US 11,671,246 B2
Data provisioning device for provisioning a data processing entity
Stephan Spitz, Karlsfeld (DE); and Haydn Povey, Cambridge (GB)
Assigned to Secure Thingz Limited, Cambridge (GB)
Filed by Secure Thingz Ltd., Cambridge (GB)
Filed on Oct. 29, 2020, as Appl. No. 17/83,785.
Claims priority of application No. 19206276 (EP), filed on Oct. 30, 2019.
Prior Publication US 2021/0135852 A1, May 6, 2021
Int. Cl. H04L 9/08 (2006.01); H04L 9/32 (2006.01); H04L 9/40 (2022.01)
CPC H04L 9/0819 (2013.01) [H04L 9/3263 (2013.01); H04L 63/0428 (2013.01); H04L 63/06 (2013.01); H04L 2209/60 (2013.01)] 14 Claims
OG exemplary drawing
 
1. A data provisioning device for provisioning a data processing entity from a set of data processing entities sharing the same joint decryption key, the data provisioning device comprising:
a network interface, the network interface being configured to receive the provisioning data for provisioning the data processing entity, a joint encryption key being associated with the joint decryption key, and control information, the control information indicating a processing scheme to be deployed by the data provisioning device when provisioning the data processing entity;
a processor being configured to process the provisioning data according to the control information to obtain processed provisioning data, to cryptographically encrypt the processed provisioning data using the received joint encryption key to obtain encrypted processed provisioning data; and
a device interface being configured to transmit the encrypted processed provisioning data to the data processing entity,
wherein the provisioning data comprises generic provisioning data intended for all data processing entities in the set of data processing entities, wherein the processor is configured to process the generic provisioning data for each individual data processing entity in the set of data processing entities in order to obtain individual processed data comprising data portions intended only for the data processing entity; and
wherein the data processing entity comprises an individual decryption key assigned only to the data processing entity, wherein the network interface is configured to further receive an individual encryption key associated with the individual decryption key of the data processing entity, and wherein the processor is further configured to encrypt the data portion using the individual encryption key prior to encrypting the provisioning data using the joint encryption key in order to process the provisioning data.