System and method for secure appliance operation
15 claims: 1 independent, 14 dependent
- 1システムであって、 第1のセキュアな制御ハブと、 セルラー通信ネットワークと通信するように構成された前記第1のハブ内のセルラートランシーバと、 前記セルラー通信ネットワーク以外と通信するように構成された前記第1のハブ内の短距離トランシーバであって、前記第1のハブは、前記第1のハブの短距離トランシーバの範囲によって定義されるカバレッジ範囲を有する、短距離トランシーバと、 前記第1のハブの動作を制御するための前記第1のハブ内のプロセッサと、 施設全体に分散された複数のネットワーク機器であって、前記複数のネットワーク機器の各々は、前記第1のハブと通信するための短距離トランシーバを有し、前記複数のネットワーク機器のうちの少なくとも第1の部分は、前記第1のハブの短距離トランシーバの前記カバレッジ範囲内にある、複数のネットワーク機器と、 前記第1のハブによって制御される前記複数のネットワーク機器に関する暗号化データを格納するように構成されたブロックチェーンデータストレージ領域と、を備え、 前記第1のハブおよび前記ネットワーク機器の前記第1の部分は、それぞれの前記短距離トランシーバを介してイントラネットネットワークを形成し、 前記第1のハブのプロセッサは、前記格納された暗号化データを使用して、前記複数のネットワーク機器のうちの選択された1つへの暗号化されたコマンドメッセージを生成し、かつ前記コマンドメッセージを送信するように前記第1のハブの短距離トランシーバを制御し、 前記ネットワーク機器の前記第1の部分は、それぞれの前記短距離トランシーバを介して前記第1のハブから前記コマンドメッセージを受信するように構成されているが、前記コマンドメッセージが向けられている前記複数のネットワーク機器のうちの前記選択された1つのみが、前記コマンドメッセージを復号化し、前記復号化されたコマンドメッセージを処理することができ、 インターネットとのすべての通信は、前記セルラートランシーバを介して生じ、そのため、前記複数のネットワーク機器のうちのいずれも、前記インターネットと直接通信することができない、システム。
- 2前記複数のネットワーク機器の前記第1の部分は、前記複数のネットワーク機器のすべてを備える、請求項1に記載のシステム。
- 3前記第1のハブの短距離トランシーバの前記カバレッジ範囲は、前記施設全体には広がっておらず、前記システムは、 前記第1および第2の制御ハブ間の無線通信を可能にするために、前記第1のハブの短距離トランシーバの前記カバレッジ範囲内にカバレッジ範囲を有する短距離トランシーバを有する第2の制御ハブと、 前記第2のハブの動作を制御するための前記第2のハブ内のプロセッサと、をさらに備え、 前記第2のハブのプロセッサは、前記第1のハブの短距離トランシーバから送信された前記暗号化されたコマンドメッセージを受信し、かつ前記第2のハブの短距離トランシーバを使用して前記受信されたコマンドメッセージを再送信するように構成されており、 前記コマンドメッセージが向けられている前記複数のネットワーク機器のうちの前記選択された1つのみが、前記コマンドメッセージを復号化し、前記復号化されたコマンドメッセージを処理することができる、請求項1または2に記載のシステム。
- 4前記セルラー通信ネットワークと通信するように構成された前記第2のハブ内のセルラートランシーバをさらに備え、前記第2のハブは、前記第1のハブとは独立して前記セルラー通信ネットワークと直接通信することができる、請求項3に記載のシステム。
- 5前記第2のハブは、前記第1のハブのセルラートランシーバを介してのみ前記セルラー通信ネットワークと通信するように構成されている、請求項3に記載のシステム。
- 6前記第1のハブの短距離トランシーバの前記カバレッジ範囲は、前記施設全体には広がっておらず、前記複数のネットワーク機器のうちの少なくとも前記第1の部分は、前記第1のハブを有するメッシュネットワーク内のノードとして構成されており、前記コマンドメッセージが、前記複数のネットワーク機器のうちの前記選択された1つ以外のネットワーク機器に向けられているとき、前記ノードは、それぞれの前記短距離トランシーバを介して前記第1のハブから前記コマンドメッセージを受信し、かつそれぞれの前記短距離トランシーバを使用して前記受信されたコマンドメッセージを再送信するように構成されており、 前記コマンドメッセージが向けられている前記複数のネットワーク機器のうちの前記選択された1つは、前記コマンドメッセージを復号化し、前記復号化されたコマンドメッセージを処理するように構成されている、請求項1または2に記載のシステム。
- 7前記複数のネットワーク機器の各々は、前記イントラネットネットワーク外の前記複数のネットワーク機器のうちのいずれからのいかなる直接通信も防止する様態で構成されている、請求項1~6のいずれか一項に記載のシステム。
- 8前記ブロックチェーンデータストレージ領域は、前記第1のハブのストレージ領域内にローカルに格納される、請求項1~7のいずれか一項に記載のシステム。
- 9前記ブロックチェーンデータストレージ領域は、前記第1のハブから遠隔のデータストレージ領域内に格納される、請求項1~7のいずれか一項に記載のシステム。
- 10前記ブロックチェーンデータストレージ領域は、前記第1のハブから遠隔の複数の分散データストレージ領域内に格納される、請求項1~7のいずれか一項に記載のシステム。
- 11前記ブロックチェーンデータストレージ領域は、単一ブロックとして前記第1のハブのストレージ領域内にローカルに格納され、前記システムは、前記第1のハブから遠隔であり、かつ複数のデータブロックをブロックチェーンとして格納するように構成された、複数の分散データストレージ領域をさらに備える、請求項1~7のいずれか一項に記載のシステム。
- 12前記第1のハブ内の前記セルラートランシーバは、ピコセルとして構成されており、無線セルラー通信リンクを介して前記セルラー通信ネットワークの基地局と通信する、請求項1~11のいずれか一項に記載のシステム。
- 13前記第1のハブのプロセッサは、前記無線セルラー通信リンクの信号品質の尺度を判定し、前記信号品質の尺度に基づいて、前記セルラートランシーバの受信部の増幅レベルを調整し、前記信号品質の尺度に基づいて、前記セルラートランシーバの送信部の送信電力レベルを調整する、請求項12に記載のシステム。
- 14前記第1のハブのプロセッサは、前記第1のハブの短距離トランシーバと、前記複数のネットワーク機器のうちの少なくとも1つの前記短距離トランシーバとの間の無線通信リンクの信号品質の尺度を判定し、前記信号品質の尺度に基づいて、前記第1のハブの短距離トランシーバの受信部の増幅レベルを調整し、前記信号品質の尺度に基づいて、前記第1のハブの短距離トランシーバの送信部の送信電力レベルを調整する、請求項1~13のいずれか一項に記載のシステム。
- 15前記短距離トランシーバは、IEEE802.11規格に従って動作するように構成されている、請求項1~14のいずれか一項に記載のシステム。
Independent claims15
64 paragraphs, as filed
Background of the Invention The present disclosure relates generally to telecommunications, and more specifically to systems and methods for secure operation using networked devices.
Connected devices have evolved in the range of capabilities and complexity. Early sensors were involved in simple functions such as reading gas meters or electric meters and reporting data to utilities over the Internet. However, safety sensors (eg, gas detectors, smoke detectors, etc.), security devices (eg, intrusion detection, motion sensors, security cameras, etc.), environmental controls (eg, heating / cooling controls, ventilation, etc.), and operating conditions. A wide range of devices are currently available for "smart homes" or offices, including surveillance (eg, surveillance in refrigerators, washing machines / dryers, etc.). A wide range of Internet-connected devices are sometimes referred to as "Internet of Things" (IoT) devices or devices. In this context, the term "equipment" broadly refers to networked devices, not just household appliances such as washing machines, dryers, refrigerators and the like.
How difficult it is to manage the security, integration, and payment issues associated with a device when considering the complexity associated with a smart home or office that is fully connected to a range of different IoT-based sensors from different companies. Will be revealed. Each device typically has its own controller. In addition, most existing smart home solutions are based on unlicensed networks that provide minimal control and security. Some devices offer no security at all. Unauthorized network implementations make the system more vulnerable to hacking.
Numerous attacks involve corrupted IoT devices. For example, IoTroop has exploited several known security vulnerabilities to infect more than 9 million IoT devices. In another example, the Mirai malware triggered a persistent distributed denial of service (DDoS) attack from over 175,000 IoT devices. A DDoS attack on Liberia has almost destroyed the country's entire Internet. In yet another example, a random denial of service (RDoS) attack in South Korea involved seven banks by abusing IoT devices. Therefore, the threat of network attacks using IoT vices is very realistic.
Vulnerability to security breaches is so high that many security checks are needed to bring the concept of smart homes to life. For example, smart homes can each have dozens of IoT devices that transfer sensitive data over the Internet. Such implementations pose a serious security threat if not properly protected. In addition, if one node on the home network is compromised, it jeopardizes the entire network. Moreover, different security protocols on different devices make it more difficult to provide a trusted network. From the consumer's point of view, privacy is an important concern when some IoT devices may be communicating using the customer's personal information. Therefore, it can be understood that there is a great need for centralized communication systems that integrate IoT devices to make networks more secure and convenient for end users. The present disclosure provides this and other advantages, as will become apparent from the detailed description below and the accompanying drawings.
<figref num="1">An example of a system architecture for implementing the system of the present disclosure is illustrated.</figref><figref num="2">An example of system implementation by the architecture shown in Fig. 1 is illustrated.</figref><figref num="3">An example of an alternative system implementation based on the architecture shown in FIG. 1 is illustrated.</figref><figref num="4">It is a functional block diagram of the network connection device used in the system architecture of FIG.</figref><figref num="5">It is a functional block diagram of a secure hub used in the system architecture of FIG.</figref><figref num="6A">A screenshot of the login procedure using the device according to the present disclosure is shown.</figref><figref num="6B">A screenshot of the login procedure using the device according to the present disclosure is shown.</figref><figref num="7">The two-step verification procedure is illustrated.</figref><figref num="8">The sample data entries of network equipment in a secure database according to the present disclosure are illustrated.</figref><figref num="9">Illustrates a blockchain implementation of a secure database.</figref>
The techniques described herein provide a fully integrated, plug-and-play-based secure solution using both licensed and unlicensed wireless networks. With the planned introduction of fixed 5G wireless networks, the bandwidth will exceed the current bandwidth capacity of existing wired Internet bandwidth, making unlimited data faster and more accessible. Cryptographic techniques such as blockchain technology are used to provide additional security, as described in more detail herein. The blockchain includes the unique ability to respond to external attacks by using the complex encryption of the transaction ledger contained within the block. In addition, blockchain technology uses distributed data storage rather than centralized data storage, which has the advantage of making it more secure and more difficult for intruding hackers. These approaches minimize the potential for attacks on networked devices. Prior art devices are commonly referred to as IoT devices because of their internet connectivity. However, as described in more detail below, devices implemented in accordance with the present disclosure cannot communicate directly with the Internet and are therefore not IoT devices. Alternatively, the devices described herein may be referred to as network-connected devices because they are connected on a mesh network. As used herein, the term "equipment" broadly refers to networked devices, not just household appliances such as washing machines, dryers, refrigerators, and the like.
In addition, the techniques described herein provide additional device security for each device using public / private key encryption as part of the blockchain while communicating securely with each device. Provides techniques for. As a certificate provider, device authentication provides the opportunity to monetize the system on a hub-by-hub or device-by-device basis.
The present disclosure provides an example of an implementation of the secure network equipment system of the present disclosure. However, those skilled in the art can apply the principles of the present disclosure in smart homes for lighting and environmental control, eg, efficient use of energy resources, smart sensors and cameras based on user and environmental behavior. Home security and surveillance with remote security and surveillance by, care and tracking of pets by using smart sensors, thereby ensuring quality of care, leveraging smart sensors to automatically request groceries Use smart sensors and vital sign detectors to detect and order smart grocery shopping and delivery for on-time delivery, and to remotely monitor elderly people and provide on-time medical response in emergencies. You will understand that it provides care for the elderly through.
In a corporate environment, the systems of the present disclosure may provide predictive maintenance, which may reduce operating capital costs by facilitating proactive service and repair of assets such as vehicles, office equipment, etc. .. In addition, the system is an asset that uses built-in sensors to control supply chain management, automation workflow utilization, validation, and processing with smart tracking of end-to-end supply chain cycles from manufacturing to delivery. Verification and optimization, can be provided. RFID-enabled sensor Interiji understand the behavior of consumers , such as to provide an E cement marketing, in order to achieve operational efficiency and retail beacons, fleet management may be provided using a smart sensor and tracker.
The system is based on smart weighing using autonomous weighing of utilities such as gas, electricity and water, smart grid operation by providing efficient energy management and load balancing, and efficient management of water resources. It provides benefits to local governments, such as water and waste management work and waste reuse for improved sustainability through the use of smart sensors. In addition, the system can provide smart transportation planning through the use of automated traffic management that utilizes real-time data provided by sensors. In addition, the system provides safety and security by monitoring potential threats through the use of security cameras and automatic alerts by response teams in the event of a safety hazard, fire, etc.
At the manufacturing site, the system enables smart manufacturing operations by providing smart control of the manufacturing process / assembly line using remote monitoring and timely adjustment of the assembly line process. The system brings smart field services and associated workers by providing smart tracking in the monitoring of work teams to improve efficiency. Prophylactic maintenance can be provided by using remote sensors, thereby reducing operating and capital costs by facilitating proactive service and repair of assets such as vehicles, industrial equipment, etc. obtain. The system provides smart environmental solutions through the use of automated environment (eg, heat / energy / water) control to enable efficient use of resources. The system also provides a digital supply chain with smart tracking of end-to-end supply chain cycles from manufacturing to delivery.
The techniques described herein are illustrated in the system diagram of FIG. 1 in which the system 100 includes a secure hub 102 in an exemplary embodiment. 104 of the plurality of network connection devices 1 to N are wirelessly connected to the hub 102 via their respective wireless communication links 106. Details of the wireless communication link 106 are provided below.
In addition to the wireless communication link 106, the hub 102 includes a cellular communication link 110 to one or more base stations 112. As will be appreciated by those skilled in the art, cellular communication links can be established with multiple base stations. For clarity, FIG. 1 illustrates only a single base station 112. Those skilled in the art will further understand that base station 112 is representative of a cellular system operated by one of many different cellular network operators. System 100 is configured to operate satisfactorily with any cellular network operator by configuring hub 102 to communicate using cellular technology compatible with the desired cellular network operator. Can be done. That is, the hub 102 may be configured to communicate using cellular standards such as CDMA, GSM®. System 100 is not limited by any particular form of cellular communication.
FIG. 1 illustrates a backhaul connection 114 between a base station 112 and a core network 116 operated by a cellular network operator. The operation of base station 112 and core network 116 is known to those of skill in the art and does not need to be described in more detail herein. In some situations, it may be desirable for hub 102 to communicate with a wide area network (WAN) 120, such as the Internet. To allow access to WAN 120, core network 116 typically includes gateway 118 to facilitate such communication. All communications from hub 102 to WAN 120 are pre-encrypted within the hub, for example, using pre-internet encryption (PIE) so that any data detector intercepts only the encrypted data.
As described in more detail below, communication control is achieved via a unique device-to-device communication protocol, referred to herein as the ioXt protocol, to provide secure communication links.
System 100 also includes network equipment 104, a secure hub 102, and a secure database 124 for storing encrypted data about the entire system architecture. As described in more detail below, the secure database 124 can be implemented in a variety of different configurations. The dashed line connecting to the secure database 124 in Figure 1 illustrates a different alternative configuration. For example, in a residential configuration, the end user may wish to have a secure database 124 that resides locally within the residential. In this implementation, a direct communication link 126 is provided between the hub 102 and the secure database 124. In another embodiment, the secure database 124 may be controlled and operated by a cellular network operator. In this implementation, the secure database 124 can be attached to the core network 116 over the communication link 128. In yet another implementation, the secure database 124 can be accessed over WAN 120. This can be especially desirable for distributed versions of secure databases. In this embodiment, the secure database 124 is linked to the WAN 120 via a communication link 130. As described in detail below, in an exemplary embodiment of System 100, the secure database 124 can be configured as a blockchain that can be part of a cloud computing network. In one embodiment, a portion of the secure database may be integrated with the hub 102 or be accessible by the hub and may include information about the local network equipment 104 controlled by the hub. The secure database 124 may include information about each user, including a list of hubs 102, network equipment 104, and user information. Those skilled in the art will appreciate that the secure database 124 contains information about multiple users and only some of the network devices 104 to which the users are connected to a particular hub. You will understand that you can authorize access to. For example, in a residential environment, system 100 allows all users to control certain elements such as lighting, while certain users (eg children) have other networks such as environmental controls, security settings, etc. It can be configured to restrict access to the device. Thus, the secure database not only contains information about hub 102 and network equipment 104, but also which secure hub 102 may be accessible to the user and which network equipment 104 may be accessible to the user. Information about the user, including the identification, can also be included.
A copy of that portion of the secure database 124 may be further stored as a block in the blockchain database. The blockchain database may contain data entries for all networked devices 104, not only in a particular dwelling, but in all dwelling, enterprise implementations, and other implementations of System 100 operating according to the ioXt protocol. ..
Finally, FIG. 1 illustrates a user device (UE) 132 that communicates with the hub 102 via a wireless communication link 134. When the UE is communicating with the hub, the UE 132 works with the hub 102 to provide a secure connection to all network devices 104. As described in more detail below, this control is achieved through the use of the ioXt protocol to provide secure links and behavior equivalent to blockchain implementations in an "intranet" mesh environment. As described in more detail below, the mesh allows various network devices 104 to communicate with each other in a peer-to-peer network. In this network, data can be securely shared from one network device 104 to another network device 104.
UE132 may also control System 100 from a remote location. For example, a homeowner may be on vacation and still have access to and control over System 100. In this embodiment, the UE 132 communicates with a secure hub via the cellular communication link 110. The UE 132 can typically access the WAN 120 and communicate with the cellular network operator via the gateway 118 and the core network 116. Alternatively, the UE 132 may communicate directly with the cellular network operator via base station 112 or another base station (not shown) that is part of the cellular network. In this embodiment, the UE 132 uses a cellular communication link (not shown) to access the core network 116.
Data from UE 132 is transmitted from base station 112 to hub 102 via cellular communication link 110. Hub 102 then acts on the command initiated by UE 132. In response to a particular command, hub 102 may receive sensor data from one or more network devices 104 and provide that information to UE 132 via base station 112 in the reverse order described above. For example, the UE 132 may send a command to check the temperature in the house. Upon receiving the command, the hub 102 communicates with a particular one of the network devices 104 to receive sensor data indicating the ambient temperature. The data can be passed to UE 132 in the manner described above. In addition, UE132 can change the temperature in the dwelling using different commands. In this situation, the command is relayed to hub 102 through WAN 120 and the cellular network operator so that it is sent to hub 102 using cellular communication link 110. In response to the command, hub 102 generates a command for a particular network device 104 and changes the ambient temperature accordingly.
A software application program running on hub 102 and UE 132 allows the user to read data from network equipment 104 (eg, read temperature from temperature-sensitive network equipment 104) and / or control network equipment (eg,). It is possible to raise the temperature). The device may be controlled directly from the hub 102 or from the UE 132 communicating with the hub.
FIG. 2 illustrates an embodiment of System 100 that may be suitable for in-house implementation. In the embodiment illustrated in FIG. 1, all network devices 104 are within communication range of hub 102 via their respective communication links 106. However, in the embodiment of FIG. 2, the effective coverage of the hub 102 does not have to provide coverage of the entire dwelling. In the embodiment of FIG. 2, one or more network devices 104 effectively function as nodes on a mesh network that receive commands in the form of encrypted data. The network device 104 decodes only the command intended for that particular device. For all other commands, network device 104 retransmits the encrypted data to other nearby network devices. That is, the network device 104 can be within the range of the hub 102 and can receive commands from it. If a command (eg, reading sensor data or performing an action) is intended for a particular network device 104, it decrypts the data and acts on the command. However, under other circumstances, the command from the hub 102 can be for a different network device 104. At that event, the network device 104 receives and retransmits the command to any other network device 104 within its range. Next, each network device 104 acts on the command if the command is intended for that particular device, and retransmits the command if the command is intended for a different network device. In this way, the command from the hub 102 can be propagated through the mesh network from one network device to another until the command is received by the intended network device 104.
Multiple devices 104 may receive the same command using the command retransmission process described above. However, through the encryption process, only commands intended for a particular device 104 can be decrypted by that particular device. All other commands received by that device 104 remain encrypted. Through this mesh network, UE132 works with software application programs to control all equipment. Even if the UE 132 is on one side of the house, it can effectively communicate with the device 104 throughout the house via the data sharing techniques described in more detail below. The mesh connection between devices effectively creates a tether that allows distant devices to still receive data intended for a particular device.
All communication between the hub 102 and the network device 104 can be encrypted using the Hypertext Transfer Protocol Secure (HTTPS). In addition, the hub 102 provides an encrypted secure Socket Layer (SSL) certificate for each device to provide a security layer. Only network equipment 104 with a proper SSL certificate can decrypt commands from hub 102. Some of the HTTPS data includes an address that identifies the intended destination network device 104. Each network device has an address and only decrypts commands from hub 102 intended for that particular network device. As mentioned above, if network device 104 receives a command (from hub 102 or another network device) that is not addressed to that particular network device, until the command is received by the intended network device 104. , It retransmits the encrypted command, thus propagating the command throughout the dwelling.
An example of data entries in the secure database 124 for television receivers (see Figure 1) is illustrated in Figure 8. Database entries include device identification, including IP address, MAC address, and device ID data entries, along with device type and name. In addition, the database may store private and public keys for encryption purposes. Finally, the database may include device controllable features such as on / off, channel selection, volume control, and so on. As mentioned above, the IP address and / or MAC address can be used to uniquely identify the device and command data sent by hub 102.
In this implementation, the network device 104 can only communicate with the hub 102 directly or through another network device. FIG. 2 illustrates multiple UE 132s that can accommodate different users' wireless communication devices (eg, smartphones) such as family members, roommates, and so on. In some cases, the UE 132 is within range of the hub 102 and can communicate directly with the hub 102 using the communication link 134 illustrated in FIG. In other situations, the UE 132 is outside the direct range of communication with the hub 102, but may be within the range of one or more network devices 104. In this situation, the UE 132 can communicate with the hub 102 via one or more network devices 104. Commands from UE 132 are relayed through one or more network devices 104 until the command is received by hub 102. Hub 102 responds to commands by generating its own commands destined for one or more network devices 104, thereby executing commands from UE 132. For example, the UE 132 may send a command to turn on all external lighting in the home. The command is propagated to hub 102 over the mesh network. The hub 102 then generates the commands needed to turn on the external lighting. Commands are sent from hub 102 to one or more network devices 104 that control external lighting. Each of the network devices 104 that control the external lighting can decode and execute the command.
Prior art IoT devices are typically connected to the Internet, either directly or via a WiFi router, making them vulnerable to attacks from the Internet. In contrast, the hub 102 acts effectively as a proxy to protect the network device 104 from Internet hacks. The network device 104 cannot be accessed by an external device other than the authenticated UE 132, thus providing a secure form of operation. As mentioned above, the UE 132 can access and control the system using the short-range communication link 134 (see Figure 1) to communicate directly with the hub 102. Alternatively, the UE 132 and the hub 102 via base station 112, either by communicating directly with the cellular network over a cellular communication link (not shown) or by accessing the cellular network using WAN 120. Can communicate.
Hub 102 includes at least a portion of a secure database 124 (see Figure 1) for all network equipment 104 in a particular environment, such as a residence. The key information for the device is stored in the hub 102 and is encrypted using, for example, AES-256 encryption. Other forms of encryption can also be satisfactorily used to protect the data in the secure database 124 within the hub. Hub 102 authenticates and verifies each user before granting access to network equipment 104. Only software applications running on hub 102 and UE 132 can decrypt any data contained within the secure database 124 within the hub. The software application in UE132 can receive an encrypted list of devices 104 from the hub 102. Using a blockchain implementation, the secure database 124 may be partially implemented within the hub 102. The portion of the secure database 124 within the hub 102 contains encrypted data for all devices controlled by the hub. In addition, a copy of that portion of the secure database is encrypted as a block in the blockchain database that contains the encrypted data of all hubs at various locations.
In addition, cellular communication with base station 112 is possible only via hub 102. Hub 102 also provides the sole access to WAN 120 through gateway 118, as described above. In one exemplary embodiment, the network device 104 communicates with the hub 102 using a short-range communication protocol such as IEEE 802.11, often referred to as WiFi. Other forms of short-range communication, such as Bluetooth®, ZigBee®, Z-Wave communication, etc., also have a wireless communication link 106 between the hub 102 and the network device 104 (see Figure 1). Can be used to form.
FIG. 2 illustrates a peer-to-peer mesh network in which each of the network devices 104 can function as a node on the network. FIG. 3 illustrates another exemplary implementation of System 100 that may be suitable for enterprise architecture. In situations where an enterprise may wish to provide network equipment 104 across large areas such as buildings, factories, buildings, campuses, etc., the installation can include multiple hubs 102 forming a peer-to-peer mesh network. In this embodiment, one of the hubs 102 may be designated as the master hub. Internet access is controlled via the master hub 102. Although the embodiment of FIG. 3 is described as a suitable implementation for a corporate architecture, one of ordinary skill in the art will appreciate that both of the different architectures of FIGS. 2-3 are useful in a residential or work environment. Let's do it.
Further, the system 100 of FIGS. 2 to 3 may be configured to operate with a plurality of UE 132s. Various users include spouses, roommates, family members, etc. in a residential environment, and employees, supervisors, managers, etc. authorized to access System 100 using their respective UE 132s in a corporate environment. possible. In one embodiment, the UE 132 may communicate with any hub 102 within range. In this embodiment, the hub 102 within the range of the UE 132 may respond to commands from the UE 132, such as reading sensor data or performing an action. In this embodiment, each hub 102 includes a database of connected users and connected network equipment 104. In a manner similar to that described above with respect to FIG. 2, the implementation of FIG. 3 allows the hub 102 to act on commands to network equipment 104 within the range of a particular hub. If the command from UE132 is intended for a network device 104 that is not within the range of a particular hub 102, the hub acts as a node in a peer-to-peer mesh network and passes the command to other hubs within the radio frequency range. .. In an exemplary embodiment, the hubs 102 communicate with each other via WiFi or other preferred form of short-range communication. The various encryption and protection techniques discussed herein (eg, WPA2, WPA3, HTTPS, etc.) are similarly applicable to the embodiments of FIG. If the network device 104 for which the command is intended is not within the wireless range of any particular hub 102, the hub acts as a node on the mesh network and commands all other hubs within the range. To send. Each hub 102 then passes the command until it is received by the network device 104 to which the command is directed. The network device 104 decrypts and executes the command.
In an alternative embodiment, only the master hub 102 may issue commands. In this embodiment, the UE 132 can communicate directly with the master hub 102 if it is within range of the master hub. If the UE 132 is in the range of a different hub 102 (ie, not the master hub), the hub that receives the command passes the command in the mesh network until the command is received by the master hub. In this embodiment, only the master hub 102 may include that portion of a secure database 124 (see Figure 1) for connected users and devices within a particular facility. As mentioned above, the secure database 124 may be encrypted using AES-256 encryption or other preferred form of encryption. When the master hub 102 receives a command from the UE 132 (either directly or via a relay hub), the master hub generates the command and propagates the command to other nearby hubs. The hub 102 in the mesh network relays the command until it is received by a hub within the range of the intended network device 104. The hub sends a command to network device 104, which decrypts and executes the command. In an exemplary embodiment, each hub 102, which is a node in the mesh network, sends command data. The command is received by another nearby hub 102 that is within range of the sending hub. The command is also received by the network device 104. However, as described above with respect to FIG. 2, the network device 104 acts only on the command intended for that particular network device or plurality of network devices. Therefore, in the above embodiment, it is not necessary to define the network topology so that all the network devices 104 are mapped to the specific hub 102. Instead, hub 102 simply sends the received command until the command has been propagated throughout system 100. At some point during its propagation, Coman
Therefore, the system 100 can be implemented using a peer-to-peer network with multiple network devices 104 that act as nodes on the mesh network (see Figure 2), or multiple that act as nodes on the mesh network. It can be implemented as a peer-to-peer network using hub 102 (see Figure 3). Those skilled in the art will appreciate that hybrid versions of the implementations in Figures 2-3 are also possible if the nodes on the mesh network include multiple hubs 102 and multiple network devices 104.
FIG. 4 is a functional block diagram of an exemplary network device 104. Network equipment 104 includes a central processing unit (CPU) 150 and memory 152. In general, the CPU 150 uses the data and instructions stored in memory 152 to execute instructions. The CPU 150 can be implemented as a conventional processor, microcontroller, application specific integrated circuit (ASIC), and so on. Similarly, memory 152 may include random access memory, read-only memory, flash memory, and the like. Those skilled in the art will appreciate that the CPU 150 and memory 152 can be integrated into a single device. Network equipment 104 is not limited by the particular hardware used to implement CPU 150 and memory 152.
The network device 104 also includes a short range transceiver 154 and an antenna 156. As mentioned above, the short range transceiver 154 can be implemented as a WiFi transceiver or other suitable short range transceiver. The short-range transceiver 154 is used to communicate with one or more hubs 102 or other network equipment 104 in a peer-to-peer mesh network.
The network device 104 also includes a controller 158 that controls the operation of the network device. The controller 158 can typically be implemented as a series of instructions stored in memory 152 and executed by the CPU 150. However, the controller 158 is illustrated as a separate block in FIG. 4 because it performs a separate function.
FIG. 4 also illustrates the actuator 160 and the sensor 162. Those skilled in the art will appreciate that FIG. 4 illustrates a general purpose network device 104 capable of performing one or more functions. Some network equipment 104 may include one or both of actuator 160 and sensor 162. For example, a thermostat in a dwelling may include a sensor 162 to read the temperature, provide the temperature data to the user, and display the temperature data on the UE 132 (see Figure 1), and the temperature in response to a command from the user. Actuator 160 may be included for control. Similarly, a security camera may include a sensor 162 in the form of a video camera element, while the actuator 160 may be an electric element to allow directional control of the camera. The other network device 104 may include only one of the actuator 160 or the sensor 162. For example, a smoke detector may include only the sensor 162, while an optical controller may include only the actuator 160. Those skilled in the art will appreciate that network equipment 104 may include multiple actuators 160 and / or multiple sensors 162. In addition, the network device 104, such as WiFi, Bluetooth®, etc., allows the actuator 160 and / or the sensor 162 to be wirelessly controlled via wireless commands from the network device 104. It may include a wireless communication device.
The various components within the network device 104 are connected to each other via the bus system 164. The bus system 164 may include an address bus, a data bus, a control bus, a power bus, and the like. However, these various buses are illustrated in FIG. 4 as a bus system 164.
The network device 104 uses a conventional power source (not shown). For example, the network device 104 may be battery powered or plugged into a wall outlet. Alternatively, the network equipment 104 may be powered by a low voltage distribution system, which may be convenient for implementation within the enterprise. These conventional forms of power supply are within the knowledge of those skilled in the art.
FIG. 5 is a functional block diagram of an exemplary embodiment of the hub 102. Hub 102 includes CPU 170 and memory 172. In general, the CPU 170 uses the data and instructions stored in memory 172 to execute instructions. The CPU 170 can be implemented as a conventional microprocessor, microcontroller, ASIC, or the like. Similarly, memory 172 may include random access memory, read-only memory, flash memory, and the like. As discussed above for network equipment 104, the CPU 170 and memory 172 can be integrated into a single device. Hub 102 is not limited by the particular hardware used to implement CPU 170 and memory 172.
Hub 102 also includes a cellular transceiver 174 and associated antenna 176. Those skilled in the art will appreciate that the specific form of the cellular transceiver 174 will depend on the particular cellular network operator. As mentioned above, the cellular transceiver 174 can be implemented using any conventional communication protocol such as CDMA, GSM®, etc. In addition, cellular transceivers can be implemented using technologies such as 4G, LTE, 5G and more.
Hub 102 also includes a short range transceiver 178 and associated antenna 180. The cellular antenna 176 and the short range antenna 180 may be implemented as a single antenna. As mentioned above, the short range transceiver 178 can be implemented as a WiFi transceiver or other suitable form of short range communication.
Hub 102 also includes a secure database 182. As mentioned above, in various implementations, the secure database 182 can be part of the secure database 124 (see Figure 1) and can contain information about all equipment controlled by the hub. The information stored in the secure database 182 can be encrypted using AES-256 encryption or other suitable form of encryption. In addition, as described in more detail below, the secure database 182 can be implemented as part of a blockchain stored locally within hub 102. Alternatively, blockchain secure databases may be stored in a centralized or decentralized manner for enterprise implementations. In yet another implementation, blockchain data storage may be distributed across multiple machines, using, for example, a cloud computing network. Details of blockchain storage are provided below.
The hub 102 also includes a controller 184 that controls the operation of the hub 102. Those skilled in the art will appreciate that the controller 184 can typically be implemented as a series of instructions stored in memory 172 and executed by the CPU 170. Nevertheless, controller 184 is illustrated as a separate block in the functional block diagram of FIG. 5 because it performs a separate function. Controller 184 may control access to secure database 182 and may also control the operation of cellular transceiver 174 and short range transceiver 178. The controller 184 is responsible for authenticating the user and generating commands that are transmitted to the network device 104 via the short-range transceiver 178 to receive data (eg, sensor data) from the network device. Controller 184 may also control access to cellular transceiver 174, thereby controlling access to WAN 120 (see Figure 1). As mentioned above, the network device 104 does not have access to the Internet, which protects it from the typical attacks that IoT devices are currently experiencing.
Hub 102 also includes a keyboard / display 186. The keyboard and display may be implemented separately, but in an exemplary embodiment, the display is a touch-sensitive display that can also be used to implement the keyboard. The keyboard / display 186 can be used to generate commands for network equipment 104 as described above. The display can be used to list the network equipment 104 and allow the user to select commands for the network equipment. As mentioned above, the application software program running on UE 132 or hub 102 can be used to control network equipment 104. The command from UE132 is sent to hub 102 as described above.
The various components within the hub 102 are connected to each other via the bus system 188. The bus system 188 may include an address bus, a data bus, a control bus, a power bus, and the like. However, these various buses are illustrated in FIG. 5 as the bus system 188.
Similar to the implementation illustrated in Figure 2, all communication between hub 102, network equipment 104, and UE 132 can be encrypted using HTTPS. In addition, the master hub can generate an encrypted SSL certificate for each device, as described above with respect to FIG. In addition, the IEEE 802.11 standard includes provisions for WiFi Protected Access 2 (WPA2) protection for additional security in communication between hub 102 and network equipment 104. An improved version of WiFi Protection (WPA3) is expected to replace WPA2 in the near future and can be incorporated into System 100.
Hub 102 may also include signal enhancement capabilities for both cellular transceiver 174 and short range transceiver 178. If the facility is located in an area with weak cellular coverage, hub 102 boosts the amplification of the signal received from base station 112 (see Figure 1), boosts transmission power, and more effectively transmits data to the base station. Can be done. Controller 184 may be configured to measure the signal strength of the received signal to determine if amplification and transmission power increase is required. In the outer edge region of cellular coverage, this technique can improve the overall operation of System 100. When operating as a picocell, hub 102 effectively operates as a base station in a manner similar to base station 112. However, unlike the base station 112, which uses the backhaul 114 to communicate with the core network 116, the hub 102 wirelessly communicates with the base station 112. However, the hub 102 may broadcast its own channel, thereby effectively functioning as a base station. Based on the type of cellular system, the channel may include, for example, a pilot signal or other cellular identifier. Cellular operation is known in the art and does not need to be described in more detail herein.
Similarly, the hub 102 can provide a wider range for the short-range transceiver 178. In this aspect, controller 184 measures the signal strength of the signal received from either network equipment 104 or UE 132, and system 100 benefits from increased amplification of the received signal and increased transmission power in the short-range transceiver 178. You can decide whether to get it. If necessary, controller 184 can enhance the amplification of the receiver of the short-range transceiver 178 to increase the transmit power on the transmit side of the short-range transceiver. This dynamic capability allows the hub 102 to effectively improve coverage, capacity, performance, and efficiency for both cellular and short range radios. Intelligent control provided by controller 184 measures signal strength and augments the signal as needed.
Access to hub 102 by UE132 is tightly controlled. As mentioned above, the software application program is located on both hub 102 and UE 132. The software application locally controls the network device 104 via the hub 102, as described above. For initial setup, a special access code is randomly generated by hub 102 to identify and authenticate UE 132. Subsequent operations and device management are performed by software application programs on hub 102 and UE 132. Subsequent authentication of UE132 uses a two-step verification procedure. FIG. 6A illustrates the screen display of UE 132 with login selection. The user provides a username and password as part of the login procedure. Upon receiving the username and password, the hub may send a verification passcode to UE132 that must be entered within a specified time period. If the user forgets the password, the user must start over and re-register the hub 102 and all network devices 104.
Hub 102 records all login attempts, successful or unsuccessful. Figure 6B illustrates a display of UE 132 enumerating a series of events, including successful logins and blocked login attempts.
System 100 uses two-factor authentication techniques. When the system 100 is initialized, the user must manually register the UE 132 and each of the plurality of network devices 104 with the hub 102. Data entries associated with UE 132 and each network device 104 are encrypted and stored in a secure database 182 (see Figure 5) within hub 102. As mentioned earlier, hub 102 periodically communicates with secure database 124 as part of the blockchain stored on one or more servers 170 in cloud 172 (see Figure 9). It keeps the hub 102 in sync with the blockchain on the cloud 172.
When the initial installation is complete, the system allows the addition of new users or network equipment. The addition of the new UE 132 is illustrated in Figure 7. In step 1 of Figure 7, an unauthenticated UE requests access. In step 2, hub 102 generates an authentication token (eg, device password and / or identification code) for transmission to a secure database 124 implemented as a blockchain. Hub 102 also sends a notification message to all previously authenticated UEs 132 to provide notifications and request approval for the addition of new UEs. In step 3, the blockchain generates token validation if approved by all previously authenticated UE 132s, and in step 4, hub 102 accesses the new UE if all tokens are authenticated. Allow. Secure database 182 (see Figure 5) and secure database 124 (see Figure 9) are updated to create new data entries for the newly authenticated UE.
In subsequent authentication, when UE 132 falls within the range of hub 102, the hub recognizes the UE because its data already exists in database 182. This is the first authentication factor. In the second authentication factor, hub 102 sends a verification message to UE132. This may be in the form of a passcode that the user must enter within a predetermined timeout period for other known authentication steps.
Similarly, new network equipment 104 may be added to the system. In one embodiment, the UE can manually add the network device 104 by clicking the "Add Device" command in the software application program. Alternatively, hub 102 automatically detects the presence of new unauthenticated network equipment and initiates the authentication process. As mentioned above, hub 102 sends a notification message to the previously authenticated UE 132 to request authorization to add new network equipment. If authenticated, the system adds new network equipment using the token verification process described for UE authentication in Figure 7 above. Those skilled in the art should require approval of all certified UEs to add new UEs or new equipment if they involve a large number of certified UEs that may be present in an enterprise implementation. You will understand that there are times when it is not. Therefore, the system can provide some designation of the authenticated UE 132 to act as a control for authentication purposes. If the new network device is designated as a certified ioXt compliant device as part of the automatic authentication process, hub 102 will remove the UE notification process described above and authenticate the new network device without human intervention. Can be done. As mentioned above, System 100 creates data entries in database 182 (see Figure 5) or database 124 (see Figure 9) for all newly authenticated UEs or network devices.
When an unauthorized individual (ie, an intruder) attempts to download a software application and access System 100, the hub 102 requires the credentials (ie username and password) as described above. Since the intruder UE is not authenticated, the notification message to the authenticated UE 132 allows any user to deny access.
If the username and password are compromised, hub 102 uses an additional layer of security provided by the blockchain, as illustrated in Figure 7. The intruder UE does not exist in any authentication database and will be blocked from access to System 100.
System 100 can automatically detect the installation of new components such as hub 102 or new network equipment 104 in the manner described above. If hub 102 is replaced, a new hub resynchronization process via the master blockchain database will be implemented for the user. Figure 9 illustrates an exemplary architecture of a blockchain database. As mentioned above, hub 102 uses base station 112 (see Figure 1), core network 116, and gateway 118 to communicate with WAN 120 through the cellular network operator. FIG. 9 illustrates a communication link 130 between the WAN 120 and the secure database 124. As illustrated in FIG. 9, the blockchain database contains a separate block for each user and contains all the data associated with that user. As discussed earlier, the information can include a list of one or more hubs that a user can access, as well as a list of all network devices 104 that can be accessed by a particular user. As illustrated in FIG. 9, each block contains data associated with each user. In this embodiment, the secure database 124 can be implemented and distributed across one or more servers 170 that can be part of the cloud computing environment 172. As will be appreciated by those skilled in the art, blockchain databases are typically distributed across a large number of servers 170, each containing the same copy of the encrypted database.
As mentioned above for hub 102, UE 132 can access the centralized secure database 124 through authorized networks such as base station 112, core network 116, and gateway 118. Alternatively, the UE 132 can access the blockchain version of the secure database 124 using an unauthorized network, such as a WiFi connection to the WAN 120.
Hub 102 can discover new compatible network equipment 104 through network scans. Hub 102 stores device information encrypted for security and authentication in a local secure database 182 (see Figure 5). As mentioned above, the certification process can be controlled manually by requesting approval of any new component to system 100 by the certified UE 132, or if the new device is certified as ioXt compliant. Completes automatically without human intervention. After completing the authentication and blockchain-based verification process, hub 102 initiates the pairing process with the new network equipment 104. The encrypted secure database 182 in hub 102 is a secure database so that the blockchain database stored in server 170 has a complete and accurate list of all network devices 104 attached to each hub 102. It is regularly shared with the remote blockchain in 124 (see Figure 9).
The aforementioned embodiments show different components that are contained or connected within other different components. It should be understood that the architecture so presented is merely exemplary and, in fact, many other architectures that achieve the same functionality can be implemented. In a conceptual sense, any configuration of components to achieve the same functionality is effectively "associated" to achieve the desired functionality. Therefore, any two components of the specification combined to achieve a particular functionality "associate" with each other to achieve the desired functionality, regardless of architecture or intermediate components. It can be regarded as "being done". Similarly, any two components so associated are also considered to be "operably connected" or "operably connected" to each other to achieve the desired functionality. Can be done.
Although specific embodiments of the present invention have been shown and described, changes and modifications can be made based on the teachings of the present invention without departing from the present invention and its broader aspects, and, therefore, attachments. It will be apparent to those skilled in the art that the claims cover the true spirit of the invention and all such modifications and modifications within the scope of the invention. Further, it should be understood that the present invention is defined only by the appended claims. In general, the terms used herein, and in particular in the appended claims (eg, the body of the appended claims), are generally "open" terms (eg, "including"). Should be interpreted as "including, but not limited to", the term "having" should be interpreted as "at least having", and the term "includes" is Those skilled in the art will appreciate that it is intended as "including, but not limited to," which should be interpreted. If a particular number of introduced claims are intended to be detailed, such intent is explicitly detailed in the claims, and in the absence of such detail, such intent is Those skilled in the art will further understand that it does not exist. For example, to aid understanding, the appended claims below may include the use of the introductory phrases "at least one" and "one or more" to introduce the details of the claim. However, the use of such a phrase specifies that the introduction of a claim detail by the indefinite article "is (a)" or "is (an)" includes a detail of the claim so introduced. Should not be construed as suggesting limiting the claims to an invention containing only one such detail, and the same claims are "one or more" or "at least one" and "(a). Indefinite articles such as ")" or "is (an)" (eg, "is (a)" and / or "is (an)" are usually interpreted to mean "at least one" or "one or more" Rube The same is true for the use of definite articles used to introduce the details of the claims, even if they include the introductory phrase. Further, even though a particular number of introductory claims details are explicitly stated, one of ordinary skill in the art will mean such details typically at least the number stated (eg, for example. You will recognize that a bare statement such as "two" without any other modifier should usually be construed as (at least two, or two or more).
Therefore, the present invention is not limited to the scope of the appended claims.
10 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10
Every citation, both waysCites: the store holds 3 of 4
| Document | Relation | Office |
|---|---|---|
| US20160180100A1 | Cites | United States of America |
| JP2016532323A | Cites | Japan |
| JP2008040634A | Cites | Japan |
| 東角 芳樹 ほか,コンソーシアムチェーンにおける証明書管理に関する一考察,2017年 暗号と情報セキュリティシンポジウム(SCIS2017)予稿集 [USB],日本,2017年 暗号と情報セキュリティシンポジウム実行,2017年 1月24日,1F2-3,p. 1-4 | Non-patent | – |
142 members in 15 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 15948913 | United States of America | – | |
| 201815948913 | United States of America | A | |
| 201815948913 | United States of America | A | |
| 15948913 | – | – | – |
| US201815948913 | – | – | – |
Members142
| Document | Office | Kind | |
|---|---|---|---|
| US2010227554A1 | United States of America | A1 | |
| US2010227610A1 | United States of America | A1 | |
| WO2010101940A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2010101940A3 | World Intellectual Property Organization (WIPO) | A3 | |
| US2011076948A1 | United States of America | A1 | |
| US7970351B2 | United States of America | B2 | |
| US2011201275A1 | United States of America | A1 | |
| SG173903A1 | Singapore | A1 | |
| US2011244875A1 | United States of America | A1 | |
| US2011246611A1 | United States of America | A1 | |
| KR20110138361A | Republic of Korea | A | |
| EP2404478A2 | European Patent Office (EPO) | A2 | |
| CN102428748A | China | A | |
| US2012129607A1 | United States of America | A1 | |
| US8190119B2 | United States of America | B2 | |
| US2012135711A1 | United States of America | A1 | |
| WO2012074929A2 | World Intellectual Property Organization (WIPO) | A2 | |
| US2012149463A1 | United States of America | A1 | |
| EP2472459A2 | European Patent Office (EPO) | A2 | |
| EP2472460A2 | European Patent Office (EPO) | A2 | |
| US2012202185A1 | United States of America | A1 | |
| JP2012520014A | Japan | A | |
| WO2012074929A3 | World Intellectual Property Organization (WIPO) | A3 | |
| US8295803B2 | United States of America | B2 | |
| WO2012149031A2 | World Intellectual Property Organization (WIPO) | A2 | |
| EP2404478A4 | European Patent Office (EPO) | A4 | |
| EP2472459A3 | European Patent Office (EPO) | A3 | |
| EP2472460A3 | European Patent Office (EPO) | A3 | |
| US2012329429A1 | United States of America | A1 | |
| US2012329555A1 | United States of America | A1 | |
| WO2012149031A3 | World Intellectual Property Organization (WIPO) | A3 | |
| US2013203036A1 | United States of America | A1 | |
| US2013205341A1 | United States of America | A1 | |
| WO2013116756A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2013116761A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2013123318A1 | World Intellectual Property Organization (WIPO) | A1 | |
| US2013231088A1 | United States of America | A1 | |
| US2013305297A1 | United States of America | A1 | |
| US2014006161A1 | United States of America | A1 | |
| EP2706763A1 | European Patent Office (EPO) | A1 | |
| US2014108149A1 | United States of America | A1 | |
| US2014157325A1 | United States of America | A1 | |
| EP2747465A1 | European Patent Office (EPO) | A1 | |
| US8774753B2 | United States of America | B2 | |
| US2014248959A1 | United States of America | A1 | |
| WO2014152618A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2014152641A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2014152658A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2014152677A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2014152695A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2014152658A3 | World Intellectual Property Organization (WIPO) | A3 | |
| US2014344847A1 | United States of America | A1 | |
| WO2014152641A3 | World Intellectual Property Organization (WIPO) | A3 | |
| WO2014152618A3 | World Intellectual Property Organization (WIPO) | A3 | |
| EP2810465A1 | European Patent Office (EPO) | A1 | |
| WO2014152677A3 | World Intellectual Property Organization (WIPO) | A3 | |
| US8995923B2 | United States of America | B2 | |
| US2015106855A1 | United States of America | A1 | |
| US9055439B2 | United States of America | B2 | |
| US9064374B2 | United States of America | B2 | |
| US9077564B2 | United States of America | B2 | |
| US2015244876A1 | United States of America | A1 | |
| US2015245209A1 | United States of America | A1 | |
| US2015289103A1 | United States of America | A1 | |
| EP2810465A4 | European Patent Office (EPO) | A4 | |
| US9179296B2 | United States of America | B2 | |
| US2016014455A1 | United States of America | A1 | |
| US9245408B2 | United States of America | B2 | |
| US9271054B2 | United States of America | B2 | |
| BRPI1009289A2 | Brazil | A2 | |
| US2016127899A1 | United States of America | A1 | |
| US2016173912A1 | United States of America | A1 | |
| US2016173913A1 | United States of America | A1 | |
| US2016173938A1 | United States of America | A1 | |
| US2016173956A1 | United States of America | A1 | |
| US9439071B2 | United States of America | B2 | |
| US9485656B2 | United States of America | B2 | |
| CA2985356A1 | Canada | A1 | |
| WO2016179188A1 | World Intellectual Property Organization (WIPO) | A1 | |
| US2016337849A9 | United States of America | A9 | |
| US9510148B2 | United States of America | B2 | |
| US2016366285A1 | United States of America | A1 | |
| US2017014716A1 | United States of America | A1 | |
| US2017046742A1 | United States of America | A1 | |
| US9586139B2 | United States of America | B2 | |
| US9609513B2 | United States of America | B2 | |
| US9662571B1 | United States of America | B1 | |
| US9675883B2 | United States of America | B2 | |
| US2017165568A1 | United States of America | A1 | |
| EP3185601A1 | European Patent Office (EPO) | A1 | |
| US9715833B2 | United States of America | B2 | |
| US9749861B2 | United States of America | B2 | |
| US2017249690A1 | United States of America | A1 | |
| US2017259172A1 | United States of America | A1 | |
| US9787855B2 | United States of America | B2 | |
| US9855500B2 | United States of America | B2 | |
| US2018034976A1 | United States of America | A1 | |
| EP3292673A1 | European Patent Office (EPO) | A1 | |
| US9986268B2 | United States of America | B2 | |
| US10009638B2 | United States of America | B2 |
8 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Notification of appointment of power of attorneyJAPANESE INTERMEDIATE CODE: R3D03RD03 | RD03 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Report on retrievalJAPANESE INTERMEDIATE CODE: A971007A977 | A977 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 6717468
- Publication, DOCDB
- 6717468
- Publication, EPODOC
- JP6717468B
- Application
- 73373
- Application, DOCDB
- 2019073373
- Application, EPODOC
- JP20190073373
Titles2
- Japanese
- セキュアな機器動作のためのシステムおよび方法
- English
- Systems and methods for secure device operation
Classification
- CPC, 45
- H04L63/0876
- H04L63/10
- H04N21/43637
- H04W12/03
- H04W4/021
- H04L12/2803
- H04L63/0428
- H04N7/18
- H04L9/0631
- H04L63/0823
- H04L63/083
- G08B17/125
- G08C17/02
- H04W12/08
- H04W12/06
- H04L9/3239
- H04L2209/805
- H04L9/0894
- H04L9/0822
- H04L9/3226
- H04L9/3228
- H04L9/50
- H04W4/80
- H04W84/18
- H04N21/632
- H04W76/45
- H04N21/6131
- H04W76/11
- H04N21/41407
- H04N21/25816
- H04N21/2541
- H04W8/205
- H04N21/2223
- H04W8/186
- H04N21/4367
- H04W12/12
- H04N21/2187
- H04W8/18
- H04N21/4753
- H04W60/00
- H04W4/70
- H04W88/04
- H04W12/30
- H04W12/069
- H04W52/241
- IPC, 5
- H04L9 10
- H04L9 32
- G06F21 44
- H04W12 10
- H04W52 24
