Secure onboarding of a component in a network

US12536253B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12536253-B2
Application numberUS-202418625376-A
CountryUS
Kind codeB2
Filing dateApr 3, 2024
Priority dateApr 3, 2023
Publication dateJan 27, 2026
Grant dateJan 27, 2026

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method for providing a secure onboarding of a component from at least one first host device into a second host device includes verifying the integrity, authenticity and/or execution environment of the first host device by an orchestrator; providing a trusted root certificate to the second host device by the orchestrator; providing an onboarding identity by the orchestrator to the first host device, when the integrity, the authenticity and/or the execution environment of the first host device has been verified; receiving the onboarding identity from the orchestrator by the first host device and assigning the onboarding identity to the component; providing the assigned onboarding identity to the second host device; and securely onboarding the component from the first host device into the second host device based on the assigned onboarding identity and the provided trusted root certificate.

First claim

Opening claim text (preview).

What is claimed is: 1 . A method for providing a secure onboarding of a component from at least one first host device into a second host device, comprising: verifying an integrity, authenticity and/or execution environment of the at least one first host device including the component by at least one orchestrator; providing a trusted root certificate to the second host device by the at least one orchestrator; providing an onboarding identity by the at least one orchestrator to the at least one first host device, when the integrity, the authenticity and/or the execution environment of the at least one first host device has been verified; receiving the onboarding identity from the orchestrator by the at least one first host device and assigning the onboarding identity to the component by the at least one orchestrator; passing the assigned onboarding identity to the second host device by the at least one first host device; and securely onboarding the component from the at least one first host device into the second host device by the orchestrator device based on the assigned onboarding identity and the provided trusted root certificate. 2 . The method according to claim 1 , wherein the verifying of the integrity of the at least one first host device is provided by a remote attestation technique. 3 . The method according to claim 1 , wherein the verifying of the authenticity of the at least one first host device is provided by a security certificate. 4 . The method according to claim 1 , wherein the verifying of the execution environment of the at least one first host device is provided by a remote attestation technique. 5 . The method according to claim 1 , wherein the assigned onboarding identity comprises an unique key and a digital certificate being associated with the orchestrator. 6 . The method according to claim 5 , wherein the unique key is generated from the at least one first host device, solely when the onboarding identity from the orchestrator is received. 7 . The method according to claim 5 , wherein the digital certificate associated to the orchestrator is a DevID, IDevID or a LDevID certificate fulfilling a IEEE 802.1AR standard. 8 . The method according to claim 1 , wherein the trusted root certificate is a certificate provided by an orchestrator's certificate authority. 9 . The method according to claim 1 , wherein the trusted root certificate is a certificate provided by a root certificate authority. 10 . The method according to claim 1 , wherein the onboarding is provided by Feature Data Object, FDO, protocol, by Bootstrapping Remote Secure Key infrastructure, BRSKI, protocol, by Open Platform Communications, OPC 10000-21, protocol or by Secure Zero Touch Provisioning, SZTP, protocol. 11 . The method according to claim 1 , further comprising: identifying a shortage of resources in a first host device by the at least one orchestrator; identifying a second host device by the at least one orchestrator; providing a trusted root certificate to the second host device by the at least one orchestrator; executing a migration protocol between the orchestrator, the first host device and the second host device; wherein the migration protocol comprises: deleting the unique key and the trusted certificate associated with the orchestrator on the first host device, and generating a new assigned onboarding identity on the second host device; and securely onboarding the component from the first host device into the second host device based on the assigned onboarding identity and the provided trusted root certificate.

Assignees

Inventors

Classifications

  • using a third party · CPC title

  • Program or device authentication · CPC title

  • via third party · CPC title

  • Network security protocols · CPC title

  • based on the identity of the terminal or configuration, e.g. MAC address, hardware or software configuration or device fingerprint · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12536253B2 cover?
A method for providing a secure onboarding of a component from at least one first host device into a second host device includes verifying the integrity, authenticity and/or execution environment of the first host device by an orchestrator; providing a trusted root certificate to the second host device by the orchestrator; providing an onboarding identity by the orchestrator to the first host d…
Who is the assignee on this patent?
Abb Schweiz Ag
What technology area does this patent fall under?
Primary CPC classification G06F21/1084. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Jan 27 2026 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).