Method for Obtaining an Operation Certificate
The method allows untrusted IoT applications to obtain operation certificates through a proxy engine, maintaining system security by avoiding the disclosure of sensitive information.
Patent Information
- Application Number
- JP2025502594
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-07-20
- Filing Date
- 2023-07-20
- Publication Date
- 2025-07-30
AI Technical Summary
In IoT systems, untrusted or third-party software applications require operation certificates for secure communication, but sharing the host device's valid certificate compromises security.
A method where an authorized host node sends a Certificate Signing Request (CSR) to a proxy engine, which submits it to a Certificate Authority (CA) for signing, ensuring the host node obtains the certificate without revealing infrastructure details.
This method secures the IoT system by preventing the leakage of sensitive information while enabling untrusted applications to obtain operation certificates for secure communication.
Smart Images

Figure 2025524686000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of certificates of operation for devices in a network such as an IoT (Internet of Things) network, and more particularly to a method for obtaining a certificate of operation for an application operating at an authorized and / or authenticated host node in a network.
Background Art
[0002] Networked devices such as IoT devices and M2M (Machine-to-Machine) devices have the ability to be communicatively connected to each other for device-to-device communication and / or to connect to other networks, cloud-based devices such as servers, or the Internet. In one example, such networked devices may include smart metering devices for electricity, water, or gas.
[0003] In one example, an IoT system may comprise IoT devices communicatively connected to each other to exchange data. The IoT system may include a set of nodes that connect directly or indirectly to a network, such as the Internet or an intranet, via one or more additional node layers.
[0004] The operation or function of such an IoT device may require one or more certificates of operation that ensure that the IoT device (or the user of the IoT device) is permitted to perform the operation or function. Typically, such a certificate of operation can identify functional and operational limitations of the IoT device, such as a time period or expiration time for performing a given function.
Summary of the Invention
Problems to be Solved by the Invention
[0005] In an IoT system, there may be a need to obtain an operation certificate signed by an authorized Certificate Authority (CA).
[0006] However, in some embodiments, an untrusted or third - party software application, known as an "app", may be executed at an authorized node within the IoT system. For secure transport, such a software application may need to obtain its own operation certificate in order to communicate securely with, for example, other nodes, servers, or devices within the IoT system.
[0007] In order for such an untrusted or third - party software application to obtain its own operation certificate, the valid certificate of the host device may be shared with the software application, which may require the software application to authorize the request using the CA. However, this may require leaking information to the software application, which may compromise the security of the host or even the security of the IoT system.
[0008] Therefore, it is desirable to provide a means for obtaining an operation certificate for a software application executed on a host device in an IoT or M2M system without leaking information to a software application that may compromise security.
[0009] Therefore, it is an object of at least one embodiment of at least one aspect of the present disclosure to avoid or at least mitigate at least one of the above - described drawbacks of the prior art.
Means for Solving the Problem
[0010] The present disclosure relates to the field of certificates of operation for devices in a network such as an IoT network, and more particularly to a method for obtaining a certificate of operation for an application operating at an authorized and / or authenticated host node in a network.
[0011] According to a first aspect of the present disclosure, there is provided a method for obtaining a certificate of operation for an application operating at an authorized and / or authenticated host node in a network. The method includes the application sending a request including a Certificate Signing Request (CSR) to a proxy engine operating at the authorized and / or authenticated host node, the proxy engine receiving the request and submitting the CSR to a Certificate Authority (CA), the CA signing the certificate of operation and sending a response including the signed certificate of operation to the proxy engine, and the proxy engine forwarding the signed certificate of operation to the application.
[0012] As an advantage, such a method effectively delegates the request for the CSR for the certificate of operation without leaking details of the signed certificate of the host device or details of the Public Key Infrastructure (PKI) framework such as the IP address of the Certificate Authority (CA).
[0013] In an exemplary IoT environment, there may be a need to obtain a certificate of operation (known in the art as an "opcert") signed by a known and / or authorized CA server. In an environment where there is an untrusted or third-party software application, such as an "app", operating at an authorized node, there may be a need for the software application to obtain one or more of its own certificates of operation for secure transport. The method described above can address this need.
[0014] That is, in a secure ecosystem related to one or more software applications and any host system on which the one or more software applications may be operating, an authorized host node may obtain one or more certificates of operation on behalf of the one or more software applications by using its credentials, such as its authorization and / or authentication.
[0015] Furthermore, by implementing the present method, the disclosed method can reduce the complexity of the system because it can relax the requirement for the software application to communicate about the infrastructure details that may be required for the software application to be able to independently request a certificate of operation.
[0016] The CA may be an authorized CA server. The CA may be an authorized CA proxy.
[0017] A proprietary protocol may be used for the application to send a request including a Certificate Signing Request (CSR) to a proxy engine operating at an authorized and / or authenticated host node.
[0018] Before receiving the signed certificate of operation, the application may be an untrusted application or an application client operating at an authorized and / or authenticated host node.
[0019] The network may comprise a Public Key Infrastructure (PKI) configured to implement an a priori method of authenticating / authorizing host nodes.
[0020] That is, the above-described signed certificate of the host device may be a so-called "birth certificate", for example, a signed certificate issued to and loaded on the host device at the factory, which provides authenticity regarding the unique host device.
[0021] The authentication / authorization of the host node may be based on a signed certificate issued and / or assigned and / or installed to the host node during the manufacture of the host node.
[0022] That is, the "birth certificate" may be used as an authentication mechanism for obtaining an operation certificate used for normal secure transport flow operations.
[0023] The application may be configured to generate a public key / private key pair. The request may include a public key for encrypting the response from the CA.
[0024] The response from the CA may include an operation certificate encrypted using the public key.
[0025] The method may include decrypting the operation certificate encrypted using the public key by using the private key.
[0026] The request may include a parameter indicating the type of the operation certificate, for example, data.
[0027] The request may include a previous operation certificate.
[0028] That is, the payload of the request may include a "cert type" indicating one or more types of operation certificates, such as TLS or signature. The payload of the request may include a CSR. The payload of the request may include, for example, one or more previous operation certificates if the request relates to an update of one or more operation certificates. The payload of the request may include a public key used to encrypt the response returning the signed operation certificate.
[0029] The proxy engine may be an authenticated certificate manager configured to receive requests from applications that request CSRs.
[0030] That is, the proxy engine may receive an operating certificate request and, using its own authentication, generate a connection to a CA (or CA proxy) and submit a CSR.
[0031] The network may be an IoT (Internet-of-Things) network.
[0032] According to a second aspect of the present disclosure, there is provided a method for authenticating / permitting an application in an IoT network, the method including obtaining an operating certificate for the application according to the method described in any preceding claim. [[ID=??]]
[0033] As an advantage, the disclosed method can enable a software application operating on a host to obtain an operating certificate without manually adding authentication permissions for each software application individually and while ensuring and / or masking the details security of any PKI framework.
[0034] According to a third aspect of the present disclosure, there is provided a computer-readable storage medium including instructions that, when executed by a computer in a permitted and / or authenticated host node in a network, cause the computer to perform the following operations. The operations include configuring an application to send a request including a certificate signing request (CSR) to a proxy engine operating in a permitted and / or authenticated host node, configuring the proxy engine to receive the request and submit the CSR to a certification authority (CA), configuring the proxy engine to receive a response including an operating certificate signed by the CA from the CA, and configuring the proxy engine to transfer the signed operating certificate to the application. It should be noted that there seems to be a typo in the original text where "??" is shown in ID 16. This has been left as is in the translation.
[0035] According to a fourth aspect of the present disclosure, there is provided a node device communicably connected to a network, comprising a computer-readable storage medium according to the third aspect and / or a node device connected to the computer-readable storage medium according to the third aspect.
[0036] The node device may be configured as a smart supply-demand meter for measuring the consumption of electricity, water, or gas.
[0037] The above summary is intended to be merely illustrative and non-limiting. The present disclosure includes, in isolation or in various combinations, one or more corresponding aspects, embodiments, or features, whether specifically described (including claims) in combination or separately. It should be understood that the features defined above for any aspect of the present disclosure, or the features defined below for any particular embodiment of the present disclosure, may be used alone or in combination with any other defined features in any other aspect or embodiment, or to form further aspects or embodiments of the present disclosure.
Brief Description of the Drawings
[0038]
Figure 1
Figure 2
Figure 3
Mode for Carrying Out the Invention
[0039] These and other aspects of the present disclosure will now be described by way of example only, with reference to the accompanying drawings.
[0040] FIG. 1 shows an example of a network 100 for implementing a method of obtaining an operation certificate according to an embodiment of the present disclosure. The network includes a plurality of nodes 105, 110, 115, 120, 125, 130.
[0041] In the exemplary network 100, the plurality of nodes 105, 110, 115, 120, 125, 130 are communicably connected to the Internet 135. The example of FIG. 1 shows connectivity to the Internet 135, but in other examples, the plurality of nodes 105, 110, 115, *************** 120, 125, 130 may be connected to an intranet. Further, the connectivity may be via any known medium such as wireless, optical, conductor, via one or more routers or gateways, etc. That is, it will be understood that FIG. 1 shows an example of the network 100 for illustrative purposes, and that networks of various other configurations may implement the invention of the present disclosure.
[0042] Furthermore, the nodes of the network 100 may be indirectly connected to the Internet 135, such as the node 110 connected to the Internet 135 via a further node 105.
[0043] In this example, the network 100 may be an IoT network, for example, a network 100 in which sensors, software, and other technologies may be embedded in the plurality of nodes 105, 110, 115, 120, 125, 130 for the purpose of connecting and exchanging data with other devices and systems via the Internet.
[0044] For example, one or more of the plurality of nodes 105, 110, 115, 120, 125, 130 may be configured as a smart supply - demand meter for measuring the consumption of electricity, water, or gas, and for transmitting consumption information to a utility company via the Internet 135 and / or for transmitting price information to consumers.
[0045] The first node 130 has processing capabilities for executing one or more software applications. In this embodiment, the software application 140 is executed on the first node 130. Thus, the first node 130 is a host device for the software application 140.
[0046] The first node 130 may be an authorized and / or authenticated host node in the network 100. That is, the first node 130 may be permitted to communicate via the network 100, such as one or more of the other ones of the plurality of nodes 105, 110, 115, 120, 125, 130 via the Internet 135.
[0047] The first node 130 may comprise a signed certificate 150, which, as described above, is a so-called "birth certificate", for example, a signed certificate issued to and loaded / installed on the first node 130 at the time of manufacture of the first node 130, and may be a certificate providing authenticity regarding its unique first node 130 in the network 100.
[0048] In use, the software application 140 may be an untrusted and / or third-party application.
[0049] In order for the software application 140 operating at the authorized and / or authenticated first node 130 to be able to communicate via the network 100, it may be necessary for the software application 140 to obtain a signed certificate of operation.
[0050] In use, software application 140 may be configured to send a request including a CSR to proxy engine 145 operating at an authorized and / or authenticated first node 130. In an embodiment, a proprietary protocol may be used for software application 140 to send a request including a certificate signing request (CSR) to proxy engine 145 operating at an authorized and / or authenticated first node 130. Software application 140 may be configured to generate a public key / private key pair. The request may include the public key.
[0051] In some embodiments, the request payload may include a "cert type" indicating one or more types of operating certificates, such as TLS or signature. The request payload may include the CSR. The request payload may include one or more previous operating certificates, for example, if the request relates to an update of one or more previously issued and / or signed operating certificates. The request payload may include the public key used to encrypt the response returning the signed operating certificate.
[0052] Proxy engine 145 may receive the request and submit the CSR to a certificate authority (CA) 155.
[0053] For illustrative purposes only, CA 155 is shown as operating at a second node 125 connected to the Internet 135. However, this is for illustrative purposes only and CA 155 may be implemented in other parts of network 100, including a server, a cloud-based device, an edge device, or parts of network 100 not shown in FIG. Network 100. CA 155 may be an authorized CA server. CA 155 may be an authorized CA proxy.
[0054] CA 155 may be configured to sign the operating certificate and subsequently send a response including the signed operating certificate to proxy engine 145. The response from CA 155 may include the operating certificate encrypted using the public key.
[0055] The proxy engine 145 may be configured to transfer the signed proof of operation certificate to the software application 140.
[0056] In some embodiments, the software application 140 may be configured to decrypt the proof of operation certificate encrypted with the public key by using the private key.
[0057] FIG. 2 shows a sequence diagram corresponding to a method for obtaining a proof of operation certificate according to an embodiment of the present disclosure. The sequence diagram also corresponds to the flowchart of FIG. 3.
[0058] In a first event 205, the software application shown as "app", which may be the software application 140 of FIG. 1, sends a request including a payload to a proxy engine shown as "proxy". The proxy engine may be the proxy engine 145 operating at the first node 130 permitted and / or authenticated by the network 100 of FIG. 1.
[0059] The payload of the request includes a certificate signing request (CSR). As described above, in other embodiments, the payload may also include one or more of "cert type", one or more previous proof of operation certificates, and / or one or more of the public keys used to encrypt the response to return the signed proof of operation certificate. The first event corresponds to the first step 305 of the flowchart of FIG. 3.
[0060] In a second event 210 corresponding to the second step 310 of the flowchart of FIG. 3, the proxy engine submits the CSR to a certification authority (CA). The CA may be the CA 155 of the network 100 of FIG. 1.
[0061] In a third event 215 corresponding to the third step 315 of the flowchart of FIG. 3, the CA signs the proof of operation certificate and sends a response including the signed proof of operation certificate to the proxy engine.
[0062] In a fourth event 220 corresponding to the fourth step 320 of the flowchart of FIG. 3, the proxy engine transfers the signed certificate of operation to the software application.
[0063] Although the present disclosure has been described with respect to specific embodiments as described above, it should be understood that these embodiments are merely examples and that the claims are not limited to those embodiments. Those skilled in the art can make modifications and changes in consideration of the present disclosure, which are intended to be included within the scope of the appended claims. Each feature disclosed or illustrated in this specification may be incorporated into any embodiment, either alone or in any suitable combination with any other feature disclosed or illustrated in this application.
Description of Reference Numerals
[0064] 105 Node 110 Node 115 Node 120 Node 125 Node 130 First Node 135 Internet 140 Software Application 145 Proxy Engine 150 Signed Certificate 155 Certification Authority 205 First Event 210 Second Event 215 Third Event 220 Fourth Event 305 First Step 310 Second Step 315 Third Step 320 Fourth Step
Claims
1. A method for obtaining an operating certificate for an application operating on a permitted and / or authenticated host node in a network, the method comprising: the application sending a request including a certificate signing request (CSR) to a proxy engine operating on the permitted and / or authenticated host node; the proxy engine receiving the request and submitting the CSR to a certification authority (CA); the CA signing the operating certificate and sending a response including the signed operating certificate to the proxy engine; the proxy engine forwarding the signed operating certificate to the application. A method.
2. The CA is a permitted CA server or a permitted CA proxy. The method according to claim 1.
3. Before receiving the signed operating certificate, the application is an untrusted application or an application client operating on the permitted and / or authenticated host node. The method according to claim 1 or 2.
4. The network comprises a public key infrastructure (PKI) configured to implement an a priori method for authenticating / authorizing the host node. The method according to any one of claims 1 to 3.
5. The authentication / authorization of the host node is based on a signed certificate issued and / or assigned and / or installed on the host node during the manufacture of the host node. The method according to claim 4.
6. The application is configured to generate a public key / private key pair, the request including a public key for encrypting a response from the CA. The method according to any one of claims 1 to 5.
7. The response from the CA includes the operating certificate encrypted using the public key. [[ID= The proxy engine is an authenticated certificate manager configured to receive requests from applications that request the CSR. The method according to one of claims 1 to 9.
11. The network is an IoT (Internet-of-Things) network. The method according to one of claims 1 to 10.
12. A method for authenticating / authorizing an application in an IoT network, the method including obtaining an operating certificate for the application according to the method according to one of claims 1 to 11. Method.
13. A computer-readable storage medium including instructions that, when executed by a computer at a permitted and / or authenticated host node in a network, cause the computer to perform the following operations, the operations including: Configuring an application to send a request including a certificate signing request (CSR) to a proxy engine operating at the permitted and / or authenticated host node; Receiving the request and configuring the proxy engine to submit the CSR to a certificate authority (CA); Configuring the proxy engine to receive a response from the CA including an operating certificate signed by the CA; Configuring the proxy engine to transfer the signed operating certificate to the application. Computer-readable storage medium.
14. A node device communicably connected to a network, comprising the computer-readable storage medium according to claim 13 and / or a node device connected to the computer-readable storage medium according to claim 13.
15. The node device according to claim 14, configured as a smart supply-demand meter for measuring power, water, or gas consumption.