IP Library Patent Application 18946167
Patent Application
App. No. 18/946,167

METHOD AND APPARATUS FOR GENERATING AND USING IMPLICITLY ATTESTED CERTIFICATE SIGNING REQUESTS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/946,167
Abstract

A method and apparatus for generating and processing implicitly attested Certificate Signing Requests (CSRs) is disclosed. In one embodiment, the method comprises generating a message having a public key of a key pair of a device and an identifier of a device; generating a digest of the message; signing the digest according to a private key of the key pair of the device; and encoding the signed digest and the public key to produce the CSR; wherein the CSR implicitly attests to the identity of the device according to at least one of the message, the digest, and the encoding.

Claims (83)

1 . A method of generating an implicitly attested certificate signing request (CSR), comprising:

generating a message having a public key of a key pair of a device and an identifier of a device;

generating a digest of the message;

generating a signature of the message by signing the digest according to a private key of the key pair of the device; and

encoding the message and the signature to produce the CSR;

wherein the CSR implicitly attests to the identity of the device according to at least one of the message, the digest, and the encoding.

2 . The method of claim 1 , wherein:

at least one of the message and the digest are processed according to a transform before the encoding, the transform reversible only by a recipient of the CSR to recover the at least one of the message and the digest and to implicitly attest to an identity of the device.

3 . The method of claim 2 , wherein the processing comprises one or more of:

permutation;

bit-swapping; and

bit-shifting.

4 . The method of claim 2 , wherein the digest is processed, and the processing comprises one or more of:

permutation of the digest;

bit-swapping of the digest;

bit-shifting of the digest; and

augmenting the digest with an identifier of the device.

5 . The method of claim 2 , wherein:

the digest is generated by a hash algorithm; and

the processing comprises hashing the digest one or more additional times.

6 . The method of claim 2 , wherein the digest is generated by a non-standard hash algorithm.

7 . The method of claim 1 , wherein the public key and the signed digest are encoded according to a non-standard encoding, decodable only by a recipient of the encoded CSR to recover the message and the digest and to implicitly attest an identity of the device.

8 . The method of claim 7 , wherein the non-standard encoding comprises an encoding proprietary to the device and recipient of the CSR.

9 . The method of claim 1 , wherein:

the method further comprises:

providing the CSR to a Certificate Authority;

attesting the CSR according to the at least one of the message, the digest, and the encoding;

authenticating the CSR by:

generating a digest of the message;

verifying the signature according to the digest and the public key to produce a verification result; and

authenticating the CSR according to the verification result.

10 . An apparatus for generating an implicitly attested certificate signing request (CSR), comprising:

a processor;

a memory, communicatively coupled to the processor, the memory storing processor instructions comprising processor instructions for:

generating a message having a public key of a key pair of a device;

generating a digest of the message;

generating a signature of the message by signing the digest according to a private key of the key pair of the device; and

encoding the message and the signature to produce the CSR; and

wherein the CSR implicitly attests to the identity of the device according to at least one of the message, the digest, and the encoding.

11 . The apparatus of claim 10 , wherein:

at least one of the message and the digest are processed according to a transform before the encoding, the transform reversible only by a recipient of the encoded CSR to recover the at least one of the message and the digest and to implicitly attest to an identity of the device.

12 . The apparatus of claim 11 , wherein the processing comprises one or more of:

permutation;

bit-swapping; and

bit-shifting.

13 . The apparatus of claim 11 , wherein the digest is processed, and the processing comprises one or more of:

permutation of the digest;

bit-swapping of the digest;

bit-shifting of the digest; and

augmenting the digest with an identifier of the device.

14 . The apparatus of claim 11 , wherein:

the digest is generated by a hash algorithm; and

the processing comprises hashing the digest one or more additional times.

15 . The apparatus of claim 11 , wherein the digest is generated by a non-standard hash algorithm.

16 . The apparatus of claim 10 , wherein the public key and the signed digest are encoded according to a non-standard encoding, decodable only by a recipient of the encoded CSR to recover the message and the digest and to implicitly attest an identity of the device.

17 . The method of claim 16 , wherein the non-standard encoding comprises an encoding proprietary to the device and recipient of the CSR.

18 . A method of providing a digital certificate in response to an implicitly attested certificate signing request (CSR), comprising:

receiving the CSR, the CSR generated by:

generating a message having a public key of a key pair of a device, and a device identifier;

generating a digest of the message;

generating a signature by signing the digest according to a private key of the key pair of the device; and

encoding the message and the signature to produce the CSR;

decoding the CSR;

implicitly attesting the CSR according to the at least one of the message, the digest, and the encoding;

authenticating the CSR by:

generating a digest of the message;

verifying the signature according to the digest and the public key to produce a verification result; and

authenticating the CSR according to the verification result; and

providing the digital certificate only if the decoded CSR is implicitly attested and authenticated.

19 . The method of claim 17 , wherein:

the message and the encoded according to a non-standard encoding decodable only by the recipient of the CSR; and

determining if the decoded CSR is attested comprises:

determining if the CSR is decodable according to the non-standard encoding; and

identifying the CSR as attested only if the CSR is decodable according to the non-standard decoding.

20 . The method of claim 17 , wherein:

at least one of the message and the digest are processed according to a transform before the encoding, the transform reversible only by the recipient of the CSR to recover the at least one of the message and the digest; and

determining if the decoded CSR is attested comprises:

reversing the transform of the at least one of the message and the digest; and

implicitly attesting to the identity of the device according to the reversed transform.

21 . The method of claim 17 , wherein determining if the decoded CSR is attested comprises:

determining if the device identifier is on a whitelist of legitimate device identifiers or on a blacklist of illegitimate device identifiers;

if the device identifier is on the whitelist of legitimate device identifiers, attesting to the identity of the device and providing the digital certificate; and

if the device identifier is on the blacklist of illegitimate device identifiers, returning an error.

Assignments (3)
SECURITY INTEREST Recorded Apr 8, 2026
From: ARRIS ENTERPRISES LLC; RUCKUS IP HOLDINGS LLC
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 075476/0814 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 28, 2025
From: QIU, XIN; YIN, YIQUN; JIANG, OSCAR; PASION, JASON A.
To: ARRIS ENTERPRISES LLC
Reel/Frame 070031/0073 →
SECURITY INTEREST Recorded Dec 17, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE INC., OF NORTH CAROLINA; OUTDOOR WIRELESS NETWORKS LLC; RUCKUS IP HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC
Reel/Frame 069889/0114 →