Secure provisioning and management of device

The secure provisioning system addresses vulnerabilities in digital asset provisioning by using authenticated channels and cryptographic protocols to ensure only authorized devices receive and install assets, enhancing security and reliability.

JP2025157390APending Publication Date: 2025-10-15INTEGRITY SECURITY SERVICES LLC
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2025119379
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2017-04-20
Filing Date
2025-07-16
Publication Date
2025-10-15

AI Technical Summary

Technical Problem

Existing systems for provisioning digital assets in computerized devices are vulnerable to unauthorized modification, tampering, and improper installation, leading to potential malfunctions and security breaches.

Method used

A secure provisioning system comprising a provisioning controller, digital asset management system, and distribution devices, utilizing secure communication channels and cryptographic protocols to authenticate and manage the provisioning process, ensuring only authorized devices receive and install digital assets.

Benefits of technology

Ensures secure, reliable, and auditable provisioning of digital assets, preventing unauthorized access and ensuring devices operate correctly and securely.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025157390000001_ABST
    Figure 2025157390000001_ABST
Patent Text Reader

Abstract

To provide systems for secure provisioning and management of computerized devices.SOLUTION: A system 100 may include: a distributor appliance that is communicatively connected to a computerized device 106A, and that is operable to receive a digital asset and to load the digital asset into the computerized device; a digital asset management system that is connected via a first secure communication channel to the distributor appliance, and that is operable to generate and conditionally transmit the digital asset to the distributor appliance; and a provisioning controller that is connected via a second secure communication channel to the distributor appliance and is connected via a third secure communication channel to the digital asset management system, and that is operable to direct the digital asset management system to transmit the digital asset to the distributor appliance. The computerized device is not fully functional before the digital asset is loaded into it.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] (CROSS-REFERENCE TO RELATED APPLICATIONS) This application claims the benefit of U.S. Provisional Patent Application No. 62 / 421,878, filed November 14, 2016, U.S. Provisional Patent Application No. 62 / 421,852, filed November 14, 2016, and U.S. Provisional Patent Application No. 62 / 487,909, filed April 20, 2017, all of which are incorporated by reference herein in their entirety.

[0002] The present invention relates to a system, device, and method for securely provisioning a computerized device. [Background technology]

[0003] As computers become increasingly miniaturized and commoditized, manufacturers are producing an ever-increasing variety of devices that contain one or more embedded computers or processors. The computer within a computerized device can, among other things, control the device's operation; collect, store, and share data; communicate with other computers and other computerized devices; and update its own software.

[0004] The Internet of Things (IoT) is a network of computerized physical devices that contain embedded processors, electronics, software, data, sensors, actuators, and / or network connectivity, enabling these devices to connect and exchange data over digital networks, including the Internet, cellular networks, and other wireless networks. Typically, each "thing" is uniquely identifiable through its embedded computing system and can interoperate within the existing Internet infrastructure.

[0005] "Things" in the IoT sense can refer to a variety of computerized devices such as home appliances, enterprise devices used in business and corporate environments, manufacturing machinery, agricultural equipment, energy-consuming devices in homes and buildings (such as switches, outlets, light bulbs, and televisions), medical and healthcare equipment, infrastructure management equipment, robots, drones, and transportation equipment and vehicles, among others.

[0006] For example, most, if not all, modern vehicles (e.g., cars, trucks, airplanes, trains, ships, etc.) contain several embedded processors or embedded computers within their subsystems and are computer-controlled in at least some aspects. Similarly, an increasing number of modern transportation infrastructure devices (e.g., traffic lights, traffic cameras, traffic sensors, bridge monitors, bridge control systems, etc.) contain at least one, and often many, embedded processors or embedded computer systems and are computer-controlled in at least some aspects. These computer-controlled elements of transportation networks typically communicate with each other to exchange various types of information, and for safe, correct, efficient, and reliable operation, they can react, respond, modify their operation, or rely on information received / sent between other vehicles in vehicle-to-vehicle (V2V, C2C, also known as vehicle-to-vehicle) communication and / or between vehicle-to-infrastructure (V2I, C2I, also known as vehicle-to-infrastructure) communication.

[0007] The computers in computerized equipment operate in accordance with their software and / or firmware and data. To ensure safe and proper operation, Because computerized devices must be properly initialized and updated with the appropriate software, firmware, executable instructions, digital certificates (e.g., public key certificates), and cryptographic keys (collectively referred to below as "digital assets" or "software") as intended by the manufacturer, the IoT will consist only of devices running authorized, working software and data. However, problems arise when unauthorized individuals or organizations (e.g., hackers) replace or modify software within computerized devices. Problems also arise when outdated, untested, unauthorized, and / or software with known bugs is installed within computerized devices.

[0008] It is therefore desirable to provide improved systems, methods, and techniques for securely provisioning digital assets within computerized devices so as to prevent the computerized devices from operating with error-sensitive, misfunctioning, untested, maliciously modified, or otherwise undesirable software and data. Summary of the Invention

[0009] Disclosed herein are systems, methods, and device systems for securely provisioning one or more computerized devices. In various embodiments, the system includes: a first distribution device communicatively connected to the computerized device and operable to receive digital assets and load the digital assets into the computerized device; a digital asset management system connected to the distribution device via a first secure communication channel and operable to generate and conditionally transmit digital assets to the distribution device; and a provisioning controller connected to the distribution device via a second secure communication channel and to the digital asset management system via a third secure communication channel and operable to instruct the digital asset management system to transmit the digital assets to the distribution device. Due to the absence of digital assets, the computerized device may be non-functional or only partially functional before the digital assets are loaded onto the computerized device. The digital assets may be at least one of a digital certificate, a cryptographic key, and executable software.

[0010] In various embodiments, the system further includes a second distribution device connected to the digital asset management system via a fourth secure communication channel, communicatively connected to the computerized device after the first distribution device is disconnected, operable to receive the second digital asset and load the second digital asset into the computerized device, and the provisioning controller is further operable to instruct the digital asset management system to transmit the second digital asset to the distribution device, wherein the computerized device can become fully functional after the second digital asset is loaded onto the computerized device.

[0011] In various embodiments, a digital asset management system includes one or more virtual machines running a registration authority application and communicatively connected to one or more computation engines that perform cryptographic calculations required by the registration authority application, one or more virtual machines running a registration certificate authority application and communicatively connected to one or more computation engines that perform cryptographic calculations required by the registration certificate authority application, one or more virtual machines running a pseudonym certificate authority application and communicatively connected to one or more computation engines that perform cryptographic calculations required by the pseudonym certificate authority application, one or more virtual machines running a first coordination station application and communicatively connected to one or more computation engines that perform cryptographic calculations required by the first coordination station application, and a second coordination station application. and one or more virtual machines executing the second cooperating station application and communicatively connected to one or more computation engines performing cryptographic computations required by the second cooperating station application.

[0012] In other embodiments, the digital asset management system may further include a database operably connected to one or more virtual machines running a registration authority application, one or more virtual machines running a registration certificate authority, one or more virtual machines running a pseudonym certificate authority application, one or more virtual machines running a first coordination authority application, and one or more virtual machines running a second coordination authority application.

[0013] In still other embodiments, the system may further include a portal operably connected to the provisioning controller to authenticate manufacturers of computerized equipment and enable the manufacturers to manage the provisioning of the computerized equipment, and / or a portal operably connected to the provisioning controller to authenticate installers of computerized equipment and enable the installers to manage the provisioning of the computerized equipment, and / or a portal operably connected to the provisioning controller to authenticate regulators of computerized equipment and enable the regulators to manage the provisioning of the computerized equipment.

[0014] In yet other embodiments, the provisioning controller may be further operable to send the digital asset (e.g., an executable software image) to the distribution equipment for loading onto the computerized device. In yet other embodiments, the provisioning controller may be further operable to create and maintain a log associated with the digital device that stores information regarding provisioning activity of the digital device, and the distribution equipment may be further operable to send information regarding provisioning activity associated with the digital device to the provisioning controller for storage in the log.

[0015] In yet other embodiments, the provisioning controller may be further operable to authenticate the digital device before instructing the digital asset management system to transmit the digital asset. [Brief explanation of the drawings]

[0016] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments of the invention and, together with the description, serve to explain the principles of the invention.

[0017] [Figure 1]1 is a block diagram illustrating an example of a system for secure provisioning, consistent with embodiments of the present invention.

[0018] [Figure 2] FIG. 1 is a swimlane diagram illustrating an example of a process for securely provisioning a computerized device consistent with embodiments of the present invention.

[0019] [Figure 3] FIG. 10 is a swimlane diagram illustrating another example of a process for securely provisioning a computerized device consistent with embodiments of the present invention.

[0020] [Figure 4A] 1 is a first portion of a block diagram of an example system for implementing a scalable and secure digital asset management system consistent with embodiments of the present invention.

[0021] [Figure 4B] 2 is a second portion of a block diagram of an example system for implementing a scalable and secure digital asset management system consistent with embodiments of the present invention.

[0022] [Figure 5] FIG. 1 is a block diagram of an example computing system that can be used to host systems and methods consistent with embodiments of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0023] Reference will now be made in detail to various embodiments of the present invention, examples of which are illustrated in the accompanying drawings. Wherever convenient, the same reference numerals will be used throughout the drawings to refer to the same or like parts.

[0024] To ensure safe and proper operation in the field, embedded devices (e.g., electronic control units (ECUs) used in vehicles) need to be properly initialized during manufacturing by provisioning them with digital assets, such as security assets. Digital assets can include various cryptographic keys, unique identifiers, digital certificates, and software. In most cases, the origin and manufacturing plants of these digital assets are in different geographic locations, and these locations are traditionally interconnected via insecure internet communications. Therefore, it is desirable to create an end-to-end secure channel from the origin of these digital assets to the device to ensure that the digital assets cannot be accessed or modified by malicious parties or accidentally.

[0025] Conventional network security protocols for end-to-end protection, such as TLS / SSL, have the drawback of requiring the pre-existence of a pre-shared key or specific secret security material on both communicating sides. This creates a recurring technical problem in that some initial secret material must exist in advance in order to provision a digital asset. This problem includes how to protect the initial secret material. This problem is particularly acute for computerized devices because, to simplify logistics, a single version of initial software is typically loaded onto the computerized device during manufacturing. If this initial software needs to include initial security material, it must contain a global secret. As a result, compromising the initial security material would lead to the compromise of all digital assets provisioned on all devices, since they all share the same global secret. Systems, methods, and apparatus consistent with the present disclosure address these and other problems of conventional provisioning systems.

[0026] Provisioning generally refers to a set of actions taken to prepare a computerized device with the appropriate data and software. It can also include a set of actions taken to properly install the device in its operating environment and make it ready for operation. Actions include loading appropriate digital assets (e.g., operating system, device drivers, middleware, applications, digital certificates, etc.) into the device's digital storage (e.g., memory) and (if necessary) properly customizing and configuring specific digital assets on the device that may be unique to each particular device. Actions can also include verifying that the computerized device is a legitimate device created by a legitimate device manufacturer and not a copy or counterfeit device.

[0027] Actions may also include properly installing the equipment in its operating environment and testing it to verify that the equipment is operating correctly. Equipment may be built by one manufacturer and later installed into a larger system or equipment by another (e.g., an on-board unit (OBU) made by a parts manufacturer may be installed in an automobile made by an automobile manufacturer). The ability to securely provision only devices that have been verified as secure is complicated by the fact that improperly installed devices may not function properly.

[0028] Various embodiments consistent with the present invention provide for secure provisioning of computerized devices, including IoT devices. Such embodiments help prevent or inhibit malicious, accidental, or erroneous tampering, modification, update, or release of digital assets used by the computerized devices, and prevent or inhibit improper installation of computerized devices and their software.

[0029] Various embodiments consistent with the present invention may also generate audit logs, records, reports, etc. of the secure provisioning process, which may be used to later analyze and resolve discovered problems.

[0030] Various embodiments consistent with the present invention may also provide a secure provisioning and management platform that may be offered as a service to device and system manufacturers.

[0031] FIG. 1 is a block diagram illustrating an example of a system 100 for secure provisioning of computerized devices consistent with embodiments of the present invention. As shown in the example of FIG. 1, system 100 includes a provisioning controller 120. Provisioning controller 120 may be implemented as a server computer (e.g., having at least one processor and associated memory) with an embedded hardware security module (HSM) that securely generates and stores digital security assets and securely performs various cryptographic and sensitive computations. The HSM protects digital security assets, such as cryptographic keys, and other sensitive data from access by potential attackers. In various embodiments, the provisioning controller 120 functions to authenticate and securely communicate with users of the system 100, securely communicate with and manage one or more distribution devices 108, 131, securely communicate with and direct the operation of the Digital Asset Management System (DAMS) 110, create and store provisioning records, create, store and distribute provisioning records, create, store and distribute audit logs, create and distribute certificates to cryptographically bind elements of the DAMS 110 and the distribution devices 108, 131, revoke users and managed devices if they are no longer trusted, and create and distribute secure encrypted backups of critical keys and data for off-site storage for business continuity and disaster recovery.

[0032] As shown in the example of FIG. 1, the provisioning controller 120 is communicatively connected to a database 125, which may store data, information, and digital assets related to the secure provisioning of devices 106a, 106b (sometimes collectively referred to as 106).

[0033] The provisioning controller 120 is also securely communicatively connected to a manufacturer's user portal 115, which may be implemented, for example, as a server or as an interface to the provisioning controller 120. In various embodiments, staff 109 at the equipment manufacturer 105 may use the manufacturer's user portal 115 to interface with the provisioning controller 120 (and thus the DAMS 110) and manage their equipment provisioning activities. In various embodiments, the manufacturer's user portal 115 may collect identifying information from staff users 109, such as usernames, passwords, two-factor identification data, facial recognition images, fingerprints, etc., and provide the identifying information to the provisioning controller 120. The provisioning controller 120 can authenticate the staff member 109 before allowing the staff member 109 access to the secure provisioning system 100. For example, the provisioning controller 120 can look up previously verified identification information associated with the staff user 109 and stored in its database 125, and compare the stored identification information with identification information collected by the manufacturer's user portal 115. Alternatively, the provisioning controller 120 or the DAMS user portal 115 can be integrated with a user's corporate identification and authentication system to determine whether the staff member 109 is authorized to use the system 100. In various embodiments, the provisioning controller 120 or the DAMS user portal 115 can grant roles to successfully authenticated staff members 109 and limit their actions within the system 100. In some embodiments, the provisioning controller 120 can only allow access if the two sets of identification information match.

[0034] Similarly, the provisioning controller 120 is also communicatively connected to an installer user portal 116, which may be implemented, for example, as a server or as an interface to the provisioning controller 120. In various embodiments, equipment installer staff 132 can use the installer user portal 116 to interface with the provisioning controller 120 (and thus the DAMS 110) and manage their equipment installation and provisioning activities. The provisioning controller 120 can authenticate the staff 132 before authorizing them and assign roles to them before allowing them to access the secure provisioning system 100 and perform authorized functions on the system.

[0035] Similarly, the provisioning controller 120 is also communicatively connected to a regulator portal 117, which may be implemented, for example, as a server or as an interface to the provisioning controller 120. In various embodiments, once authenticated by the provisioning controller 120, the regulator 140 may use the regulator portal 117 to interface with the provisioning controller 120 and manage the review and approval of the manufacturer 104, the installer 130, the equipment 106, and / or the software / digital assets installed on the equipment 106. The provisioning controller 120 may authenticate the regulator 140 before allowing the regulator 140 to access the secure provisioning system 100. In some embodiments of the system 100, the regulator 140 and the regulator portal 117 are optional.

[0036] The provisioning controller 120 is further communicatively coupled to the DAMS 110. In various embodiments, the DAMS 110 can be implemented as a server, a device, or a system of secure devices and / or servers. The DAMS 110 securely retrieves public keys from end-entity devices to be provisioned and securely provides digital certificates and related data that are installed on the devices 106 via distribution equipment 108, 131 or other secure, authenticated connections. The DAMS 110 also securely receives status information regarding the provisioning, installation, functionality, etc. of the computerized devices 106 from the manufacturer 105 and installer 130 via distribution equipment 108, 131. Furthermore, the DAMS 110 can perform this provisioning at a single site as shown in FIG. 1 or at multiple sites. As described in more detail with respect to FIG. 4, the DAMS 110 can include the following main elements: a root certificate authority (CA), a policy generator, a CRL generator, a fraud authority, an intermediate CA, a registration CA, an association authority, a pseudonym CA, and a registration authority.

[0037] The DAMS 110 adds new functionality and improves on the components and functionality described in the paper "Secure Credential Management System for V2V Communications" by William Whyte et al., presented at the 2013 IEEE Vehicular Networking Conference in December 2013. In various embodiments, the DAMS 110 includes multi-stage programming and flexible management (e.g., allowing for the inclusion of a regulator 140). Various embodiments of the DAMS 110 also enable features that allow a single DAMS 110 to provide different levels of provisioning to different subscribers. Various embodiments of the DAMS 110 also enable features that allow subscribers to assign different digital certificates over a period of time (e.g., per week) as well as different certificate loads (e.g., one week instead of three years as in conventional systems). Various embodiments of the DAMS 110 may also provide subscriber-specific URLs so that computerized equipment 106 from a particular manufacturer (e.g., an OEM's automobiles) can remain within the manufacturer's purview (e.g., their URLs reflect their name).

[0038] As shown, the provisioning controller 120 is also communicatively connected to distribution equipment 108, 131. In various embodiments, the distribution equipment 108, 131 can be implemented as standalone secure equipment installed on company premises (as shown) or as web or cloud services, among other things. In various embodiments, the distribution equipment 108, 131 is realized as a trusted endpoint device that securely transmits and receives digital assets and other information to and from the DAMS 110 and the provisioning controller 120, preferably over a dedicated, non-Internet communication channel. As shown, the distribution equipment 108, 131 also connects, either directly or indirectly, with the devices 106a, 106b to download digital assets to and receive data from the devices 106a, 106b. In various embodiments, the distribution equipment 108, 131 can be implemented as a box including a server computer (e.g., having at least one processor and associated memory) with a hardware security module, a hardened operating system (OS), an internal firewall, and an internal host intrusion detection / prevention system. The distribution equipment may be specifically designed to operate in an untrusted environment and still provide trusted and reliable operation. The distribution equipment has a secure communication channel between itself and the secure provisioning controller 120 and the DAMS 110. This channel is used to control the distribution equipment and to send and receive provisioning-related data and log information. The distribution equipment may also have a secure communication channel to the tester 107 used to program or provision the device 106. This channel protects the provisioning and log data from being leaked or altered over the manufacturing site's communication network. The distribution equipment 108 may also establish a secure communication channel directly with the device 106 to be programmed, so that the provisioning data cannot be compromised or altered by third parties (including unauthorized testers 107).In various embodiments, the distribution equipment may collect other data, such as a public key and a microprocessor serial number, from the device 106 it is attempting to provision. The distribution equipment may send this information to the provisioning controller 120 and / or the DAMS 110. The distribution equipment may also receive data, commands, and other information from the provisioning controller 120 and / or the DAMS 110 for programming into the device 106. The distribution equipment may return its own log data, and the distribution equipment may return data from the tester 107 to the provisioning controller 120 and / or the DAMS 110.

[0039] As illustrated with respect to device manufacturer 105, distribution equipment 108 may be communicatively connected to tester 107 (e.g., computerized manufacturing equipment, product inspection equipment, etc.), which in turn communicates with devices manufactured by manufacturer 105, such as OBU devices. The manufacturer 105 may include or be a factory that manufactures and / or markets the computerized equipment 106a. As one of many possible examples, the computerized equipment 106a may be an embedded universal integrated circuit card (eUICC) used in a cellular modem for telecommunications that is later incorporated as part of an on-board unit (OBU) installed in a vehicle for communication between the vehicle and transportation infrastructure equipment. It may also be a V2V secure microprocessor installed in the OBU for communication with other vehicles and roadside units (RSUs). These newly manufactured devices 106a must be properly provisioned with digital assets (e.g., digital certificates from the DAMS 110) to operate properly. Staff 109 at the manufacturer 105 can use the user portal 115 to interact with the provisioning controller 120 and manage product provisioning activities with the DAMS 110.

[0040] As shown with respect to the installer 130, the distribution equipment 131 may alternatively be communicatively connected directly to the equipment 106b while or after the equipment 106b is being installed in its operating environment. The installer 130 may include or be a factory or shop that installs the computerized equipment 106b into their operating environment (e.g., installing an OBU in an automobile). Upon installation, the computerized equipment 106b must be further properly provisioned with digital assets (e.g., additional digital certificates from the DAMS 110) to operate properly. Staff 132 at the installer 130 can use the installer user portal 116 to interact with the provisioning controller 120 and manage product provisioning activities with the DAMS 110.

[0041] In various embodiments, the provisioning controller 120, the distribution equipment 108, 131, and the DAMS 110 can have secure, non-publicly accessible communication links or channels between them, and in various embodiments, all of the communication links shown in FIG. 1 can be secure, non-publicly accessible communication channels. In various embodiments, these secure channels are encrypted and mutually authenticated to prevent unauthorized endpoints from communicating within this secure infrastructure. Multiple security mechanisms can be used to protect these communication channels so that even if the outer layer is somehow compromised, the inner layer remains secure. As an example, a mutually authenticated TLS tunnel can be used as an outer layer along with an inner layer using another protocol, such as a proprietary secure communication protocol. These secure connections between infrastructure components that comprise the system 100 are used to protect confidential communications between the components and ensure their correct operation. Using these secure pathways, the provisioning controller 120 and the DAMS 110 can transmit digital data between the components without concern that it will be leaked or altered in transit. Command and control information can also be passed over these channels. For example, the provisioning controller 120 can control which distribution equipment 108, 131 to send specific digital assets and data to. It can also instruct the distribution equipment 108, 131 on how to meter this data to the equipment 106 on the manufacturing line it is provisioning. Furthermore, the distribution equipment 108, 131 can report information back to the provisioning controller 120 without worrying that the information will be leaked or altered in transit. For example, the secure provisioning controller 120 can program the distribution equipment 108, 131 to provision up to 10,000 devices with any type of digital asset (e.g., certificates, software, fuse content, etc.).The distribution device 108, 131 can count the devices it is provisioning and when it reaches its limit, reports it to the provisioning controller 120. In various embodiments, the provisioning controller 120. Devices (e.g., 108, 110, 131, 115, 116, 117) managed by 20 include functionality that renders them inoperable if they do not regularly communicate with the provisioning controller 120, and therefore if they are stolen and rendered useless. This functionality prevents lost / stolen devices from continuing to operate and provision devices 106 as if they were still in the proper manufacturing environment.

[0042] 1 , in operation, distribution equipment 108 located at manufacturer 105 securely receives digital assets from DAMS 110 and provides them to tester 107 for device 106a. As each device 106a is manufactured by manufacturer 105, tester 107 communicates with device 106a to obtain information from device 106a, such as its unique identification number and status, and downloads or otherwise installs digital assets (e.g., digital certificates) into the device. Tester 107 can also provide information (e.g., provisioning status) from device 106a to distribution equipment 108, which securely communicates that information to DAMS 110 and / or provisioning controller 120. In some embodiments, the tester 107 may include a software Transport Layer Security (TLS) agent that securely transports data between the distribution equipment 108 and the devices 106a, which in effect creates a secure encrypted communication path between the DAMS 110 and the devices 106a via the distribution equipment 108 and the tester 107 using a temporary key associated with each device 106a.

[0043] After it is initially provisioned, the manufacturer 105 ships the device 106a to the installer 130, who installs the device 106b. In various embodiments, before the initial provisioning, the device 106a is non-functional, and after the initial provisioning by the manufacturer 105, the device 106a may be partially functional but not yet fully functional. In such embodiments, the initial provisioning makes the device functional only to the extent required for installation and further final provisioning, which is required to make it fully operational.

[0044] The installer 130 installs the equipment 106b within its operating environment, and a staff member 132 of the installer 130 notifies the provisioning controller 120 of that fact via the installer portal 116. This notification preferably certifies that the installation was properly completed and includes information that uniquely identifies the equipment 106b to the provisioning controller 120. In some embodiments, the distribution equipment 131 may automatically notify the provisioning controller 120 after querying the equipment 106b for status and identification information. In various embodiments in which the installer 130 certifies that he or she properly installed the equipment 106b via the installer portal 116, this certification may be recorded / stored by the provisioning controller 120 in the database 125. The certification may include specific test data associated with each particular installed equipment 106b, such as wireless transmit power measurements or verification of GPS antenna location.

[0045] In response to the installation notification, the provisioning controller 120 verifies that (i) the device 106b is listed in its database 125 as a device legitimately manufactured by the manufacturer 105, (ii) the device 106b is listed in its database 125 as having been successfully initially provisioned by the manufacturer 105, and (iii) the installer 130 is listed in its database 125 as an authorized installer. If this verification is successful, the controller 120 instructs the DAMS 110 to send digital assets (e.g., a pseudonymous certificate (PC)) and / or other information necessary to operationally provision the device 106b so that the device 106b can function properly when installed in its operating environment.

[0046] In various embodiments, via the regulator portal 117, the regulator 140 interacts with the provisioning controller 120 to identify, verify, and manage the installers 130 and / or manufacturers 105, preventing unauthorized installers (e.g., hackers) from obtaining authentic digital assets from the system 100. Staff members of the regulator 140 can be authenticated by the provisioning controller 120 and have unique identities with the system 100 so that their actions can be uniquely recorded. In various embodiments, the regulator 140 can use the regulator portal 117 to query the provisioning controller 120 to obtain copies and reports of information recorded by the controller 120, such as verification reports, installer actions, the number and identification of manufactured equipment 106a, and the number and identification of installed, fully provisioned equipment 106b.

[0047] In various embodiments, the installer 130 must be authenticated as authorized by the provisioning controller 120 in order to interact with the system 100. To be authorized, the installer 130 may, for example, have to execute appropriate contractual documents stating that they will properly install the equipment 106b in the target environment (e.g., a target vehicle or site, etc.). The installer 130 may also be required to certify other contractual elements, for example, by the regulator 140. Preferably, each installer 130 has a unique ID within the system 100 so that their actions can be uniquely recorded by the provisioning controller 120.

[0048] The described embodiment of the system 100 and its functionality ensures that only equipment 106 manufactured by a manufacturer 105 and properly installed and tested by an authorized installer 130 is fully provisioned with the digital assets necessary to make the equipment 106 operational. The provisioning controller 120 generates extensive logs and reports of who took what action at each stage of the provisioning process, providing important audit capabilities not present in conventional systems.

[0049] Those skilled in the art will appreciate that the components, processes, data, operations, and implementation details shown in FIG. 1 are examples presented for brevity and clarity of explanation. This example is not intended to be limiting, and many variations are possible, so other components, processes, implementation details, and variations can be used without departing from the principles of the present invention. For example, while FIG. 1 shows only one manufacturer 105, one installer 130, and one regulator 140, other embodiments may have any number of each of these entities. In another example, while the DAMS 110 and the provisioning controller 120 are shown as separate devices, other embodiments may combine their functionality into a single device (e.g., a single server). As yet another example, the same could be done for the portals 115-117. As yet another example, the system 100 could further include an asset management appliance (AMA, not shown), as described in U.S. Provisional Patent Application No. 62 / 421,852, filed November 14, 2016, which is incorporated by reference. In one such embodiment, the AMA may be communicatively connected to the provisioning controller 120 and / or the distribution equipment 108, 131 and / or the DAMS 110. In various embodiments, the AMA may include a user-friendly GUI and functionality that enables a production coordinator to easily and efficiently manage the configuration and build of products (e.g., equipment 106) and enables an asset owner to easily and efficiently manage their inventory of digital assets.

[0050] FIG. 2 is a swim-lane diagram illustrating an example process 200 for securely provisioning a computerized device consistent with embodiments of the present invention. Although some or all of the illustrated process 200 or operations may be performed by code executing on a general-purpose computing system (which may include one or more processors or one or more computing subsystems), by a hardware-only system, or by a system that is a hybrid of the two. As shown across the top of Figure 2, the entities involved in process 200 include a manufacturer 105 of computerized equipment 106, distribution equipment 108 located at the manufacturer 105, a provisioning controller 120, and a DAMS 110. In various embodiments, these entities can be as described with respect to Figure 1 and throughout this disclosure and can communicate with each other as such.

[0051] As shown in the example of FIG. 2 , process 200 begins at 205 when a manufacturer 105 (e.g., staff member 109) requests digital asset provisioning services from a provisioning controller 130, where a digital asset is to be provisioned to (e.g., used by) a device 106a, and the request may identify the device 106a to which the digital asset is destined. The request may be, for example, the manufacturer 105 requesting provisioning services for a new product 106 or making a new provisioning service request for an existing product 106. In various embodiments, this operation may include an authorized user logging on to the provisioning controller 130, for example, via the user portal 115. In some cases, the requested digital asset may be secure credentials, such as, for example, an enrollment certificate, executable code for the device 106 to execute, digital operating parameters, etc. A registration certificate is a public key certificate that identifies its holder as an authorized participant in an ecosystem where all participants must share a valid registration certificate (e.g., USDOT's V2X ecosystem) and authorized participants can also receive pseudonymous certificates that enable communication and operation of devices 106 in the ecosystem (e.g., in the USDOT's V2X ecosystem example, to enable communication and operation between vehicles and roadside infrastructure).

[0052] At 210, the provisioning controller 120 determines whether the user from the manufacturer 109 is an authorized user. In some embodiments, the provisioning controller 120 may also determine at 210 whether the device 106a (e.g., product) to be provisioned is authorized for use with the system 100. In some cases, a list of authorized devices may be provided by the regulator 140 of FIG. 1 and used by the provisioning controller 120 to make this determination.

[0053] If the user (and / or product) is not authorized, the provisioning controller 120 denies the request to the digital asset provisioning service (not shown in FIG. 2). On the other hand, if an authorized user is making the request (e.g., for an authorized product) (210, yes), the provisioning controller 120 instructs, commands, or otherwise controls the DAMS 110 to fulfill the service request (e.g., by sending a service request instruction to the DAMS 110 (at 215)).

[0054] At 220, in response to and conditional on receiving the request from 215, the DAMS 110 configures itself to begin servicing the device 106a based on the request. In some embodiments, the DAMS 110 may also send instructions (not shown) to the distribution equipment 108 to configure the distribution equipment 108 to provide service to the device 106a.

[0055] At 222, the DAMS 110 generates, creates, calculates, and / or retrieves digital assets for the device 106a as requested at 205. The DAMS 110 can create or generate requested digital security assets such as public and private key pairs, as well as registration and pseudonymous certificates for the device 106a.

[0056] In an alternative embodiment of operation 222 (not shown in FIG. 2 ), the DAMS 110 requests and receives digital asset generation information associated with the device 106a from the distribution device 108 (e.g., registration and pseudonymous public keys generated by or retrieved from the device 106a and data that uniquely identifies the device 106a (e.g., a microprocessor serial number)). In such an embodiment, the DAMS 110 then uses the registration and pseudonymous public keys to generate digital assets (e.g., a registration certificate and an appropriate number of pseudonymous certificates for the device 106a).

[0057] At 225, the DAMS 110 transmits the digital asset to the distribution equipment 108 of the manufacturer 105 that requested the digital asset service at 205. For example, the DAMS 110 can securely transmit the public and private key pair, the registration certificate, and the pseudonym certificate to the distribution equipment 108 of the manufacturer 105.

[0058] At 226, the DAMS 110 sends log information about the digital asset to the provisioning controller 120. In various embodiments, the log information may include information describing the request and transfer of the digital asset, such as, for example, the requestor's ID, the digital asset's ID, the distribution equipment's ID, timestamps of the request and send actions, and the serial number of the receiving microprocessor. In some embodiments, the log information may include a copy of the digital asset. At 227, the provisioning controller 120 receives the log information and stores it, for example, in the database 125. In practice, the provisioning controller 120 maintains an audit trail of all activity occurring within the system 100, which may assemble many types of data, such as data regarding how and when the device 106a can be built and provisioned by the manufacturer 105. Such data and log information may be used for billing and auditing purposes.

[0059] At 230, the distribution equipment 108 receives and stores the digital assets (eg, public and private key pairs, registration certificates and pseudonym certificates) sent by the DAMS 110.

[0060] At 235, the distribution equipment 108 requests and receives from the device 106a a digital security asset, such as a public key, that can be used to securely transfer the digital asset from the distribution equipment 108 to the device 106a. Various types of devices 106a have the ability to generate a temporary key pair, perhaps using a secure processor built into the device 106, and the public key can be part of the temporary key pair. At 240, the distribution equipment 108 uses the digital security asset (e.g., the public key) to securely transmit the digital asset (e.g., a registration certificate) to the device 106a. In various embodiments, the distribution equipment 108 can use the device 106a's public key, for example, to form a virtual private network (VPN) with the device 106a and securely transmit the digital asset therein.

[0061] In various embodiments, distribution equipment 108 may use Transport Layer Security (TLS) between itself and tester 107 to secure communications with tester 107, which may be connected to device 106a. In embodiments where secure communications directly to device 106a are desired, the system may create a temporary public key pair on device 106a and use that public key, along with a certificate from distribution equipment 108 containing the distribution equipment's 108 public key, to create a secure tunnel to device 106a. In such embodiments, device 106a runs special code within it using the system's 100 root public key to verify the certificate that distribution equipment 108 sends to it.

[0062] Once a secure path is established between device 106a or tester 107 and distribution equipment 108, device 106a creates a registration and pseudonymous public key pair (e.g., for a V2X ecosystem) and exports the public key and other data to distribution equipment 108, which can then transmit this data to DAMS 110 and provisioning controller 120. As described above with respect to the alternative embodiment of operation 222, DAMS 110 can create registration and pseudonymous certificates using the received public keys, and in some embodiments there can be a large number (e.g., 3,000) of pseudonymous certificates. In this alternative example of an embodiment, DAMS 110 returns these certificates to distribution equipment 108 at operation 225, as described above. In some other embodiments, DAMS 110 can send these certificates to distribution equipment 108 instead of DAMS 110, depending on where provisioning is being performed.

[0063] In some embodiments, distribution equipment 108 may communicate directly with equipment 106, for example, if equipment 106 has its own wireless or wired communication capabilities and is at least partially operational. In other embodiments, distribution equipment 108 may communicate indirectly with equipment 106 through an intermediate device, such as tester 107.

[0064] The device 106a receives the digital asset and stores it for use during operation. For example, if the device 106a is an automotive on-board unit (OBU) or an electronic control unit (ECU), and the digital asset is a security asset (e.g., a public key certificate) required to join a wireless network, the digital security asset is stored by the OBU. When the OBU is later installed in the car and turned on, it attempts to connect to the wireless network. Before allowing the OBU to connect to the network, the network attempts to authenticate the OBU. The OBU can authenticate and join the network only if it has the digital security asset provided by the distribution equipment 108 at the manufacturer 105.

[0065] At 245 , the distribution device 108 receives or accesses status information from the device 106 a indicating whether the device 106 a successfully received and installed (eg, stored) the digital asset transmitted at 240 .

[0066] At 250, the distribution device 108 sends the status information to the provisioning controller 120. And, at 255, the provisioning controller 120 receives and stores the status information in association with the log information stored at operation 227. Thus, the provisioning controller 120 maintains an audit trail or audit log of all of the system 100 activity associated with each particular device 106. In various embodiments, the audit log can include information for each device 106 indicating the manufacturer's provisioning success or failure (e.g., operations 235-245), the identity of the digital asset (and / or copies of the digital asset itself), encryption type, etc.

[0067] At 270, if the device 106a has been successfully provisioned with the digital assets, the manufacturer 105 releases the device to the market. For example, the manufacturer 105 may physically ship the device 106a to a company (e.g., the installer company 130 of FIG. 1 ) that will install the device in its operating environment. In some embodiments, the device 106a may be fully programmed or provisioned at this point and capable of operating with full functionality, while in other embodiments, the device 106a may only be partially programmed or provisioned at this point and may not be able to or will not operate with full functionality.

[0068] The example shown in FIG. 2 is for illustrative purposes only and is not intended to be limiting. Moreover, while the illustrated process 200 is a somewhat simplified example for clarity of description of certain novel and innovative configurations consistent with certain disclosed embodiments, this example is not intended to be limiting, and many variations are possible. For example, while functions and operations are shown as being performed in a particular order, the described order is merely an example, and various different sequences of operations can be performed that are consistent with certain disclosed embodiments. Furthermore, while operations are described as separate steps merely for purposes of explanation, in some embodiments, multiple operations may be performed simultaneously and / or as part of a single computation or larger operation. The described operations are not intended to be exhaustive, limiting, or absolute, and various operations may be modified, inserted, or deleted. As an example of a variation, although FIG. 2 is generally described in the context of a single digital asset (e.g., a single digital certificate), the system and process similarly function to process multiple digital assets (e.g., two or more digital certificates). As another example, if device 106a does not have secure communications capabilities, operations 235 and 240 can be eliminated and distribution device 108 can communicate with device 106b using unencrypted communications.

[0069] As yet another example, in various embodiments, the provisioning controller 120, or a delegation authority such as a dedicated signing device, may similarly transmit to the distribution device 108 to cause another or additional digital asset to be loaded onto the device 106b, including digital assets such as software, firmware, fuse blobs, manifest files, etc. In such embodiments, the provisioning controller 120 may additionally or alternatively search, retrieve, or otherwise access or direct access of the requested digital asset from storage. For example (not shown in FIG. 2 ), the provisioning controller 120 or its authorized delegate may search for an executable software image (e.g., a compiled computer program stored in database 125) to be loaded and executed on the device 106a and transmit the executable software image to the distribution device 10 for programming into the device. In various embodiments, the digital assets accessed by the provisioning controller 120 may consist only of software, etc., securely supplied, released, and / or licensed by the manufacturer 105 of the device 106a, so that unauthorized software cannot be loaded into the device 106a. In some embodiments, the digital assets retrieved by the provisioning controller 120 may be stored in a storage device or database associated with the provisioning controller 120, such as database 125 of FIG.

[0070] 3 is a swim-lane diagram illustrating one example of a process 200 for securely provisioning computerized equipment consistent with embodiments of the present invention. In various embodiments, process 300 or some or all of the illustrated operations may be performed by code executing on a general-purpose computing system (which may include one or more processors or one or more computing subsystems), by a hardware-only system, or by a system that is a hybrid of the two. As shown across the top of FIG. 3, entities involved in process 300 include an installer 130 of computerized equipment 106, distribution equipment 131 located at the installer 130, provisioning controller 120, and DAMS 110. In various embodiments, these entities may be as described with respect to FIG. 1 and throughout this disclosure and may communicate with each other as such.

[0071] As shown in the example of Figure 3, process 300 begins at 305 when an installer 130 receives equipment 106b (e.g., an OBU or ECU) that has been manufactured and released or shipped by a manufacturer 105 (see operation 270 of Figure 2). At 310, the installer 130 The equipment 106b may be installed in its operating environment, such as a vehicle, a larger system, etc. For example, the installer 130 may be an automobile manufacturer that purchases the OBU from the manufacturer 105, and the installer 130 may install the OBU in the automobile. In various embodiments, installing the equipment 106b may include testing the operation, functionality, etc. of the equipment 106b after installation and collecting associated status data.

[0072] In some embodiments, the device 106b may be only partially provisioned and not fully functional. For example, the manufacturer 105 of the device 106b may provision the device 106b with only an enrollment certificate, such that the device 106b needs to be further provisioned with another digital certificate (e.g., a pseudonymous certificate) to gain full functionality (e.g., the ability to communicate with another fully programmed device 106).

[0073] At 315, the installer 130 (e.g., staff member 132) sends installation status data to the provisioning controller 120. In various embodiments, the installation status data includes an immutable identifier for the installed equipment (e.g., a serial number or other fixed, unique identifying information, such as a public key from a key pair that is generated once and never erased). The installation status data may also include other information, such as a unique identifier for the installer 130, information indicating when and how the equipment 106b was installed, information regarding the results of tests performed on the installed equipment 106b, information certifying that the installer 130 installed the equipment 106b in accordance with applicable specifications, contractual requirements, and / or instructions, and / or other similar information.

[0074] At 320, the provisioning controller 120 determines whether the user from the installer 130 is an authorized user. If not, the provisioning controller 120 rejects the installation status communication (not shown in FIG. 3 ). On the other hand, if an authorized user is making the request (320, yes), the provisioning controller 120 determines whether the device 106b identified in the installation status data is an authorized device (325). In some embodiments, the provisioning controller 120 can determine that the device 106b is authorized by verifying its database 125 against previously stored information that: 1) a record for the device 106b exists in its database 125, 2) the record indicates that the device 106b was successfully provisioned with the manufacturer 105, and 3) the record indicates that the device 106b was sent to the installer 130 (which was verified to be an authorized installer at 320).

[0075] If the device identified in the installation status data is not authorized, the provisioning controller 120 rejects the installation status communication (not shown in FIG. 3). On the other hand, if the device 106b identified in the installation status data is authorized (325, yes), the provisioning controller 120 stores 330 the installation status data along with log information associated with the device 106b. For example, the log information associated with the device 106b may have been previously stored in the database 125 as described with respect to operation 227 in FIG. 2.

[0076] At 335, the provisioning controller 120 instructs, commands, or otherwise controls the DAMS 110 to fulfill the provisioning request (e.g., by sending a request to the DAMS 110 to provision the equipment 106b at the installer 130). At 340, in response to and conditional upon receiving the request from 335, the DAMS 110 generates and / or retrieves the digital asset requested at 335. In various embodiments, the DAMS 110 may be configured to process the digital asset 106b as shown in FIG. 2. As described above, the requested digital asset, such as a pseudonym certificate or other public key certificate, may be created or generated. In various embodiments, the DAMS 110, or the provisioning controller 120 on behalf of the DAM 110, may additionally or alternatively search for, retrieve, or otherwise access the requested digital asset from storage, such as an executable image previously stored in database 125 for use with a device of the type of device 106b.

[0077] At 345, the DAMS 110 transmits the digital asset to the distribution equipment 131 of the installer 130 that transmitted the installation status at 315. For example, the DAMS 110 can securely transmit a pseudonymous certificate to the distribution equipment 131 of the installer 130.

[0078] At 350, distribution equipment 131 performs operations the same as or similar to operations 230-245, as described with respect to Figure 2. At 355, distribution equipment 131 transmits status information to provisioning controller 120. And, at 360, provisioning controller 120 receives and stores status information related to previously stored information associated with device 106b, such as the status information stored at operation 227. Thus, provisioning controller 120 maintains an audit trail or audit log of all of the system 100 activity associated with each particular device 106.

[0079] The process 300 shown in FIG. 3 is an example for illustrative purposes and is not intended to be limiting. Moreover, the illustrated process 300 is a somewhat simplified example for clarity of description of certain novel and innovative configurations consistent with certain disclosed embodiments, although many variations are possible. For example, while functions and operations are shown to be performed in a particular order, the described order is merely an example, and various different sequences of operations can be performed consistent with certain disclosed embodiments. Furthermore, while operations are described as separate steps for illustrative purposes only, in some embodiments, multiple operations may be performed simultaneously and / or as part of a single computation or larger operation. The described operations are not intended to be exhaustive, limiting, or absolute, and various operations may be modified, inserted, or deleted.

[0080] 4A and 4B together illustrate a block diagram of an example system 400 for implementing a scalable and secure digital asset management system in accordance with an embodiment of the present invention. Various embodiments of system 400 can be used for extremely high volume device transaction and certificate generation processing. In various embodiments, system 400 can be implemented using multiple servers, hardware security modules, multiple calculation or computing engines, and multiple virtual machines (VMs). An example system 400 can be implemented in a private data center, a cloud data center (e.g., AWS), or a hybrid of a private data center and a cloud data center.

[0081] In various embodiments, system 400 may be, be part of, or interact with a digital asset management system (DAMS) 110, which may function as described with respect to FIG. 1 and other sections of this disclosure.

[0082] 4, this architecture can include two provisioning controllers 120 (i.e., a primary and a standby) (preferably implemented on separate servers). The two provisioning controllers 120 include functionality such that objects, data, etc. contained in the primary provisioning controller are copied or otherwise contained in the standby (secondary) provisioning controller. If the primary provisioning controller goes offline for any reason, In this case, a standby provisioning controller can be brought online to replace the primary provisioning controller. This provides continuous (or very high) availability of the provisioning controller 120. In various embodiments, the primary and standby provisioning controllers can be as described with respect to FIG. 1 and other sections of this disclosure. In various embodiments, the provisioning controller 120 can be connected to the system 400 in the same or similar manner as described herein with respect to the connection and communication between the provisioning controller 120 and the DAMS 110 of FIG. 1. In general, the provisioning controller 120 manages the system elements that make up the infrastructure so that only explicitly authorized elements can participate and interact with the system 400. In various embodiments, the provisioning controller 120 can integrate with a user's (e.g., the manufacturer 105 or installer 130) employee identification and authorization system or provide its own identification and authorization capabilities so that only authorized users can use the system 400.

[0083] The architecture of system 400 separates non-security-related applications from security functions. As shown in this example, registration authority 420, certificate authorities 430, 440, and collaboration authorities 450, 460 are implemented as applications on their own virtual machines running on their own dedicated compute engines 425, 435, 445, 455, 465, all of which are separate from non-security-related applications and functions. This provides both technical and security advantages and improvements over conventional systems where hardware security modules are slow, or where cloud service providers are unable to supply HSMs, or where proper management of HSMs is uncertain. As shown in Figure 4, by separating critical security functions from each other and onto separate compute engines, computationally intensive cryptographic and security functions (e.g., elliptic curve butterfly expansion operations or elliptic curve digital signatures), such as those performed by registration authority 420, certificate authorities 430, 440, and collaboration authorities 450, 460, run significantly faster than in existing registration authority systems. This design allows "bottleneck" applications to scale as needed, significantly improving transaction processing. For example, if the registration authority applications running on 405 and 420 need to scale, additional VMs can be added without any changes to the secure computation capabilities of 425. Alternatively, if security computations are limiting performance, additional secure computation engines 425 can be added. This same multidimensional scaling applies to other components of 400. This capability provides significant performance improvements over other existing SCMS systems.

[0084] In various embodiments, registration authority 405 may be an authority within a provisioning network that validates user requests for digital certificates or other types of digital security assets and may enable certificate authorities (e.g., certificate authorities 430, 440) to issue digital certificates. In various embodiments, registration authority 405 may be similar to registration authorities known in public key infrastructure (PKI) systems. In various embodiments, registration authority 405 may be implemented as a Representational State Transfer (REST) ​​web service. As represented by the three "stacked" rectangles shown in FIG. 4 for registration authority 405, in various embodiments, there may be multiple instances of registration authority 405 running simultaneously. This is represented similarly for the other "stacked" elements in FIG. 4.

[0085] As represented by the "DB" arrow that appears in the bottom left of the rectangle, registration authority 405 (and other components of FIG. 4 indicated by "DB" arrows) can connect to database 470. In a preferred embodiment, database 470 is a fast-access, low-latency database. In some embodiments, database 470 may be a NoSQL database or a database service (e.g., the DynamoDB data service offered by Amazon Web Services). In various embodiments, the data stored in database 410 is application dependent, but may include previously issued certificates, various federation authority values, data regarding devices to which certificates have been issued, operator actions, etc. Note that the data may be stored unencrypted, encrypted, or some combination thereof.

[0086] 4, registration authority 405 is connected to other components, which are connected to each other by a messaging subsystem or service represented by box 410. In some embodiments, messaging service 410 can be a high-speed message queuing service, such as Amazon Simple Queue Service (SQS) offered by Amazon Web Services.

[0087] In various embodiments, system 400 includes a registration certificate authority 430 and a pseudonymous certificate authority 440 because the digital certificates generated by registration authority 405 are divided into different segments (e.g., registration digital certificates and pseudonymous digital certificates).

[0088] In various embodiments, the cooperating authority 450, 460 links the identity of the certificate requester (ie, a unique identifier of the certificate requester's device) to the issued pseudonymous certificate for revocation purposes.

[0089] In various embodiments, computation engines 425, 435, 445, 455, and 465 and provisioning controller 120 include HSMs that allow these components to perform secure computations without undue threat from hackers. In some embodiments, computation engines 425, 435, 445, 455, and 465 can be designed to perform secure computations themselves without requiring an embedded HSM, and in such embodiments, they embody an HSM.

[0090] Those skilled in the art will appreciate that the components, processes, data, operations, and implementation details shown in Figure 4 are examples presented for simplicity and clarity of explanation. This example is not intended to be limiting, and many variations are possible, so other components, processes, implementation details, and variations can be used without departing from the principles of the invention.

[0091] 5 is a block diagram of an example computing environment 501 including a computing system 500 that can be used to implement systems and methods consistent with embodiments of the present invention. Other components and / or arrangements can also be used. In some embodiments, computing system 500 can be used to at least partially implement various components of FIGS. 1-3 (e.g., provisioning controller 120 and DAMS 110, among others). In some embodiments, a series of computing systems similar to computing system 500 can each be customized with dedicated hardware and / or programmed as a dedicated server to implement one of the components of FIGS. 1-3 and can communicate with each other via network 535.

[0092] 5, the computing system 500 includes a number of components, such as a central processing unit (CPU) 505, memory 510, input / output (I / O) devices 525, a hardware security module (HSM) 540, and a non-volatile storage device 520. The system 500 can be implemented in a variety of ways. For example, a server, An implementation as an integrated platform (such as a workstation, personal computer, laptop, etc.) may include a CPU 505, memory 510, non-volatile storage 520, and I / O devices 525. In such a configuration, the components 505, 510, 520, and 525 may connect and communicate via a local data bus and may access a data repository 530 (e.g., implemented as a separate database system) via an external I / O connection. The I / O component 525 may connect to external devices via a direct communication link (e.g., a wired or local WiFi connection), through a network such as a local area network (LAN) or wide area network (WAN, e.g., a cellular network or the Internet), and / or through other suitable connections. The system 500 may be standalone or may be a subsystem of a larger system.

[0093] CPU 505 may be one or more known processors or processing devices, such as the Core® family of microprocessors manufactured by Intel® Corporation of Santa Clara, California, or the Athlon® family of microprocessors manufactured by AMD® Corporation of Sunnyvale, California. Memory 510 may be one or more high-speed storage devices configured to store instructions and information executed or used by CPU 505 to perform certain functions, methods, and processes related to embodiments of the present invention. Storage 520 may be volatile or non-volatile, magnetic, semiconductor, tape, optical, or other types of storage devices or computer-readable media, including devices such as CDs and DVDs, and solid-state devices intended for long-term storage.

[0094] In the illustrated embodiment, memory 510 includes one or more programs or applications 515 loaded from storage 520 or from a remote system (not shown) that, when executed by CPU 505, perform various operations, procedures, processes, or methods consistent with the present invention. Alternatively, CPU 505 can execute one or more programs located remotely from system 500. For example, system 500 can access one or more remote programs over network 535 that, when executed, perform functions and processes related to embodiments of the present invention.

[0095] In one embodiment, memory 510 may include programs 515 for performing the specialized functions and operations described herein for provisioning controller 120, DAMS 110, and / or distribution equipment 108, 131. In some embodiments, memory 510 may also include other programs or applications that implement other methods and processes that provide auxiliary functionality to the present invention.

[0096] Memory 510 may also be configured with other programs (not shown) unrelated to the present invention and / or an operating system (not shown) that performs certain functions known in the art when executed by CPU 505. By way of example, the operating system may be Microsoft Windows®, Unix®, Linux®, Apple Computers® operating system, or other operating system. The choice of operating system, or even the use of an operating system, is not critical to the present invention.

[0097] The HSM 540 can be a device with its own processor that securely generates and stores digital security assets and / or securely performs various cryptographic and confidential calculations. The HSM 540 can store digital security assets such as cryptographic keys and other functions. Protects sensitive data from access by potential attackers. In some embodiments, the HSM may be a plug-in card or board attached directly to the computing system 500.

[0098] The I / O devices 525 may include one or more input / output devices that allow data to be received and / or transmitted by the system 500. For example, the I / O devices 525 may include one or more input devices (e.g., a keyboard, a touch screen, a mouse, etc.) that allow data to be input from a user. Additionally, the I / O devices 525 may include one or more output devices (e.g., a display screen, a CRT monitor, an LCD monitor, a plasma display, a printer, a speaker device, etc.) that allow data to be output or presented to a user. The I / O devices 525 may also include one or more digital and / or analog communication input / output devices that allow the computing system 500 to communicate (e.g., digitally) with other machines and devices. Other configurations and / or numbers of input and / or output devices may be incorporated into the I / O devices 525.

[0099] In the illustrated embodiment, system 500 is connected to a network 535 (e.g., the Internet, a private network, a virtual private network, a cellular phone network, and / or other networks), which in turn may be connected to various systems and computing machines (e.g., servers, personal computers, laptop computers, client devices, etc.). Generally, system 500 may input data from and output data to external machines and devices via network 535.

[0100] 5, data source 530 is a standalone database (e.g., database 125) external to system 500. In other embodiments, data source 530 may be hosted by system 500. In various embodiments, data source 530 may manage and store data used to implement systems and methods consistent with the present invention. For example, data source 530 may manage and store data structures including, for example, status and log information for each device 106 provisioned by system 100.

[0101] Data source 530 may include one or more databases that store information and that are accessed and / or managed through system 500. By way of example, database 530 may be an Oracle® database, a Sybase® database, or other relational database. However, systems and methods according to the present invention are not limited to separate data structures or databases, or even to the use of databases or data structures.

[0102] Those skilled in the art will appreciate that the components and implementation details of the system in Figure 5 are examples presented for simplicity and clarity of explanation, and that other components and implementation details may be used.

[0103] Although the foregoing examples use specific examples of computerized devices, such as an OBU, an ECU, and an RSU, for clarity of explanation, the present invention is not limited to those specific examples. Various embodiments consistent with the present invention may be used with and for a wide variety of computerized devices, such as medical devices (e.g., dialysis machines, infusion pumps, etc.), robots, drones, autonomous vehicles, wireless communication modules (e.g., embedded universal integrated circuit cards (eUICCs)), among others.

[0104] Other embodiments of the invention will be apparent to those skilled in the art from consideration of the specification and practice of the invention disclosed herein. It is intended that the specification and examples be considered as exemplary only, with the true scope of the invention being indicated by the following claims.

Claims

1. 1. A system for securely provisioning a computerized device, comprising: a first distribution device communicatively coupled to the computerized device and operable to receive digital assets and load the digital assets into the computerized device; a digital asset management system connected to the distribution equipment via a first secure communication channel and operable to generate and conditionally transmit the digital asset to the distribution equipment; a provisioning controller connected to the distribution equipment via a second secure communication channel and to the digital asset management system via a third secure communication channel, the provisioning controller operable to instruct the digital asset management system to transmit the digital asset to the distribution equipment; The system wherein the computerized device is non-functional before the digital assets are loaded onto the computerized device.

2. a second distribution device connected to the digital asset management system via a fourth secure communication channel, communicatively connected to the computerized device after the first distribution device is disconnected, and operable to receive a second digital asset and load the second digital asset into the computerized device; the provisioning controller is further operable to instruct the digital asset management system to transmit the second digital asset to the distribution device; 10. The system for securely provisioning a computerized device of claim 1, wherein the computerized device is fully functional after the second digital asset is loaded into the computerized device.

3. The digital asset management system includes: one or more virtual machines that execute a registration authority application and are communicatively connected to one or more computation engines that perform cryptographic computations required by said registration authority application; one or more virtual machines that execute a registration certificate authority application and are communicatively connected to one or more computation engines that perform cryptographic computations required by the registration certificate authority application; one or more virtual machines that execute a pseudonymous certificate authority application and are communicatively connected to one or more computation engines that perform the cryptographic computations required by said pseudonymous certificate authority application; one or more virtual machines executing a first cooperating station application and communicatively connected to one or more computation engines performing cryptographic computations required by the first cooperating station application; 10. The system for securely provisioning a computerized device of claim 1, further comprising: one or more virtual machines that execute a second cooperating station application and are communicatively connected to one or more computation engines that perform cryptographic computations required by the second cooperating station application.

4. The digital asset management system includes:

4. The system for securely provisioning a computerized device of claim 3, further comprising a database operatively connected to the one or more virtual machines running the registration authority application, the one or more virtual machines running the registration certificate authority, the one or more virtual machines running the pseudonym certificate authority application, the one or more virtual machines running the first coordination station application, and the one or more virtual machines running the second coordination station application.

5. 10. The system for securely provisioning a computerized device of claim 1, further comprising a first portal operatively connected to the provisioning controller for authenticating a manufacturer of the computerized device and enabling the manufacturer to manage provisioning of the computerized device.

6. 6. The system for securely provisioning a computerized device of claim 5, further comprising a second portal operatively connected to the provisioning controller for authenticating an installer of the computerized device and enabling the installer to manage provisioning of the computerized device.

7. 10. The system for securely provisioning a computerized device of claim 1, further comprising a third portal operatively connected to the provisioning controller for authenticating a regulator of the computerized device and enabling the regulator to manage the provisioning of the computerized device.

8. 2. The system for securely provisioning a computerized device of claim 1, wherein the provisioning controller is further operable to transmit the digital asset to the distribution device for loading onto the computerized device.

9. 9. The system for securely provisioning a computerized device of claim 8, wherein the digital asset is executable code executed by the computerized device.

10. The system for securely provisioning a computerized device of claim 1 , wherein the digital asset is at least one of a digital certificate, a cryptographic key, and executable software.

11. 10. The system for securely provisioning a computerized device of claim 1, wherein the provisioning controller is further operable to create and maintain a log associated with the digital device and storing information regarding provisioning activities of the digital device.

12. 12. The system for securely provisioning a computerized device of claim 11, wherein the digital asset management system is further operable to send information regarding provisioning activities associated with the digital device to the provisioning controller for storage in the log.

13. 12. The system for securely provisioning a computerized device of claim 11, wherein the first distribution device is further operable to transmit information regarding provisioning activities associated with the digital device to the provisioning controller for storage in the log.

14. 2. The system for securely provisioning a computerized device of claim 1, wherein the provisioning controller is further operable to authenticate the digital device before instructing the digital asset management system to transmit the digital asset.

15. 10. The method of claim 1, wherein the computerized device is an embedded universal integrated circuit card (eUICC). System for.

Citation Information

Patent Citations

  • Provisioning a plurality of computing devices

    US20150081837A1

  • Automating internet of things security provisioning

    US20160248746A1

  • Secure network accessing method for POS terminal, and system thereof

    US20160321638A1