US20110258454A1

Cross-domain identity management for a whitelist-based online secure device provisioning framework

Claim Score by NHIP

Read claim 9, the broadest

Abstract

A method for managing identifiers associated with network-enabled devices and used in an identity data system provisioning the network-enabled devices with identity data includes receiving a first set data that includes a previously assigned identifier for one or more of the network-enabled devices that are authorized to be provisioned with new identity data. If identity data is currently installed on the one or more network-enabled devices, each of the previously assigned identifiers in the first set of data is associated with a corresponding identifier linked to the identity data currently installed on the one or more network-enabled devices to establish a second set of data. New identity data is bound to each of the one or more network-enabled devices by assigning a new identifier linked with the new identity data to each of the one or more network-enabled devices to establish a whitelist. The whitelist specifies, for each of the one or more network-enabled devices, its previously assigned identifier, its corresponding identifier and its new identifier that is linked with the new identity data.

US20110258454A1, drawing sheet 1
Sheet 1 of 14

Term

6.1 yearsto projected expiry

Projected expiry 4 November 2032, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

27 claims: 4 independent, 23 dependent

  1. 1
    A method for managing identifiers associated with network-enabled devices and used in an identity data system provisioning the network-enabled devices with identity data, comprising:receiving a first set of data that includes a previously assigned identifier for one or more of the network-enabled devices that are authorized to be provisioned with new identity data;if identity data currently is installed on the one or more network-enabled devices, associating each of the previously assigned identifiers in the first set of data with a corresponding identifier linked to the identity data currently installed on the one or more network-enabled devices to establish a second set of data;and binding new identity data to each of the one or more network-enabled devices by assigning a new identifier linked with the new identity data to each of the one or more network-enabled devices to establish a whitelist specifying, for each of the one or more network-enabled devices, its previously assigned identifier, its corresponding identifier and its new identifier that is linked with the new identity data.
  2. 9
    Broadest claimClaim Score 48, average(NHIP)A method for updating network-enabled devices with new identity data, each of said network-enabled devices having at least three types of identifiers associated therewith, comprising:receiving over a communications network a request for new identity data for a plurality of network-enabled devices, each of said requests including an identifier of the third- type associated with the network-enabled devices;obtaining an identifier of the first type associated with the network-enabled devices, said first identifier type being an identifier that is included in identity data with which the network-enabled device is currently provisioned, wherein the network-enabled devices have previously been provisioned with identifiers of the first type by respectively assigning the identifiers of the first type to network-enabled devices that are already identified by identifiers of the second type;receiving new identity data assigned with new identifiers of the first type, wherein each of the new identifiers is matched with a corresponding identifier of the third type;and delivering over the communications network the new identity data assigned with the new identifiers to respective ones of the network-enabled devices in accordance with their respective third identifiers.
  3. 21
    At least one computer-readable medium encoded with instructions which, when executed by a processor, performs a method for updating network-enabled devices with new identity data, each of said network-enabled devices having at least two types of identifiers associated therewith, comprising:receiving over a communications network a request for new identity data for a plurality of network-enabled devices, each of said requests including a identifier of the second type associated with the network-enabled devices;obtaining an identifier of the first type associated with the network-enabled devices, said first identifier type being an identifier that is included in identity data with which the network-enabled device is currently provisioned, wherein the network-enabled devices have previously been provisioned with identifiers of the first type by respectively assigning the identifiers of the first type to network-enabled devices that are already identified by identifiers of the second type;receiving new identity data assigned with new identifiers of the first type, wherein each of the new identifiers is matched with a corresponding identifier of the second type;and delivering over the communications network the new identity data assigned with the new identifiers to respective ones of the network-enabled devices in accordance with their respective second identifiers.
  4. 25
    A server for use in an identity data system provisioning network-enabled devices with identity data, comprising:a whitelist parser and correlator configured to (i) receive a first set of data specifying one or more of the network-enabled devices that are authorized to be provisioned with new identity data, wherein the one or more network-enabled devices are identified in the first set of data by identifiers of a third type, (ii) to access one or more databases to retrieve identifiers of a first and second type each of which also identify the one or more network-enabled devices, said identifiers of the first type being linked to identity data currently provisioned in the network- enabled devices and (iii) correlate the identifiers of the third type with corresponding identifiers of the first and second type to establish a whitelist that identifies the network-enabled devices that are authorized to be provisioned by their respective identifiers of the first type and at least one additional identifier to be linked to new identity data to be provisioned in the one or more network-enabled devices;and a configuration manager to specify a whitelist format, assign different types of identity data to the network-enabled devices and associate the different types of identity data with network operators who deploy the network-enabled devices.