IP Library Granted Patent US 12,659,301
Granted Patent B2
US 12,659,301 · App. 18/082,130 · Granted Jun 16, 2026

System and method for field provisioning of credentials using qr codes

Inventors: Alexander Medvinsky (San Diego, CA); Nicol C. P. So (Newtown, PA); Tat Keung Chan (San Diego, CA); Greg Nakanishi (San Diego, CA)
Assignee: ARRIS Enterprises LLC
H04L63/0435G06K7/1417H04L9/0825H04L9/14H04L9/3073H04L9/3226
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,659,301
App. No.
18/082,130
Granted
Jun 16, 2026
Kind
B2
Abstract

A system and method for authenticating a user device is disclosed. In one embodiment, the method comprises: transmitting a request for credentials from the user device, wherein the request comprises a user device identifier and the credentials comprise an asymmetric key pair having a public key and an associated private key, the private key being encrypted; receiving the credentials in the user device, the credentials comprising the encrypted private key and the public key; retrieving quick response (QR) code data associated with the user device identifier from a QR code data directory, the QR code data generated from the public key and stored in the QR code data directory according to the user device identifier by a secure online service; extracting the public key from the QR code data; and establishing an authenticated and encrypted communication session with the user device according to the extracted public key.

Claims (72)

1 . A method of authenticating a user device, comprising:

transmitting a request for credentials from the user device, wherein:

the request comprises a user device identifier;

the credentials comprise an asymmetric key pair having a public key and an associated private key, the private key being encrypted, where the private key is encrypted according to an inner key pre-provisioned to the user device and the encrypted private key is decrypted according to the inner key and stored in the user device;

receiving the credentials in the user device, the credentials comprising the encrypted private key and the public key;

retrieving quick response (QR) code data associated with the user device identifier from a QR code data directory, the QR code data generated from the public key and stored in the QR code data directory according to the user device identifier by a secure online service;

extracting the public key from the QR code data; and

establishing an authenticated and encrypted communication session with the user device according to the extracted public key.

2 . The method of claim 1 , wherein:

the public key and associated encrypted private key is one of a plurality public keys and associated encrypted private keys, generated by:

generating, in an off-line system, a plurality of asymmetric key pairs, each asymmetric key pair having a generated public key and an associated generated private key;

encrypting each private key of each symmetric key pair; and

storing public keys and encrypted private key in the secure online service; and

the encrypted private key and the public key is received from the secure online service in response to the request for personalization data.

3 . The method of claim 2 , wherein:

the user device identifier is provided to the secure online service as part of a request for credentials, and

the QR code data is generated by the secure online service based on the public key and forwarded to the QR code directory along with the associated user device identifier for storage.

4 . The method of claim 2 , wherein the QR code data is retrieved at least in part via a user interface (UI) enabled device for displaying a QR code generated from the QR code data.

5 . The method of claim 4 , wherein:

retrieving the QR code data associated with the user device identifier from the QR code data directory comprises:

accepting a request for the QR code data, the request comprising the user device identifier;

providing the QR code data to the UI enabled device; and

scanning a QR code presented on the UI enabled device, the QR code generated from the QR code data.

6 . The method of claim 5 , wherein:

the request for credentials further comprises at least one of a media access control (MAC) address of the user device or a Wi-Fi channel of the user device; and

the request for the QR code data further comprises the at least one of the MAC address of the user device or the Wi-Fi channel of the user device.

7 . The method of claim 6 , wherein the QR code data generated by the secure online service is based on the public key and the at least one of the MAC address of the user device and the Wi-Fi channel of the user device.

8 . The method of claim 5 , wherein:

the request for the QR code data is accepted in a user registration portal and forwarded from the user registration portal to the QR code data directory; and

the QR code data is provided by the QR code data directory to the UI enabled device via the user registration portal.

9 . The method of claim 4 , wherein:

a communication path between the user device and the secure online service is selected from a group comprising:

a mobile operator network; and

a temporary Wi-Fi connection established by password-based authentication.

10 . The method of claim 2 , wherein:

the user device identifier is inaccessible to prohibited users;

retrieving the QR code data associated with the user device identifier from the QR code data directory comprises:

accepting the request for the QR code data from a configurator via an encrypted and authenticated communication session, the request for the QR code data including the user device identifier; and

transmitting the QR code data from the QR code data directory to the configurator.

11 . An apparatus for authenticating a user device, comprising

a processor; and

a memory, communicatively coupled to the processor, the memory storing processor instructions comprising processor instructions for:

transmitting a request for credentials from the user device, wherein:

the request comprises a user device identifier;

the credentials comprise an asymmetric key pair having a public key and an associated private key, the private key being encrypted, where the private key is encrypted according to an inner key pre-provisioned to the user device and the encrypted private key is decrypted according to the inner key and stored in the user device;

receiving the credentials in the user device, the credentials comprising the encrypted private key and the public key;

retrieving quick response (QR) code data associated with the user device identifier from a QR code data directory, the QR code data generated from the public key and stored in the QR code data directory according to the user device identifier by a secure online service;

extracting the public key from the QR code data; and

establishing an authenticated and encrypted communication session with the user device according to the extracted public key.

12 . The apparatus of claim 11 , wherein:

the public key and associated encrypted private key is one of a plurality public keys and associated encrypted private keys, generated by:

generating, in an off-line system, a plurality of asymmetric key pairs, each asymmetric key pair having a public key and an associated private key;

encrypting each private key of each symmetric key pair; and

storing public keys and encrypted private key in the secure online service; and

the encrypted private key and the public key is received from the secure online service in response to the request for personalization data.

13 . The apparatus of claim 12 , wherein:

the user device identifier is provided to the secure online service as part of a request for credentials, and

the QR code data is generated by the secure online service based on the public key and forwarded to the QR code directory along with the associated user device identifier for storage.

14 . The apparatus of claim 11 , wherein the QR code data is retrieved at least in part via a user interface (UI) enabled device for displaying a QR code generated from the QR code data.

15 . The apparatus of claim 14 , wherein:

the processor instructions for retrieving the QR code data associated with the user device identifier from the QR code data directory comprise processor instructions for:

accepting a request for the QR code data, the request comprising the user device identifier;

providing the QR code data to the UI enabled device; and

scanning a QR code presented on the UI enabled device, the QR code generated from the QR code data.

16 . The apparatus of claim 15 , wherein:

the request for the QR code data is accepted in a user registration portal and forwarded from the user registration portal to the QR code data directory; and

the QR code data is provided by the QR code data directory to the UI enabled device via the user registration portal.

17 . The apparatus of claim 12 , wherein:

the user device identifier is inaccessible to prohibited users;

the processor instructions for retrieving the QR code data associated with the user device identifier from the QR code data directory comprise processor instructions for:

accepting the request for the QR code data from a configurator via an encrypted and authenticated communication session, the request for the QR code data including the user device identifier; and

transmitting the QR code data from the QR code data directory to the configurator.

Assignments (7)
SECURITY INTEREST Recorded Apr 8, 2026
From: ARRIS ENTERPRISES LLC; RUCKUS IP HOLDINGS LLC
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 075476/0814 →
RELEASE OF SECURITY INTEREST AT REEL/FRAME 067252/0657 Recorded Jan 12, 2026
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE NORTH CAROLINA, LLC (F/K/A COMMSCOPE, INC. OF NORTH CAROLINA)
Reel/Frame 074593/0348 →
RELEASE OF SECURITY INTEREST AT REEL/FRAME 067259/0697 Recorded Dec 19, 2024
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: ARRIS ENTERPRISES LLC (F/K/A ARRIS ENTERPRISES, INC.); COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC
Reel/Frame 069790/0575 →
SECURITY INTEREST Recorded Dec 17, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE INC., OF NORTH CAROLINA; OUTDOOR WIRELESS NETWORKS LLC; RUCKUS IP HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC
Reel/Frame 069889/0114 →
PATENT SECURITY AGREEMENT (TERM) Recorded Apr 29, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 067259/0697 →
PATENT SECURITY AGREEMENT (ABL) Recorded Apr 29, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 067252/0657 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 12, 2023
From: MEDVINSKY, ALEXANDER; SO, NICOL C. P.; CHAN, TAT KEUNG; NAKANISHI, GREG
To: ARRIS ENTERPRISES LLC
Reel/Frame 064883/0067 →
Continuity (2)
Provisional Application 63290355 · Dec 16, 2021
Related Publication 20230198968A1 · Jun 22, 2023
References Cited (23)
US 9130928B2 · Qiu et al. · 2015 [cited by applicant]
US 11251955B2 · Clancy · 2022 [cited by examiner]
US 20130232336A1 · Cheung · 2013 [cited by examiner]
US 20160147979A1 · Kato · 2016 [cited by examiner]
US 20170193543A1 · Priebatsch · 2017 [cited by examiner]
US 20170257819A1 · McCann · 2017 [cited by examiner]
US 20180109418A1 · Cammarota · 2018 [cited by examiner]
US 20180183666A1 · Likar · 2018 [cited by examiner]
US 20180225444A1 · Frenz · 2018 [cited by examiner]
US 20180308086A1 · Shan · 2018 [cited by examiner]
US 20190156167A1 · Singh · 2019 [cited by examiner]
US 20190303071A1 · Tsuji · 2019 [cited by examiner]
US 20190305964A1 · Hamel · 2019 [cited by examiner]
US 20190327311A1 · Khassanov · 2019 [cited by examiner]
US 20190356482A1 · Nix · 2019 [cited by examiner]
US 20200274699A1 · Watson · 2020 [cited by examiner]
US 20200274868A1 · Passaglia · 2020 [cited by examiner]
US 20210111906A1 · Kang · 2021 [cited by examiner]
US 20210306161A1 · Medvinsky · 2021 [cited by examiner]
US 20210365914A1 · Oe · 2021 [cited by examiner]
Symington Susan et al: “NIST Cybersecurity White Paper (Draft) Trusted Internet of Things (IOT) Device Network—Layer Onboarding and Lifecycle Management”, National Institute of Standards and Technology. Sep. 8, 2020, pp… [cited by applicant]
Wi-Fi Alliance: “Wi-Fi Easy Connect; Specification Versions 2.0”, Dec. 14, 2020, pp. 1-266, XP055768216, Retrieved from the Internet: URL: https://www.wi-fi.org/download.php?file=/sites/default/files/private/Wi-Fi_Easy_… [cited by applicant]
International Search Report and Written Opinion RE: Application No. PCT/US22/053018, dated Mar. 28, 2023. [cited by applicant]