US 12,271,507 B2
Method and arrangement for exchanging a domain registrar for authenticating and configuring digital certificates
Oskar Camenzind, Steinen (CH)
Assigned to SIEMENS SCHWEIZ AG, Zurich (CH)
Appl. No. 17/911,338
Filed by Siemens Schweiz AG, Zürich (CH)
PCT Filed Feb. 16, 2021, PCT No. PCT/EP2021/053792
§ 371(c)(1), (2) Date Sep. 13, 2022,
PCT Pub. No. WO2021/185520, PCT Pub. Date Sep. 23, 2021.
Claims priority of application No. 10 2020 203 364.1 (DE), filed on Mar. 17, 2020.
Prior Publication US 2023/0131803 A1, Apr. 27, 2023
Int. Cl. H04L 9/40 (2022.01); G06F 21/44 (2013.01); G06F 21/64 (2013.01)
CPC G06F 21/64 (2013.01) [G06F 21/44 (2013.01)] 8 Claims
OG exemplary drawing
 
1. A method for exchanging a predecessor domain registrar for the authentication and configuration of digital certificates of Internet of Things (IoT) devices with a new domain registrar, wherein the predecessor domain registrar and the IoT devices of a technical installation are stored in a device register using blockchain technology, the method comprising:
determining by the predecessor domain registrar a number of nearby attestations needed, wherein the number is greater than one;
entering the new domain registrar into the device register;
gathering a set of nearby attestations of the respective IoT devices using the new domain registrar, wherein a respective nearby attestation is provided by a respective IoT device;
checking whether the new domain registrar fulfills the number of nearby attestations needed;
accepting the technical installation with the new domain registrar as authentication and configuration entity of digital certificates for the IoT devices of the technical installation;
sending voucher requests using the IoT devices to the new domain registrar;
forwarding the voucher requests from the new domain registrar to an authorization authority;
checking the authorization authority in the device register of whether the respective IoT device belongs to the new domain registrar; and
if the authorization authority establishes that the respective IoT device belongs to the new domain registrar, issuing a voucher for the respective IoT device using the authorization authority and sending the voucher to the respective IoT device.