IDENTITY DATA MANAGEMENT SYSTEM FOR HIGH VOLUME PRODUCTION OF PRODUCT-SPECIFIC IDENTITY DATA
    1.
    发明申请
    IDENTITY DATA MANAGEMENT SYSTEM FOR HIGH VOLUME PRODUCTION OF PRODUCT-SPECIFIC IDENTITY DATA 有权
    用于高产量产品特定身份数据的身份数据管理系统

    公开(公告)号:US20130227077A1

    公开(公告)日:2013-08-29

    申请号:US13407081

    申请日:2012-02-28

    CPC分类号: G06F17/30595 H04L63/0823

    摘要: A method and apparatus is provided for maintaining inventory levels of identity data to be provisioned in electronic devices. The method includes monitoring over a communications network inventory levels of identity data records stored on a plurality of identity data personalization servers that each provision electronic devices with an identity data record. Additionally, if the inventory level on at least one of the identity data personalization servers falls below a minimum specified level, a refill request is sent to an identity data management authority requesting that additional identity data records be uploaded to the identity data personalization server.

    摘要翻译: 提供了一种用于维护在电子设备中提供的身份数据的库存水平的方法和装置。 该方法包括监视存储在多个身份数据个性化服务器上​​的身份数据记录的通信网络库存水平,每个身份数据记录提供具有身份数据记录的电子设备。 此外,如果至少一个身份数据个性化服务器上​​的库存级别低于最小指定级别,则向身份数据管理机构发送重新填充请求,请求将附加的身份数据记录上传到身份数据个性化服务器。

    Method and apparatus for a configurable online public key infrastructure (PKI) management system
    2.
    发明授权
    Method and apparatus for a configurable online public key infrastructure (PKI) management system 有权
    可配置在线公钥基础设施(PKI)管理系统的方法和装置

    公开(公告)号:US08370626B2

    公开(公告)日:2013-02-05

    申请号:US12854922

    申请日:2010-08-12

    IPC分类号: H04L9/00

    CPC分类号: H04L9/3265 H04L9/007

    摘要: A method and apparatus are provided for generating identity data to be provisioned in product devices that are a part of a project. The method includes establishing a template associated with each CA in a hierarchical chain of CAs having a root CA at a highest level in the chain and a signing CA at a lowest level in the chain. The template associated with the signing CA inherits mandatory attribute fields specified in the root CA and any intermediate CA in the hierarchical chain. The mandatory attribute fields are user-specifiable fields to be populated with PKI data. A configuration file is generated upon receipt of an order for digital certificates using PKI data provided by a user to populate the mandatory attribute fields of the template associated with the signing CA. The digital certificates requested in the order are generated using the PKI data in the configuration file.

    摘要翻译: 提供了一种用于生成作为项目的一部分的产品设备中提供的身份数据的方法和装置。 该方法包括在具有链中最高级别的根CA的CA的分级链中建立与每个CA相关联的模板以及链中最低级的签名CA。 与签名CA相关联的模板继承根CA中指定的强制属性字段和层级链中的任何中间CA。 强制属性字段是要填充PKI数据的用户指定字段。 使用由用户提供的PKI数据接收到数字证书的订单时,生成配置文件来填充与签名CA相关联的模板的强制属性字段。 使用配置文件中的PKI数据生成订单中请求的数字证书。

    CONFIGURABLE ONLINE PUBLIC KEY INFRASTRUCTURE (PKI) MANAGEMENT FRAMEWORK
    3.
    发明申请
    CONFIGURABLE ONLINE PUBLIC KEY INFRASTRUCTURE (PKI) MANAGEMENT FRAMEWORK 审中-公开
    可配置在线公钥基础设施(PKI)管理框架

    公开(公告)号:US20110197061A1

    公开(公告)日:2011-08-11

    申请号:US12854920

    申请日:2010-08-12

    IPC分类号: H04L29/06

    CPC分类号: H04L9/006 H04L9/3265

    摘要: A method and apparatus is provided for establishing a process for provisioning a digital certificate service delivered by a PKI system. The method includes receiving a request for a digital certificate service and receiving data specifying a project that includes at least one product to be provisioned with a digital certificate. Data specifying an identification of an owner organization of the project and at least one participant organization participating in the project is also received. Attributes with which PKI data to be included in the digital certificates is to comply is received from the owner organization. Based on the received data and attributes, an account is established for each of the organizations associated with the project through which users associated with each of the organizations can respectively request digital certificates for the at least one product in accordance with the attributes received from the owner organization.

    摘要翻译: 提供了一种用于建立用于提供由PKI系统提供的数字证书服务的过程的方法和装置。 该方法包括接收对数字证书服务的请求,并且接收指定项目的数据,所述项目包括至少一个要被提供数字证书的产品。 还收到了指定项目所有者组织的标识和参与该项目的至少一个参与组织的数据。 从所有者组织收到要包含在数字证书中的PKI数据符合的属性。 根据接收到的数据和属性,为与项目相关联的每个组织建立一个帐户,通过该帐户,与每个组织相关联的用户可以根据从所有者接收的属性分别为至少一个产品请求数字证书 组织。

    METHOD AND APPARATUS FOR A CONFIGURABLE ONLINE PUBLIC KEY INFRASTRUCTURE (PKI) MANAGEMENT SYSTEM
    4.
    发明申请
    METHOD AND APPARATUS FOR A CONFIGURABLE ONLINE PUBLIC KEY INFRASTRUCTURE (PKI) MANAGEMENT SYSTEM 有权
    可配置在线公钥基础设施(PKI)管理系统的方法与装置

    公开(公告)号:US20110047374A1

    公开(公告)日:2011-02-24

    申请号:US12854922

    申请日:2010-08-12

    IPC分类号: H04L9/00

    CPC分类号: H04L9/3265 H04L9/007

    摘要: A method and apparatus are provided for generating identity data to be provisioned in product devices that are a part of a project. The method includes establishing a template associated with each CA in a hierarchical chain of CAs having a root CA at a highest level in the chain and a signing CA at a lowest level in the chain. The template associated with the signing CA inherits mandatory attribute fields specified in the root CA and any intermediate CA in the hierarchical chain. The mandatory attribute fields are user-specifiable fields to be populated with PKI data. A configuration file is generated upon receipt of an order for digital certificates using PKI data provided by a user to populate the mandatory attribute fields of the template associated with the signing CA. The digital certificates requested in the order are generated using the PKI data in the configuration file.

    摘要翻译: 提供了一种用于生成作为项目的一部分的产品设备中提供的身份数据的方法和装置。 该方法包括在具有链中最高级别的根CA的CA的分级链中建立与每个CA相关联的模板以及链中最低级的签名CA。 与签名CA相关联的模板继承根CA中指定的强制属性字段和层级链中的任何中间CA。 强制属性字段是要填充PKI数据的用户指定字段。 使用由用户提供的PKI数据接收到数字证书的订单时,生成配置文件来填充与签名CA相关联的模板的强制属性字段。 使用配置文件中的PKI数据生成订单中请求的数字证书。

    LAYERED PROTECTION AND VALIDATION OF IDENTITY DATA DELIVERED ONLINE VIA MULTIPLE INTERMEDIATE CLIENTS
    6.
    发明申请
    LAYERED PROTECTION AND VALIDATION OF IDENTITY DATA DELIVERED ONLINE VIA MULTIPLE INTERMEDIATE CLIENTS 有权
    通过多个中间客户在线提供的身份数据的分层保护和验证

    公开(公告)号:US20110213957A1

    公开(公告)日:2011-09-01

    申请号:US12854925

    申请日:2010-08-12

    IPC分类号: H04L9/14

    摘要: A method is provided for securely delivering identity data units over a communications network to a client device. The method includes receiving a selection from a customer identifying a final zipped package to be unpacked. The final zipped package is unpacked to obtain a common package and a digital signature file signed by an entity generating identity data requested by the customer. The digital signature in the digital signature file is verified and the common package is unpacked to obtain a plurality of outer packages and an encrypted symmetric key. The symmetric key is decrypted with a private key associated with the customer and each of the outer packages is decrypted with the symmetric key to obtain a plurality of identity data units.

    摘要翻译: 提供了一种用于通过通信网络将身份数据单元安全地传送到客户端设备的方法。 该方法包括从客户接收标识要解包的最终压缩包的选择。 最后的压缩包解包以获得由生成客户请求的身份数据的实体签名的公用包和数字签名文件。 验证数字签名文件中的数字签名,并解压缩公用包以获得多个外包和加密对称密钥。 对称密钥用与客户相关联的私钥解密,并且每个外部包被对称密钥解密以获得多个身份数据单元。

    Online secure device provisioning framework
    7.
    发明授权
    Online secure device provisioning framework 有权
    在线安全设备配置框架

    公开(公告)号:US09130928B2

    公开(公告)日:2015-09-08

    申请号:US13087847

    申请日:2011-04-15

    IPC分类号: H04L29/06 G06F21/57

    摘要: A method for updating network-enabled devices with new identity data includes generating a plurality of new identity data records and loading the new identity data records onto an update server. A request is received at the update server for new identity data from at least one network-enabled device having a previously assigned identity linked to an identifier. The previously assigned identifier is linked to a new identifier that is linked to one of the new identity data records. One or more new identity data records are securely delivered to the network-enabled device.

    摘要翻译: 用新的身份数据更新启用网络的设备的方法包括生成多个新的身份数据记录并将新的身份数据记录加载到更新服务器上。 在更新服务器处接收到来自具有链接到标识符的先前分配的身份的至少一个启用网络的设备的新身份数据的请求。 先前分配的标识符被链接到链接到新的身份数据记录之一的新标识符。 一个或多个新的身份数据记录被安全地传送到启用网络的设备。

    CROSS-DOMAIN IDENTITY MANAGEMENT FOR A WHITELIST-BASED ONLINE SECURE DEVICE PROVISIONING FRAMEWORK
    8.
    发明申请
    CROSS-DOMAIN IDENTITY MANAGEMENT FOR A WHITELIST-BASED ONLINE SECURE DEVICE PROVISIONING FRAMEWORK 有权
    基于列表的在线安全设备提供框架的跨域标识管理

    公开(公告)号:US20110258454A1

    公开(公告)日:2011-10-20

    申请号:US13087843

    申请日:2011-04-15

    申请人: Xin Qiu Ting Yao

    发明人: Xin Qiu Ting Yao

    CPC分类号: H04L63/08 H04L63/10

    摘要: A method for managing identifiers associated with network-enabled devices and used in an identity data system provisioning the network-enabled devices with identity data includes receiving a first set data that includes a previously assigned identifier for one or more of the network-enabled devices that are authorized to be provisioned with new identity data. If identity data is currently installed on the one or more network-enabled devices, each of the previously assigned identifiers in the first set of data is associated with a corresponding identifier linked to the identity data currently installed on the one or more network-enabled devices to establish a second set of data. New identity data is bound to each of the one or more network-enabled devices by assigning a new identifier linked with the new identity data to each of the one or more network-enabled devices to establish a whitelist. The whitelist specifies, for each of the one or more network-enabled devices, its previously assigned identifier, its corresponding identifier and its new identifier that is linked with the new identity data.

    摘要翻译: 一种用于管理与启用网络的设备相关联并在身份数据系统中配置具有身份数据的启用网络的设备的标识符的方法包括:接收第一组数据,该第一组数据包括先前分配的一个或多个网络使能设备的标识符, 被授权提供新的身份数据。 如果身份数据当前安装在一个或多个启用网络的设备上,则第一组数据中先前分配的标识符中的每一个都与与当前安装在一个或多个启用网络的设备上的身份数据链接的对应标识符相关联 建立第二组数据。 通过将与新的身份数据链接的新标识符分配给一个或多个启用网络的设备中的每一个来建立白名单,将新的身份数据绑定到一个或多个网络启用设备中的每一个。 白名单为一个或多个网络启用设备中的每一个指定其先前分配的标识符,其对应的标识符及其与新的身份数据链接的新标识符。

    Secure large volume feature license provisioning system

    公开(公告)号:US09646332B2

    公开(公告)日:2017-05-09

    申请号:US13238850

    申请日:2011-09-21

    IPC分类号: G06F21/00 G06Q30/06

    摘要: Disclosed is a manufacturing process and feature licensing system for provisioning personalized (device-unique) licenses to devices. The secure system uses a secure key wrapping mechanism to deliver the LSK to LPS. Another feature is that various network communication links are secured using standard security protocol. Application messages, license templates, licenses are digitally signed. The system is flexible, configured to allow multiple manufacturers and to allow various feature configurations via the use of License Template; scalable, as it is possible to use multiple LPS hosts to serve multiple programming stations; and available in that the delegation of license signing capability from CLS to LPS eliminates the dependency on unreliable Internet connections. Redundant LPS hosts provide high level of availability required for high volume license provisioning. The system is traceable: license and device association are replicated back to the CLS to provide full license request and generation traceability.

    Online secure device provisioning with online device binding using whitelists
    10.
    发明授权
    Online secure device provisioning with online device binding using whitelists 有权
    使用白名单的在线安全设备配置与在线设备绑定

    公开(公告)号:US08627083B2

    公开(公告)日:2014-01-07

    申请号:US13267672

    申请日:2011-10-06

    IPC分类号: H04L9/32

    摘要: One or more servers are provided including a session manager, authentication module, authorization module, encryption module, database, and protocol handler. The session manager is configured to receive requests for new identity data from network-enabled devices. Each request is authenticated first by the update server via its authentication module by validating the signature of the request message as well as the certificate chain trusted by the update server. The authorization module is configured to determine if the network-enabled devices specified on a whitelist are authorized to be provisioned with new identity data. The database is configured to receive new identity records generated by an identity data generation system. Each of the new identity records includes a new identifier. The new identifier is not associated or linked to any previously assigned/used identifiers and identity data, thus all the new identity records are generated independently and then loaded to the update server.

    摘要翻译: 提供一个或多个服务器,包括会话管理器,认证模块,授权模块,加密模块,数据库和协议处理程序。 会话管理器被配置为从网络启用的设备接收新的身份数据的请求。 通过验证请求消息的签名以及由更新服务器信任的证书链,通过其认证模块,更新服务器首先对每个请求进行认证。 授权模块被配置为确定白名单上指定的启用网络的设备是否被授权为新的身份数据提供。 数据库被配置为接收由身份数据生成系统生成的新的身份记录。 每个新的身份记录都包含一个新的标识符。 新标识符不与任何先前分配/使用的标识符和身份数据相关联或链接,因此所有新的身份记录都是独立生成的,然后加载到更新服务器。