会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 1. 发明申请
    • Secure Large Volume Feature License Provisioning System
    • 安全大容量功能许可证配置系统
    • WO2012040393A2
    • 2012-03-29
    • PCT/US2011/052656
    • 2011-09-21
    • GENERAL INSTRUMENT CORPORATIONZHENG, JinsongCHAN, Tat KeungCHEN, LiqiangNAKANISHI, Greg N.PASION, Jason A.QIU, XinYAO, Ting
    • ZHENG, JinsongCHAN, Tat KeungCHEN, LiqiangNAKANISHI, Greg N.PASION, Jason A.QIU, XinYAO, Ting
    • G06Q30/06
    • G06F21/105G06Q30/06G06Q2220/18
    • Disclosed is a manufacturing process and feature licensing system for provisioning personalized (device-unique) licenses to devices, with the following characteristics. The system is secure in that it uses a secure key wrapping mechanism to deliver the LSK to LPS. Another feature is that various network communication links are secured using standard security protocol. Further, application messages, license templates, licenses are digitally signed. The system is also flexible because it is configured to allow multiple manufacturers and to allow various feature configurations via the use of License Template. The system is also scalable, as it is possible to use multiple LPS hosts to serve multiple programming stations. The system is available in that the delegation of license signing capability from CLS to LPS eliminates the dependency on unreliable Internet connections. Redundant LPS hosts provide high level of availability required for high volume license provisioning. The system is traceable in that license and device association are replicated back to the CLS to provide full license request and generation traceability, characteristics are crucial for subsequent license upgrades in the field.
    • 公开了一种用于向设备提供个性化(设备唯一)许可证的制造过程和特征许可系统,具有以下特征。 该系统是安全的,因为它使用安全的钥匙包装机构将LSK传送到LPS。 另一个特征是使用标准安全协议来保护各种网络通信链路。 此外,应用程序消息,许可证模板,许可证都经过数字签名。 该系统也是灵活的,因为它被配置为允许多个制造商通过使用许可证模板来允许各种功能配置。 该系统也是可扩展的,因为可以使用多个LPS主机来服务多个编程站。 该系统是可用的,从CLS到LPS的许可证签名功能的委派消除了对不可靠的因特网连接的依赖。 冗余LPS主机提供高容量许可证配置所需的高可用性。 该系统是可跟踪的,该许可证和设备关联被复制回CLS以提供完整的许可证请求和生成可追溯性,特性对于该领域的后续许可证升级至关重要。
    • 5. 发明申请
    • FRAMEWORK FOR PROVISIONING DEVICES WITH EXTERNALLY ACQUIRED COMPONENT-BASED IDENTITY DATA
    • 用外部获取的基于组件的身份数据提供设备的框架
    • WO2014120436A2
    • 2014-08-07
    • PCT/US2014/011540
    • 2014-01-14
    • GENERAL INSTRUMENT CORPORATION
    • YAO, TingQIU, XinMEDVINSKY, Alexander
    • H04L29/06
    • H04L63/062H04L9/0891
    • A method is provided for updating identity data on devices. The method provides for acquiring a device comprising a component associated with a component identifier and having a One Time Programmable Key installed on the component, submitting the component identifier and the One Time Programmable Key to an External Trust Authority, receiving new identity data tied to the component identifier from the External Trust Authority that is encrypted with the One Time Programmable Key, loading the new identity data onto an Update Server, receiving a request at the Update Server from the device that requests new identity data, and providing the new identity data upon receipt of the request, upon which the device decrypts and installs the identity data using the One Time Programmable Key installed on the component within the device.
    • 提供了一种用于更新设备上的身份数据的方法。 该方法提供用于获取包括与组件标识符相关联的组件并且具有安装在组件上的一次性可编程密钥的组件的设备,将组件标识符和一次性可编程密钥提交给外部信任机构,接收与 来自外部信任机构的组件标识符,其使用一次性可编程密钥加密,将新的身份数据加载到更新服务器上,从请求新身份数据的设备在更新服务器处接收请求,以及提供新的身份数据 接收请求,设备使用安装在设备中的组件上的一次性可编程密钥解密并安装身份数据。
    • 6. 发明申请
    • ONLINE SECURE DEVICE PROVISIONING WITH UPDATED OFFLINE IDENTITY DATA GENERATION AND OFFLINE DEVICE BINDING
    • 在线安全设备提供更新的离线身份数据生成和离线设备绑定
    • WO2011130713A1
    • 2011-10-20
    • PCT/US2011/032789
    • 2011-04-15
    • GENERAL INSTRUMENT CORPORATIONQIU, XinMEDVINSKY, AlexanderMOSKOVICS, Stuart, P.NAKANISHI, Greg, N.PASION, Jason, A.WANG, FanYAO, Ting
    • QIU, XinMEDVINSKY, AlexanderMOSKOVICS, Stuart, P.NAKANISHI, Greg, N.PASION, Jason, A.WANG, FanYAO, Ting
    • H04L9/08H04L29/06
    • H04L63/062H04L9/006H04L9/0825H04L9/0866H04L9/0891H04L63/0823
    • A system for generating new identity data for network-enabled devices includes a whitelist reader configured to extract attributes from a whitelist. The whitelist includes, for each device specified in the whitelist, a previously assigned identifier of the first type. The previously assigned identifiers of the first type are linked to identity data previously provisioned in each of the respective devices. A data retrieval module is configured to receive the identifiers of the first type from the whitelist reader and, based on each of the identifiers, retrieve each of the previously provisioned identity data records linked thereto. A new data generation module is configured to (i) obtain a cryptographic key associated with the identity data previously provisioned in the devices specified on the whitelist and the corresponding identifiers of the first type, (ii) generate new identity data records each linked to a new identifier and (iii) encrypt each of the new identity data records with one of the cryptographic keys and link each new identity data record to the identifier of the first type corresponding to each respective cryptographic key. A data output module is configured to load onto an external source the encrypted new identity data records along with their respective new identifiers and their respective previously assigned identifiers of the first type.
    • 用于为启用网络的设备生成新的身份数据的系统包括被配置为从白名单中提取属性的白名单阅读器。 对于白名单中指定的每个设备,白名单包括先前分配的第一类型的标识符。 先前分配的第一类型的标识符被链接到先前在每个相应设备中提供的标识数据。 数据检索模块被配置为从白名单读取器接收第一类型的标识符,并且基于每个标识符检索与之相关联的之前提供的标识数据记录中的每一个。 新的数据生成模块被配置为(i)获得与先前在白名单上指定的设备中提供的身份数据和第一类型的相应标识符相关联的加密密钥,(ii)生成新的身份数据记录,每个连接到 新的标识符和(iii)使用密码密钥之一加密每个新的身份数据记录,并将每个新的身份数据记录链接到与每个相应密码密钥对应的第一类型的标识符。 数据输出模块被配置为将加密的新身份数据记录及其各自的新标识符及其各自先前分配的第一类型的标识符加载到外部源上。
    • 8. 发明申请
    • CROSS-DOMAIN IDENTITY MANAGEMENT FOR A WHITELIST-BASED ONLINE SECURE DEVICE PRIVISIONING FRAMEWORK
    • 基于列表的在线安全设备专用框架的跨域标识管理
    • WO2011130711A2
    • 2011-10-20
    • PCT/US2011/032787
    • 2011-04-15
    • GENERAL INSTRUMENT CORPORATIONQIU, XinYAO, Ting
    • QIU, XinYAO, Ting
    • H04L29/06
    • H04L63/08H04L63/10
    • A method for managing identifiers associated with network-enabled devices and used in an identity data system provisioning the network-enabled devices with identity data includes receiving a first set data that includes a previously assigned identifier for one or more of the network-enabled devices that are authorized to be provisioned with new identity data. If identity data is currently installed on the one or more network-enabled devices, each of the previously assigned identifiers in the first set of data is associated with a corresponding identifier linked to the identity data currently installed on the one or more network-enabled devices to establish a second set of data. New identity data is bound to each of the one or more network-enabled devices by assigning a new identifier linked with the new identity data to each of the one or more network-enabled devices to establish a whitelist. The whitelist specifies, for each of the one or more network-enabled devices, its previously assigned identifier, its corresponding identifier and its new identifier that is linked with the new identity data.
    • 一种用于管理与启用网络的设备相关联并在身份数据系统中配置具有身份数据的启用网络的设备的标识符的方法包括:接收第一组数据,该第一组数据包括先前分配的一个或多个网络使能设备的标识符, 被授权提供新的身份数据。 如果身份数据当前安装在一个或多个启用网络的设备上,则第一组数据中先前分配的标识符中的每一个都与与当前安装在一个或多个启用网络的设备上的身份数据链接的对应标识符相关联 建立第二组数据。 通过将与新的身份数据链接的新标识符分配给一个或多个启用网络的设备中的每一个来建立白名单,将新的身份数据绑定到一个或多个网络启用设备中的每一个。 白名单为一个或多个网络启用设备中的每一个指定其先前分配的标识符,其对应的标识符及其与新的身份数据链接的新标识符。