US2022230176A1PendingUtilityA1

System and method for downloading a payload to a network device

Assignee: TORONTO DOMINION BANKPriority: Nov 27, 2015Filed: Apr 7, 2022Published: Jul 21, 2022
Est. expiryNov 27, 2035(~9.3 yrs left)· nominal 20-yr term from priority
H04L 2463/102G07F 7/1025G06Q 20/3829H04L 63/0823G06Q 20/4012G06Q 20/027H04L 63/0853
59
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A network gateway includes a network interface and a computer processing unit. The network interface is configured to interface the network gateway with a first computer network. The computer processing unit is in communication with the network interface and is configured to receive from a network device, via the first computer network, a payload request that includes a first credential. The network device is configured to receive the first credential from a hardware token that is interfaced with the network device. The computer processing unit is configured to verify that, before the network device received the first credential from the hardware token, the first credential was associated with the network device in a database. The computer processing unit is configured to download a payload to the network device via the first computer network, after the verification.

Claims

exact text as granted — not AI-modified
1 . A network gateway comprising:
 a network interface configured to interface the network gateway with a first computer network; and   a computer processing unit in communication with the network interface and configured to:
 (i) receive from a network device, via the first computer network, a payload request including a first credential, the network device being configured to receive the first credential from a hardware token interfaced with the network device; 
 (ii) verify that, before the network device received the first credential from the hardware token, the first credential was associated with the network device in a database; and 
 (iii) after the verification, download a payload to the network device via the first computer network. 
   
     
     
         2 . The network gateway according to  claim 1 , wherein the payload request includes a second credential uniquely associated with the network device, and wherein the computer processing unit is configured to download the payload after verifying that, before the network device received the first credential from the hardware token, the first credential was associated with the second credential in the database. 
     
     
         3 . The network gateway according to  claim 1 , wherein the payload comprises a digital certificate authenticating the network device to a second computer network distinct from the first computer network, and the computer processing unit is configured to (i) receive a second credential from the network device and (ii) download the payload to the network device after confirming that the second computer network validated the first and second credentials. 
     
     
         4 . The network gateway according to  claim 1 , wherein the computer processing unit is configured to:
 provide the network device with a private cryptographic key;   receive an activation request from the network device;   verify that the activation request was generated from the private cryptographic key; and   download the payload to the network device after the verifying that the activation request was generated from the private cryptographic key.   
     
     
         5 . The network gateway according to  claim 4 , wherein the computer processing unit is configured to provide the network device with the private cryptographic key after verifying that, before the network device received the first credential from the hardware token, the first credential was associated with the network device in the database. 
     
     
         6 . The network gateway according to  claim 4 , wherein the payload request includes a second credential uniquely associated with the network device, and the computer processing unit is configured to provide the network device with the private cryptographic key after verifying that, before the network device received the first credential from the hardware token, the first credential was associated with the second credential in the database. 
     
     
         7 . The network gateway according to  claim 6 , wherein the computer processing unit is configured to provide the network device with the private cryptographic key together with a second credential, and to download the payload to the network device after verifying that (i) the activation request was generated from the private cryptographic key and the second credential and (ii) before the network gateway provided the network device with the second credential, the private cryptographic key and the second credential were uniquely associated with the network device in the database. 
     
     
         8 . A method of downloading a payload to a network device, the method comprising:
 the network device receiving a first credential from a hardware token interfaced with the network device;   a computer server receiving a payload request from the network device via a first computer network, the payload request including the first credential;   the computer server verifying that, before the network device received the first credential from the hardware token, the first credential was associated with the network device in a database; and   after the verifying, the computer server downloading a payload to the network device via the first computer network.   
     
     
         9 . The method according to  claim 8 , wherein the payload request includes a second credential uniquely associated with the network device, and the downloading a payload comprises the computer server providing the network device with the payload after verifying that, before the network device received the first credential from the hardware token, the first credential was associated with the second credential in the database. 
     
     
         10 . The method according to  claim 8 , wherein the payload comprises a digital certificate authenticating the network device to a second computer network distinct from the first computer network, and the downloading a payload comprises the computer server (i) receiving a second credential from the network device, and (ii) confirming that the second computer network validated the first and second credentials. 
     
     
         11 . The method according to  claim 8 , wherein the downloading a payload comprises:
 the computer server providing the network device with a private cryptographic key;   the computer server receiving an activation request from the network device;   the computer server verifying that the activation request was generated from the private cryptographic key; and   the computer server providing the network device with the payload after the verifying that the activation request was generated from the private cryptographic key.   
     
     
         12 . The method according to  claim 11 , wherein the providing the network device with a private cryptographic key comprises the computer server downloading the private cryptographic key to the network device after the computer server verifying that, before the network device received the first credential from the hardware token, the first credential was associated with the network device in the database. 
     
     
         13 . The method according to  claim 11 , wherein the payload request includes a second credential uniquely associated with the network device, and the providing the network device with a private cryptographic key comprises the computer server downloading the private cryptographic key to the network device after the computer server verifying that, before the network device received the first credential from the hardware token, the first credential was associated with the second credential in the database. 
     
     
         14 . The method according to  claim 13 , wherein the downloading the private cryptographic key comprises the computer server providing the network device with the private cryptographic key and a second credential, and the providing the network device with the payload comprises the computer server downloading the payload to the network device after the computer server verifying that (i) the activation request was generated from the private cryptographic key and the second credential and (ii) before the computer server provided the network device with the second credential, the private cryptographic key and the second credential were uniquely associated with the network device in the database. 
     
     
         15 . A non-transitory computer-readable medium comprising computer processing instructions stored thereon, the computer processing instructions, when executed by a computer processing unit of a computer server causing the computer server to:
 receive from a network device, via a first computer network, a payload request including a first credential, the network device being configured to receive the first credential from a hardware token interfaced with the network device;   verify that, before the network device received the first credential from the hardware token, the first credential was associated with the network device in a database; and   after the verification, download a payload to the network device via the first computer network.   
     
     
         16 . The computer-readable medium according to  claim 15 , wherein the payload request includes a second credential uniquely associated with the network device, and wherein the computer processing instructions cause the computer server to download the payload after verifying that, before the network device received the first credential from the hardware token, the first credential was associated with the second credential in the database. 
     
     
         17 . The computer-readable medium according to  claim 15 , wherein the payload comprises a digital certificate authenticating the network device to a second computer network distinct from the first computer network, and the computer processing instructions cause the computer server to (i) receive a second credential from the network device and (ii) download the payload to the network device after confirming that the second computer network validated the first and second credentials. 
     
     
         18 . The computer-readable medium according to  claim 15 , wherein the computer processing instructions cause the computer server to:
 provide the network device with a private cryptographic key;   receive an activation request from the network device;   verify that the activation request was generated from the private cryptographic key; and   download the payload to the network device after the verifying that the activation request was generated from the private cryptographic key.   
     
     
         19 . The computer-readable medium according to  claim 18 , wherein the computer processing instructions cause the computer server to provide the private cryptographic key after verifying that, before the network device received the first credential from the hardware token, the first credential was associated with the network device in the database. 
     
     
         20 . The computer-readable medium according to  claim 18 , wherein the payload request includes a second credential uniquely associated with the network device, and the computer processing instructions cause the computer server to provide the network device with the private cryptographic key after verifying that, before the network device received the first credential from the hardware token, the first credential was associated with the second credential in the database.

Join the waitlist — get patent alerts

Track US2022230176A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.