Method for bootstrapping and / or onboarding a device into an industrial network
Zero-knowledge proofs in device onboarding protocols address the issue of exposing device details by verifying device membership, enhancing privacy and security in zero-touch onboarding processes.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- SIEMENS AG
- Filing Date
- 2025-11-25
- Publication Date
- 2026-05-28
Smart Images

Figure EP2025084126_28052026_PF_FP_ABST
Abstract
Description
[0001] 202420993 Auslandsfassung
[0002] 1
[0003] Description
[0004] Method for bootstrapping and / or onboarding a device into an industrial network
[0005] The invention relates to a method for bootstrapping and / or onboarding a device into an industrial network and to a method for enabling bootstrapping and / or onboarding a device into an industrial network and to a registrar and to a device provider, particularly a device manufacturer, as trusted 3rdparty, i.e. , a manufacturer signing authority.
[0006] Privacy is becoming a standard design goal for more and more protocols, given the many scandals over breaches and authorized access to users’ data from big companies. This makes no exception to zero-touch onboarding solutions, which may expose sensitive data throughout the onboarding process. Specifically, in Voucher (IETF RFC 8366) based Zero-Touch Onboarding (ZTO) protocols like BRSKI, i. e.ETF RFC 8995 and further variants, which aim to deliver the necessary bootstrapping and / or onboarding information by exchanging signed objects, where a trusted third party from the manufacturer as the device provider is required to supply the device with the domain / customer site trust anchor, but also verify the identity of the new device, also referred to as pledge during the bootstrapping and / or onboarding process, for the operator / owner. This, however, would expose to the manufacturer the details of the operator / owner in the site deployment, such as which specific instance of the device has been onboarded and when and where. This would not allow the operator / owner to control its data about specific deployments. This invention provides a way for ZTO protocols / solutions to hide sensitive data, precisely the specific instance of a Pledge onboarded into a new and untrusted domain from the voucher request.
[0007] Thus, the present invention aims at providing an improved and / or enhanced method for bootstrapping and / or onboarding a device into an industrial network and an improved method for enabling bootstrapping and / or onboarding a device into an industrial network. Furthermore, the present invention aims at providing an improved and / or enhanced registrar service and an improved / enhanced device manufacturer service.
[0008] This aim of the invention is solved with a method for bootstrapping and / or onboarding a device into an industrial network according to claim 1 , with a method for enabling bootstrapping and / or onboarding a device, also referred to as pledge, into an industrial network according to claim 3 and with a registrar service according to claim 8 and with a device manufacturer service according to claim 9. 202420993 Auslandsfassung
[0009] 2
[0010] Advantageous aspects of the invention are described in the respective dependent claims, the subsequent description and the attached drawings.
[0011] The invention provides a method for bootstrapping and / or onboarding a device into an industrial network. In this method according to the invention, a bootstrapping and / or onboarding request is received from the device comprising a membership token, that allows to proof the membership of the device to a device group by a zero-knowledge proof, and the membership token is verified by a signing authority, e.g., manufacturer signing authority, using this zero-knowledge proof.
[0012] Preferably, this method according to the invention may be either directed to onboarding a device, wherein an onboarding request is received or the method may be a bootstrapping method, wherein a bootstrapping request is received. Alternatively and also preferred, the method may be a combined method for bootstrapping and onboarding, wherein a bootstrapping and onboarding request is received.
[0013] Preferably, the bootstrapping and / or onboarding request is granted, when the membership token is successfully verified.
[0014] In an advantageous aspect of the invention, the method described above may be carried out by a registrar service.
[0015] Furthermore, the invention provides a method for enabling bootstrapping and / or onboarding of a device into an industrial network. In this method according to the invention, the device is provided with a membership token, that allows to proof the membership of the device to a device group by a zero-knowledge proof and wherein a signing authority, e.g., manufacturer signing authority, is provided with information to verify the membership token.
[0016] Similarly, as stated above, also this method according to the invention may preferably either relate to onboarding or bootstrapping. Alternatively, the method according to the invention may preferably jointly involve onboarding and bootstrapping.
[0017] In a particularly advantageous aspect of the invention, the two methods according to the invention may be carried out combined, namely the method for enabling bootstrapping and / or onboarding of a device may be carried out first and the method for actually bootstrapping and / or 202420993 Auslandsfassung
[0018] 3 onboarding the device into an industrial network may be carried out subsequently, wherein identical terms refer to identical instances, such as the industrial network for which bootstrapping and / or onboarding of a device is provided is actually the very same industrial network, into which the mentioned device is onboarded.
[0019] The invention using zero-knowledge proofs can be used to provide privacy enhancements to device bootstrapping and / or onboarding processes and specifically to BRSKI. Using zeroknowledge proofs avoids the disclosure of pledge instance-specific data but still enables manufacturers to issue a voucher for bootstrapping and / or onboarding of a device of a specific product series. The concept also allows the provision of additional information like a last well- known software state for that product series. Considering this, the proposed enhancement with zero-knowledge proofs keeps the general security targets of zero-touch onboarding protocols such as BRSKI but provides a technical solution for enhanced privacy considerations.
[0020] In an advantageous and optional aspect of the invention, the bootstrapping and / or onboarding request may be verified as specified in a zero-touch onboarding protocol, particularly in BRSKI or in a variant of BRSKI protocol.
[0021] In an advantageous aspect of the invention, verifying the membership token may be carried out as specified in a zero-touch onboarding protocol, particularly in BRSKI or in a variant of BRSKI protocol, with verifying the membership token substituting verifying an identity of the device, particularly the verification of a product-serial-number.
[0022] Advantageously the methods according to the invention may be computer implemented.
[0023] In an advantageous aspect of the invention, the zero-knowledge proof is a cryptographic proof, particularly involving cryptographic accumulators as described e. g. in https: / / eprint.iacr.org / 2019 / 1255.pdf as of the date of filing this application.
[0024] The registrar or the registrar service according to the invention is configured to carry out the first method according to the invention for bootstrapping and / or onboarding a device into an industrial network.
[0025] The device provider or the device manufacturer service according to the invention is configured to carry out the second method according to the invention for enabling bootstrapping and / or 202420993 Auslandsfassung
[0026] 4 onboarding the device into an industrial network.
[0027] In the following, the invention is described in more details with the help of the attached figures.
[0028] Fig. 1 shows an industrial network IN with a registrar RE according to the invention and with a manufacturer authorized signing authority SA and a new device P according to the invention, that is to be bootstrapped and / or onboarded within the industrial network IN in a schematic drawing.
[0029] Fig. 2 shows the steps of the method according to the invention
[0030] The invention implements an onboarding protocol like BRSKI. In contrast, however, the communication of the registrar RE with the manufacturer authorized signing authority SA, the communication uses zero-knowledge proofs ZKP to hide device specific details in the registrar’s RE voucher request RVR. Thus, the manufacturer MA is only provided with information about a specific device type, but not with detailed information about a specific device.
[0031] The communication, thus representing a BRSKI communication using zero-knowledge proofs will proceed as follows:
[0032] The device P to be onboarded into the industrial network IN is a new device P and is conventionally also called pledge. The terms pledge and new device may be interchanged in throughout this application.
[0033] Prior to the onboarding, the new device Pgets imprinted by the manufacturer MA with proof of set membership during manufacturing alongside the I Devi D credentials IDevIDCreds. This proof represents a zero-knowledge proof and contains this proof in a data field inside a memory ME of the new device P and is called Membership Token MT in what follows. The Membership Token MT may be verified with membership verification information VI, which is updated with the generated membership token MT and sent to the manufacturer authorized signing authority SA.
[0034] For the actual onboarding process, the new device P sends in a first step 1 a Pledge-Voucher- Request PVR to the registrar RE. The device P includes the membership token MT inside the Pledge-Voucher-Request PVR, and aside from that, the Pledge-Voucher-Request PVR will be constructed as a normal Pledge-Voucher-Request PVR as known from the BRSKI protocol. 202420993 Auslandsfassung
[0035] 5
[0036] Upon reception and verification V of the Pledge-Voucher-Request PVR, the registrar RE will construct a Registrar-Voucher Request RVR in a second step 2 as it would typically do but include the membership token MT instead of the 'previously signed Pledge-Voucher-Request PVR. The registrar RE will then send the Registrar-Voucher Request RVR in a third step 3 to the manufacturer authorized signing authority SA. This way, the identity of the new device P will not be revealed to the manufacturer authorized signing authority SA, but the manufacturer authorized signing authority SA can still perform membership verification as part of the RVR verification V, i. e., the verification of the registrar issued RVR as well as the set membership of the device P based on the membership token MT.
[0037] Then, in a fourth step 4, the manufacturer authorized signing authority SA will verify the registrar’s RE Registrar-Voucher Request RVR as specified in the protocol BRSKI. However, it will perform the verification of the membership token MT as a substitution of the product-serial- number claim verification and the prior-signed-voucher-request claim verification. In BRSKI, in contrast, the Pledge-Voucher-Request PVR is included in the registrar’s RE Registrar-Voucher- Request RVR as the prior-signed-voucher-request claim. The verification V is performed with the membership verification information VI. As a result of a successful verification, the signing authority SA will issue a signed voucher SV and provide this information to the registrar RE, which provides it further to the device PL.
[0038] It is understood, that a similar method could be carried out in a further embodiment of the invention, that is not individually depicted and described, as a bootstrapping method. All onboarding steps may be substituted by bootstrapping steps. In further embodiments, which are not additionally depicted and described, a similar method could be carried out as a bootstrapping and onboarding method.
[0039] The steps of the method according to the invention are shown in Fig. 2.
Claims
202420993 Auslandsfassung6Claims1. Method for bootstrapping and / or onboarding a device (P) into an industrial network (IN), wherein an bootstrapping and / or onboarding request is received from the device comprising a membership token (MT), that allows to proof the membership of the device (P) to a device group by a zero-knowledge proof (ZKP), and wherein the membership token (MT) is verified by a signing authority using this zeroknowledge proof (ZKP).
2. Method according to claim 1, which is carried out by a registrar (RE).
3. Method for enabling bootstrapping and / or onboarding of a device (P) into an industrial network (IN), wherein the device (P) is provided with a membership token (MT), that allows to proof the membership of the device (P) to a device group by a zero-knowledge proof (ZKP) and wherein a signing authority (SA) is provided with a verification information (VI) to verify the membership token (MT).
4. Method according to one of the previous claims, wherein the bootstrapping and / or onboarding request (PVR) is verified (V) as specified in a zero-touch onboarding (ZTO) protocol, particularly in a BRSKI protocol.
5. Method according to one of the previous claims, wherein verifying (V) the membership token (MT) is carried out as specified in a BRSKI protocol, with verifying (V) the membership token (MT) substituting verifying (V) an identity of the device, particularly verification of a product- serial-number, in a zero-touch onboarding protocol, particularly in a BRSKI protocol.
6. Method according to one of the previous claims, which is computer implemented.
7. Method according to one of the previous claims, wherein the zero-knowledge proof is a cryptographic proof, particularly involving cryptographic accumulators.
8. Registrar Service or registrar, configured to carry out a method according to claim 1 or 2 and preferably to one of the claims 4 to 7.202420993 Auslandsfassung79. Device Manufacturer Service or device provider, configured to carry out the method according to claim 3 and preferably to one of the claims 4 to 7.
Citation Information
Patent Citations
Secure device onboarding techniques
US20200275273A1