Systems and methods for self and automated management of certificates in a network of moving things, for example including a network of autonomous vehicles

US10756909B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10756909-B2
Application numberUS-201715787933-A
CountryUS
Kind codeB2
Filing dateOct 19, 2017
Priority dateDec 6, 2016
Publication dateAug 25, 2020
Grant dateAug 25, 2020

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Communication network architectures, systems and methods for supporting a network of mobile nodes. As a non-limiting example, various aspects of this disclosure provide communication network architectures, systems, and methods for supporting a dynamically configurable communication network comprising a complex array of both static and moving communication nodes (e.g., the Internet of moving things). More specifically, systems and methods for self and automated management of certificates in a network of moving things that may include autonomous vehicles.

First claim

Opening claim text (preview).

What is claimed is: 1. A method of managing digital certificates in nodes of a wireless network comprising a plurality of nodes, the method comprising: receiving, at a first node of the plurality of nodes from a second node of the plurality of nodes, a notification comprising information identify one or more certificate revocation lists, wherein each certificate revocation list identifies one or more digital certificates that have been revoked, wherein each digital certificate prior to revocation authorizes access to a service supported by the wireless network, and wherein each certificate revocation list comprises a respective indication of one or both of a date and a time of expiration; adding to a list of certificate revocation lists maintained by the first node, the information identifying those of the one or more certificate revocation lists not already present on the list of certificate revocation lists; adjusting a time interval based on a number of nodes of the plurality of nodes within wireless communication range of the first node; periodically sending the list of certificate revocation lists to nodes of the plurality of nodes within wireless communication range of the first node, according to the time interval; rejecting a request from a third node of the plurality of nodes for access to a resource of the first node, based on a digital certificate of the third node and the digital certificates identified by the certificate revocation lists of the list of certificate revocation lists; discarding a certificate revocation list identified on the list of certificate revocation lists and removing the discarded certificate revocation list from the list of certificate revocation lists, according to the respective indication of expiration of each certification revocation list on the list of certificate revocation lists; and adjusting the time interval based on a number of certificate revocation lists on the list of certificate revocation lists. 2. The method according to claim 1 , wherein the method further comprises: receiving, from a certificate authority of the wireless network, an alert identifying a certificate revocation list identifying at least one revoked digital certificate. 3. The method according to claim 1 , wherein the plurality of nodes comprises one or more fixed nodes at respective fixed physical locations and one or more mobile nodes that are mobile within a service area of the wireless network. 4. The method according to claim 1 , wherein one or more nodes of the plurality of nodes comprise mobile access point functionality configured to provide radio frequency wireless Internet service by the wireless network to one or more end-user devices. 5. The method according to claim 1 , wherein one or more nodes of the plurality of nodes comprise interface functionality configured to communicate with a system of an autonomous vehicle. 6. A non-transitory computer-readable medium on which is stored a number of code sections, each code section comprising a plurality of instructions executable by one or more processors to cause the one or more processor to perform the steps of a method of managing digital certificates in nodes of a wireless network comprising a plurality of nodes, the steps of the method comprising: receiving, at a first node of the plurality of nodes from a second node of the plurality of nodes, a notification comprising information identify one or more certificate revocation lists, wherein each certificate revocation list identifies one or more digital certificates that have been revoked, wherein each digital certificate prior to revocation authorizes access to a service supported by the wireless network, and wherein each certificate revocation list comprises a respective indication of one or both of a date and a time of expiration; adding to a list of certificate revocation lists maintained by the first node, the information identifying those of the one or more certificate revocation lists not already present on the list of certificate revocation lists; adjusting a time interval based on a number of nodes of the plurality of nodes within wireless communication range of the first node; periodically sending the list of certificate revocation lists to nodes of the plurality of nodes within wireless communication range of the first node, according to the time interval; rejecting a request from a third node of the plurality of nodes for access to a resource of the first node, based on a digital certificate of the third node and the digital certificates identified by the certificate revocation lists of the list of certificate revocation lists; discarding a certificate revocation list identified on the list of certificate revocation lists and removing the discarded certificate revocation list from the list of certificate revocation lists, according to the respective indication of expiration of each certification revocation list on the list of certificate revocation lists; and adjusting the time interval based on a number of certificate revocation lists on the list of certificate revocation lists. 7. The non-transitory computer-readable medium according to claim 6 , wherein the steps of the method further comprise: receiving, from a certificate authority of the wireless network, an alert identifying a certificate revocation list identifying at least one revoked digital certificate. 8. The non-transitory computer-readable medium according to claim 6 , wherein the plurality of nodes comprises one or more fixed nodes at respective fixed physical locations and one or more mobile nodes that are mobile within a service area of the wireless network. 9. The non-transitory computer-readable medium according to claim 6 , wherein one or more nodes of the plurality of nodes comprise mobile access point functionality configured to provide radio frequency wireless Internet service by the wireless network to one or more end-user devices. 10. The non-transitory computer-readable medium according to claim 6 , wherein one or more nodes of the plurality of nodes comprise interface functionality configured to communicate with a system of an autonomous vehicle. 11. A system for managing digital certificates in nodes of a wireless network comprising a plurality of nodes, the system comprising: at a first node of the plurality of nodes, one or more processors operably coupled to storage for storing a list of certificate revocation lists and to one or more wireless communication interfaces for communication with other nodes of the plurality of nodes, the one or more processors operable to, at least: receive, at a first node of the plurality of nodes from a second node of the plurality of nodes, a notification comprising information identify one or more certificate revocation lists, wherein each certificate revocation list identifies one or more digital certificates that have been revoked, wherein each digital certificate prior to revocation authorizes access to a service supported by the wireless network, and wherein each certificate revocation list comprises a respective indication of one or both of a date and a time of expiration; add to a list of certificate revocation lists maintained by the first node, the information identifying those of the one or more certificate revocation lists not already present on the list of certificate revocation lists; adjust a time interval based on a number of nodes of the plurality of nodes within wireless communication range of the first node; periodically send the list of certificate revocation lists to nodes of the plurality of nodes within wireless communication range of the first node, according to the time interval; reject a request from a third

Assignees

Inventors

Classifications

  • Access control lists [ACL] · CPC title

  • for collecting sensor information · CPC title

  • using certificates (cryptographic mechanisms or cryptographic arrangements for entity authentication involving certificates H04L9/3263) · CPC title

  • H04L9/3268Primary

    using certificate validation, registration, distribution or revocation, e.g. certificate revocation list [CRL] · CPC title

  • for vehicles, e.g. vehicle-to-pedestrians [V2P] · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10756909B2 cover?
Communication network architectures, systems and methods for supporting a network of mobile nodes. As a non-limiting example, various aspects of this disclosure provide communication network architectures, systems, and methods for supporting a dynamically configurable communication network comprising a complex array of both static and moving communication nodes (e.g., the Internet of moving thi…
Who is the assignee on this patent?
Veniam Inc
What technology area does this patent fall under?
Primary CPC classification H04L9/3268. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Aug 25 2020 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 2 related publications on this page (citations in our corpus or others sharing the same primary CPC).