST Recorded Dec 17, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE INC., OF NORTH CAROLINA; OUTDOOR WIRELESS NETWORKS LLC; RUCKUS IP HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC
Reel/Frame 069889/0114 →
SECURITY INTEREST Recorded Nov 19, 2021
From: ARRIS SOLUTIONS, INC.; ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA; RUCKUS WIRELESS, INC.
To: WILMINGTON TRUST
Reel/Frame 060752/0001 →
PATENT SECURITY AGREEMENT Recorded Jul 3, 2019
From: ARRIS ENTERPRISES LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 049820/0495 →
ABL SECURITY AGREEMENT Recorded Jul 3, 2019
From: COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; ARRIS ENTERPRISES LLC; ARRIS TECHNOLOGY, INC.; RUCKUS WIRELESS, INC.; ARRIS SOLUTIONS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 049892/0396 →
TERM LOAN SECURITY AGREEMENT Recorded Jul 3, 2019
From: COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; ARRIS ENTERPRISES LLC; ARRIS TECHNOLOGY, INC.; RUCKUS WIRELESS, INC.; ARRIS SOLUTIONS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 049905/0504 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 5, 2017
From: YAO, TING; QIU, XIN; ZHENG, JINSONG; DIZON, PATRICK; MYINT, AYE; KURAMOTO, ANNIE C.; SHAHABUDDIN, RESHMA; BARBOUR, THOMAS J.
To: ARRIS ENTERPRISES LLC
Reel/Frame 042250/0750 →
CHANGE OF NAME Recorded Mar 14, 2017
From: ARRIS ENTERPRISES INC
To: ARRIS ENTERPRISES LLC
Reel/Frame 041995/0031 →
Continuity (2)
Provisional Application 62304641 · Mar 7, 2016
Related Publication 20170257380A1 · Sep 7, 2017