Enabling externally initiated communication with an electronic device

By using a hardware identifier embedded in a cryptographic certificate to register and establish communication channels, the challenge of flexible and secure externally initiated communication in electronic devices is addressed, ensuring secure and flexible interactions.

WO2026098858A1PCT designated stage Publication Date: 2026-05-15ASSA ABLOY AB
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
ASSA ABLOY AB
Filing Date
2025-10-02
Publication Date
2026-05-15

AI Technical Summary

Technical Problem

Existing electronic devices face challenges in enabling flexible and secure externally initiated communication, particularly in constrained environments, where devices need to be uniquely identified and securely located by external entities.

Method used

The solution involves obtaining a hardware identifier from read-only memory, forming part of a cryptographic certificate, and using it to register the device in a resource directory, establishing a communication channel based on this certificate, allowing external devices to securely communicate by looking up addressing data using the hardware identifier.

Benefits of technology

This approach enhances the flexibility of connection options while maintaining high security, enabling secure and flexible externally initiated communication between electronic devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025078440_15052026_PF_FP_ABST
    Figure EP2025078440_15052026_PF_FP_ABST
Patent Text Reader

Abstract

It is provided a method for enabling externally initiated communication with an electronic device (2). The method comprises: obtaining (40) a hardware identifier identifying the electronic device (2), the hardware identifier forming part of a cryptographic certificate for the electronic device (2); obtaining (42) addressing data enabling requesting device (5) to reach and communicate with the electronic device; transmitting (44) a registration request to a resource directory device (4), for registering the electronic device (2) in a resource directory (7), the registration request comprising the hardware identifier and the addressing data; and establishing (46) a communication channel with a requesting device (5), based on the requesting device (5) initiating communication with the electronic device, the communication channel being based on the cryptographic certificate for the electronic device (2).
Need to check novelty before this filing date? Find Prior Art

Description

ENABLING EXTERNALLY INITIATED COMMUNICATION WITH AN ELECTRONIC DEVICETECHNICAL FIELD

[0001] The present disclosure relates to the field of communication with an electronic device, and in particular to an electronic device interacting with a resource directory to enable externally initiated communication.BACKGROUND

[0002] In the field of electronic devices, secure communication has become increasingly important as the number of connected devices continues to rise. Many devices today are capable of interacting with external systems or networks, often requiring some form of identification or registration to enable secure communication. Electronic devices, including those used in constrained environments or the Internet of Things (loT), frequently need to communicate with external devices or systems initiated from outside the device itself.

[0003] Traditionally, methods of establishing such communication involve the device being identified and accessible through various protocols. Ensuring that the electronic device can be uniquely identified and securely located by an external entity is crucial. To facilitate this, several protocols and standards exist, each offering different solutions to handle aspects such as device authentication, address resolution, and secure communication.

[0004] It would be of great benefit to enable more flexible registration, while still providing high security.SUMMARY

[0005] One object is to improve how externally initiated communication is supported in terms of flexibility of connection options, while providing a high security.

[0006] According to a first aspect, it is provided 1. A method for enabling externally initiated communication with an electronic device. The method is performed in the electronic device. The method comprises: obtaining a hardware identifier identifying theelectronic device, the hardware identifier forming part of a cryptographic certificate for the electronic device; obtaining addressing data enabling requesting device to reach and communicate with the electronic device; transmitting a registration request to a resource directory device, for registering the electronic device in a resource directory, the registration request comprising the hardware identifier and the addressing data; and establishing a communication channel with a requesting device, based on the requesting device initiating communication with the electronic device, the communication channel being based on the cryptographic certificate for the electronic device.

[0007] The obtaining the hardware identifier may comprise reading the hardware identifier from read-only memory of the electronic device.

[0008] The hardware identifier may be read from a read-only memory of a secure element complying with ISO / IEC 15408.

[0009] The method may further comprise: establishing a registration communication channel between the electronic device and the resource directory device based on the cryptographic certificate. In this case, the transmitting a registration request comprises transmitting the registration request over the registration communication channel.

[0010] The transmitting a registration request may cause the resource directory device to publish data about the registration as a publication in accordance with the Message Queuing Telemetry Transport, MQTT, protocol.

[0011] The addressing data may comprise an indication of a communication protocol used for communicating with the electronic device, and an address of the electronic device using the communication protocol.

[0012] The communication protocol may be Internet Protocol, IP, in which case the address is an IP address.

[0013] The electronic device may comply with Constrained RESTful Environments, CoRE.

[0014] According to a second aspect, it is provided an electronic device for enabling externally initiated communication with the electronic device. The electronic device comprises: processing circuitry; and memory circuitry storing instructions that, when executed by the processing circuitry, cause the electronic device to: obtain a hardware identifier identifying the electronic device, the hardware identifier forming part of a cryptographic certificate for the electronic device; obtain addressing data enabling requesting device to reach and communicate with the electronic device; transmit a registration request to a resource directory device, for registering the electronic device in a resource directory, the registration request comprising the hardware identifier and the addressing data; and establish a communication channel with a requesting device, based on the requesting device initiating communication with the electronic device, the communication channel being based on the cryptographic certificate for the electronic device.

[0015] According to a third aspect, it is provided a computer program for enabling externally initiated communication with an electronic device. The computer program comprises computer program code which, when executed on an electronic device causes the electronic device to: obtain a hardware identifier, being a hardware identifier identifying the electronic device, the hardware identifier forming part of a cryptographic certificate for the electronic device; obtain addressing data enabling requesting device to reach and communicate with the electronic device; transmit a registration request to a resource directory device, for registering the electronic device in a resource directory, the registration request comprising the device identifier and the addressing data; and establish a communication channel with a requesting device, based on the requesting device initiating communication with the electronic device, the communication channel being based on the cryptographic certificate for the electronic device.

[0016] According to a fourth aspect, it is provided a computer program product comprising a computer program according to claim 10 and a computer readable means comprising non-transitory memory in which the computer program is stored.

[0017] Generally, all terms used in the claims are to be interpreted according to their ordinary meaning in the technical field, unless explicitly defined otherwise herein. All references to "a / an / the element, apparatus, component, means, step, etc." are to beinterpreted openly as referring to at least one instance of the element, apparatus, component, means, step, etc., unless explicitly stated otherwise. The steps of any method disclosed herein do not have to be performed in the exact order disclosed, unless explicitly stated.BRIEF DESCRIPTION OF THE DRAWINGS

[0018] Aspects and embodiments are now described, by way of example, with reference to the accompanying drawings, in which:

[0019] Fig 1 is a schematic diagram illustrating an environment in which embodiments presented herein can be applied;

[0020] Fig 2 is a swimlane diagram illustrating embodiments of methods for enabling externally initiated communication with an electronic device;

[0021] Fig 3 is a schematic diagram illustrating components of the electronic device 2 of Fig 1 and Fig 2 according to one embodiment;

[0022] Fig 4 shows one example of a computer program product comprising computer readable means.DETAILED DESCRIPTION

[0023] The aspects of the present disclosure will now be described more fully hereinafter with reference to the accompanying drawings, in which certain embodiments of the invention are shown. These aspects may, however, be embodied in many different forms and should not be construed as limiting; rather, these embodiments are provided by way of example so that this disclosure will be thorough and complete, and to fully convey the scope of all aspects of invention to those skilled in the art. Like numbers refer to like elements throughout the description.

[0024] According to embodiments presented herein, it is provided a solution for an electronic device to enable externally initiated communication with the electronic device. A hardware identifier, also embedded in a cryptographic certificate, is comprised in addressing data that allows other devices to reach and communicate with the electronic device. The electronic device registers itself with a resource directory bytransmitting a registration request containing the hardware identifier and addressing data. When an external device initiates communication, a secure communication channel is established based on the hardware identifier (e.g. included in the cryptographic certificate), ensuring secure interaction between the devices. In this way, as long as the external device has access to the hardware identifier, the external device can look up the address data and communicate with the electronic device. Notably, the addressing data is not limited to only one protocol; any protocol can be used for initiating communication with the electronic device.

[0025] Fig 1 is a schematic diagram illustrating an environment in which embodiments presented herein can be applied.

[0026] At least one electronic device 2 and at least one requesting device 5 is provided. The electronic device 2 can be any suitable electronic device with which a requesting device 5 wants to initiate communication.

[0027] The electronic device 2 can be an loT device, for instance a device such as an electronic lock, a credential reader, keypad, sensor, etc. that is part of an electronic access control system.

[0028] The requesting device 5 can be any type of device that can benefit from being able to initiate communication with the electronic device 2. For instance, the requesting device 5 can be a smartphone comprising an application (also known as ‘app’) that can communicate with the electronic device 2. Alternatively, the requesting device 5 is a server that can collect data from the electronic device 2, set data in the electronic device 2 or actuate an action to be performed by the electronic device 2.

[0029] A resource directory device 4 is provided, holding a resource directory 6 in a database. The resource directory device 4 can e.g. be implemented as a server. The resource directory 6 is implemented using any suitable database structure, known in the art per se.

[0030] The electronic device 2, the requesting device 5 and the resource directory device 4 are connected to each other via a communication network 7.

[0031] The communication network 7 can be an internet protocol (IP) based network. The network can e.g. comprise any one or more of a local wireless network, a cellular network, a wired local area network, a wide area network (such as the Internet), etc. Optionally, the electronic device 2 connects to the communication network 7 via a communication hub (not shown). The communication hub can then act as a gateway between a short-range wireless communication protocol for communicating with the electronic device 2, and a long-range protocol for communicating with the communication network 7. The short-range wireless protocol can e.g. be any one or more of such as Bluetooth, Bluetooth Low Energy (BLE), Zigbee, Z-wave, Thread, Matter, etc. The long-range protocol can e.g. be any one or more of Ethernet, Wi-Fi, cellular network, etc.

[0032] According to embodiments presented herein, the electronic device 2 can register its address data in the resource directory 6 of the resource directory device 4. The requesting device 5 can obtain the addressing data from the resource directory device 4, enabling the requesting device 5 to initiate communication with the electronic device 2.

[0033] Fig 2 is a swimlane diagram illustrating embodiments of methods for enabling externally initiated communication with an electronic device. The entities shown here are the electronic device 2, the resource directory device 4 and the requesting device 5 of Fig 1. Furthermore, it is shown a manufacturing facility manufacturing facility 11 and a certificate authority 10, The swimlane diagrams can be considered to comprise a flow chart for methods in the electronic device 2 on the left. Communication between the various entities is also shown. The manufacturing facility 11 can e.g. be a factory where the electronic device 2 is prepared for delivery. The CA 10 is a certificate authority that is capable of generating cryptographic keypairs that are trusted by the requesting device 5. For instance, the CA 10 can be a CA within public or private public key infrastructure (PKI). 8. The method according to any one of the preceding claims, wherein the electronic device (2) complies with Constrained RESTful Environments, CoRE.

[0034] In a create and store certificate step 30, the CA 10, the manufacturing facility11 and the electronic device 2 cooperate such that the electronic device 2 is providedwith a valid certificate. This can occur according to the following. The manufacturing facility n transmits a request to the electronic device 2 to create a certificate signing request (CSR). The electronic device 2 generates a CSR which comprises a hardware identifier of the electronic device 2, to the manufacturing facility manufacturing facility 11. The hardware identifier can e.g. be a sixteen byte UUID (universally unique identifier) or other number which is practically unique for the purposed presented herein. The configuration enablement device 1, in turn, asks the CA 10 to generate a certificate based on the CSR, including the hardware identifier. The generated certificate is then returned to the manufacturing facility 11, which provides the generated certificate to the electronic device 2.

[0035] In a config (configure) step 38, the electronic device 2 can then be configured. The configuration can include connection details, e.g. to a Wi-Fi network or communication hub. Furthermore, the configuration can include connection details for the resource directory device 4, such as an address (fully qualified domain name or IP address to the resource directory device 4) and optionally a port number, when the resource directory device 4 is not automatically discovered. Furthermore, if a proxy is needed for connecting the electronic device 2 to the communication network 7, the proxy can be configured. The configuration can be applied manually or using a configuration service.

[0036] In an obtain h / w (hardware) identifier step 40, the electronic device 2 obtains a hardware identifier identifying the electronic device 2. The hardware identifier forms part of a cryptographic certificate for the electronic device 2, i.e. the certificate explained above in conjunction with the create and store certificate step 30. The hardware identifier is tied to the electronic device 2. In one embodiment, the hardware identifier is obtained by reading the hardware identifier from read-only memory (ROM) of the electronic device 2. For instance, the hardware identifier is read from a ROM of a secure element complying with ISO / IEC 15408.

[0037] In an obtain address data step 42, the electronic device 2 obtains addressing data. The addressing data enables requesting device 5 to reach and communicate with the electronic device. For instance, the addressing data can comprise an indication of a communication protocol used for communicating with the electronic device, and anaddress of the electronic device 2 using the communication protocol, such as where the communication protocol is IP, and the address is an IP address. As an example, the addressing data can contain information about the communication protocol being IP and the (IP) address is a.b.c.d, where each one of a, b, c and d is an integer between o and 255. Alternatively or additionally any one or more of the following protocols can be indicated in the addressing data: Wi-Fi, Bluetooth, BLE. Zigbee, Z-wave, Thread, and Matter.

[0038] In an establish reg (registration) channel step 43, the electronic device 2 establishes a registration communication channel between the electronic device 2 and the resource directory device 4 based on the cryptographic certificate. The registration communication channel can e.g. be an encrypted channel established based on the cryptographic certificate.

[0039] In a transmit registration req. (request) step 44, the electronic device 2 transmits a registration request 20 to a resource directory device 4, for registering the electronic device 2 in a resource directory 7. The registration request 20 comprises the hardware identifier and the addressing data. The registration request is transmitted over the registration communication channel, when available.

[0040] In a process registration request step 140, the resource directory device 4 receives the registration request 20 and stores the addressing data in the registration request 20 in the resource directory 6 of the resource directory device 4, keyed by the hardware identifier.

[0041] In a publish step 142, the resource directory device 4 makes the data in the registration request available to other entities. The hardware identifier can be used as a key to look up the addressing data. For instance, the resource directory device 4 can publish data about the registration (i.e. the addressing data being accessible using the hardware identifier) in a publication 21 in accordance with the Message Queuing Telemetry Transport (MQTT) protocol. The MQTT is a publish-subscribe protocol that is suitable for this purpose. Nevertheless, other protocols can be employed for the same purpose if desired.

[0042] In a receive registration data step 240, the requesting device 5 obtains registration data. This is based on the requesting device 5 having previous access to the hardware identifier, e.g. as part of the cryptographic certificate which the requesting device 5 may have received, indirectly or directly, from the CA 10 or from the manufacturing facility manufacturing facility 11. Based on the hardware identifier, the requesting device 5 looks up the addressing data from the resource directory device 4. The requesting device 5 is now ready to initiate communication with the electronic device 2.

[0043] In an establish communication channel step 46, the electronic device 2 establishing a communication channel with the requesting device 5. This is based on the requesting device 5 initiating communication with the electronic device. The communication channel is based on the cryptographic certificate for the electronic device 2.

[0044] In a communicate step 48, the electronic device 2 and the requesting device 5 communicate with each other over the established communication channel.

[0045] Fig 3 is a schematic diagram illustrating components of the electronic device2 of Fig 1 and Fig 2. Processing circuitry 60 is provided using any combination of one or more of a suitable central processing unit (CPU), graphics processing unit (GPU), multiprocessor, neural processing unit (NPU), microcontroller, digital signal processor (DSP), etc., capable of executing software instructions 67 stored in memory circuitry 64, which can thus be a computer program product. The processing circuitry 60 could alternatively be implemented using an application specific integrated circuit (ASIC), field programmable gate array (FPGA), etc. The processing circuitry 60 can be configured to execute the method of the electronic device 2 described with reference to Fig 2 above.

[0046] The memory circuitry 64 can be any combination of random-access memory (RAM) and / or read-only memory (ROM). The memory circuitry 64 also comprises non- transitory persistent storage, which, for example, can be any single one or combination of magnetic memory, optical memory, solid-state memory or even remotely mounted memory.

[0047] A data memory 66 is also provided for reading and / or storing data during execution of software instructions in the processing circuitry 60. The data memory 66 can be any combination of RAM and / or ROM.

[0048] An I / O interface 62 is provided for communicating with external and / or internal entities using wired communication, e.g. based on Ethernet, and / or wireless communication, e.g. Wi-Fi, Bluetooth, BLE. Zigbee, Z-wave, Thread, Matter, and / or a cellular network, complying with any one or a combination of sixth generation (6G) mobile networks, next generation mobile networks (fifth generation, 5G), LTE (Long Term Evolution), or any other current or future wireless network, as long as the principles described hereinafter are applicable.

[0049] Other components of the electronic device 2 are omitted in order not to obscure the concepts presented herein.

[0050] Fig 4 shows one example of a computer program product 90 comprising computer readable means. On this computer readable means, a computer program 91 can be stored in a non-transitory memory. The computer program can cause processing circuitry to execute a method according to embodiments described herein. In this example, the computer program product 90 is in the form of a removable solid-state memory, e.g. a Universal Serial Bus (USB) drive. As explained above, the computer program product could also be embodied in a memory of a device, such as the computer program product 64 of Fig 3. While the computer program 91 is here schematically shown as a section of the removable solid-state memory, the computer program can be stored in any way which is suitable for the computer program product, such as another type of removable solid-state memory, or an optical disc, such as a CD (compact disc), a DVD (digital versatile disc) or a Blu-Ray disc.

[0051] The aspects of the present disclosure have mainly been described above with reference to a few embodiments. However, as is readily appreciated by a person skilled in the art, other embodiments than the ones disclosed above are equally possible within the scope of the invention, as defined by the appended patent claims. Thus, while various aspects and embodiments have been disclosed herein, other aspects and embodiments will be apparent to those skilled in the art. The various aspects andembodiments disclosed herein are for purposes of illustration and are not intended to be limiting, with the true scope being indicated by the following claims.

Claims

CLAIMS1. A method for enabling externally initiated communication with an electronic device (2), the method being performed in the electronic device (2), the method comprising: obtaining (40) a hardware identifier identifying the electronic device (2), the hardware identifier forming part of a cryptographic certificate for the electronic device (2); obtaining (42) addressing data enabling requesting device (5) to reach and communicate with the electronic device; transmitting (44) a registration request to a resource directory device (4), for registering the electronic device (2) in a resource directory (7), the registration request comprising the hardware identifier and the addressing data; and establishing (46) a communication channel with a requesting device (5), based on the requesting device (5) initiating communication with the electronic device, the communication channel being based on the cryptographic certificate for the electronic device (2).

2. The method according to claim 1, wherein the obtaining (40) the hardware identifier comprises reading the hardware identifier from read-only memory of the electronic device (2).

3. The method according to claim 2, wherein the hardware identifier is read from a read-only memory of a secure element complying with ISO / IEC 15408.

4. The method according to any one of the preceding claims, further comprising: establishing (43) a registration communication channel between the electronic device (2) and the resource directory device (4) based on the cryptographic certificate; and wherein the transmitting (44) a registration request comprises transmitting the registration request over the registration communication channel.

5. The method according to any one of the preceding claims, wherein the transmitting (44) a registration request causes the resource directory device (4) to publish data about the registration as a publication in accordance with the Message Queuing Telemetry Transport, MQTT, protocol.

6. The method according to any one of the preceding claims, wherein the addressing data comprises an indication of a communication protocol used for communicating with the electronic device, and an address of the electronic device (2) using the communication protocol.

7. The method according to claim 6, wherein the communication protocol is Internet Protocol, IP, and the address is an IP address.

8. The method according to any one of the preceding claims, wherein the electronic device (2) complies with Constrained RESTful Environments, CoRE.

9. An electronic device (2) for enabling externally initiated communication with the electronic device (2), the electronic device (2) comprising: processing circuitry (60); and memory circuitry (64) storing instructions (67) that, when executed by the processing circuitry, cause the electronic device (2) to: obtain a hardware identifier identifying the electronic device (2), the hardware identifier forming part of a cryptographic certificate for the electronic device (2); obtain addressing data enabling requesting device (5) to reach and communicate with the electronic device; transmit a registration request to a resource directory device (4), for registering the electronic device (2) in a resource directory, the registration request comprising the hardware identifier and the addressing data; and establish a communication channel with a requesting device (5), based on the requesting device (5) initiating communication with the electronic device, the communication channel being based on the cryptographic certificate for the electronic device (2).

10. A computer program (67, 91) for enabling externally initiated communication with an electronic device (2), the computer program comprising computer program code which, when executed on an electronic device (2) causes the electronic device (2) to: obtain a hardware identifier, being a hardware identifier identifying the electronic device (2), the hardware identifier forming part of a cryptographic certificate for the electronic device (2) ; obtain addressing data enabling requesting device (5) to reach and communicatewith the electronic device; transmit a registration request to a resource directory device (4), for registering the electronic device (2) in a resource directory, the registration request comprising the device identifier and the addressing data; and establish a communication channel with a requesting device (5), based on the requesting device (5) initiating communication with the electronic device, the communication channel being based on the cryptographic certificate for the electronic device (2).

11. A computer program product (64, 90) comprising a computer program according to claim 10 and a computer readable means comprising non-transitory memory in which the computer program is stored.