Automatic Credential Provisioning for Cloud IoT Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for provisioning and re-provisioning authentication credentials for cloud platform access are impractical, especially for devices with hardcoded credentials or those installed in inaccessible locations, as they require manual intervention and are not scalable.

Innovation Solution

A system and method for automatic provisioning and re-provisioning of credentials using a provisioning server that communicates with devices to obtain sensor data and send authentication credentials, allowing devices to request and store credentials without user intervention, enabling secure and scalable onboarding and migration between cloud platforms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If credentials are manually provisioned by a system administrator during installation, then authentication credentials can be securely transferred to computer devices, but re-provisioning becomes impractical for large numbers of devices or devices that are not physically accessible

Engineering Contradiction:
Improvesecure credential transferVSAvoidre-provisioning practicality
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The computer device automatically requests and receives credential provisioning from a provisioning server without requiring manual administrator intervention. The device initiates the credential request, receives the credential automatically, and configures itself, enabling both initial provisioning and re-provisioning to be performed autonomously at scale.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

A provisioning server acts as an intermediary between the cloud platform and computer devices. The server receives credential requests from devices, obtains credentials from the cloud platform, and automatically delivers them to the requesting device, eliminating the need for manual administrator involvement in the credential transfer process.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of manufacture

If credentials are hardcoded to computer devices during manufacturing, then authentication credentials are pre-configured for cloud platform access, but re-provisioning becomes impossible when switching to a new cloud platform

Engineering Contradiction:
Improvepre-configured authenticationVSAvoidcloud platform switching capability
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The credential provisioning system transitions from a static hardcoded approach to a dynamic automated system. The computer device can dynamically request credentials from a provisioning server at any time, allowing credentials to be updated or changed without physical reconfiguration, thereby enabling cloud platform switching while maintaining manufacturing simplicity.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The computer device is pre-configured with the capability to automatically request credentials from a provisioning server during manufacturing, but the actual credential content is obtained automatically later. This preliminary setup of the request mechanism enables both easy manufacturing and future adaptability to different cloud platforms.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If manual credential provisioning is performed for each computer device, then authentication credentials can be customized for specific devices and locations, but the process becomes time-consuming and not scalable

Engineering Contradiction:
Improvedevice-specific credential customizationVSAvoidprovisioning speed
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

Each computer device automatically requests its own credentials from the provisioning server, eliminating the need for administrators to manually provision each device. This self-service approach maintains device-specific customization while dramatically increasing provisioning speed and scalability to large numbers of devices.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The provisioning server serves as an automated intermediary that handles credential requests from multiple devices simultaneously. It receives requests, obtains appropriate credentials from the cloud platform, and distributes them automatically, enabling customized credential provisioning at scale without administrator involvement.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11652811B2Automatic provisioning
Publication Date: 2023.05.16 SAP SE
  • US11652811B2 patent drawing
  • US11652811B2 patent drawing
  • US11652811B2 patent drawing

AI summary

The present disclosure pertains to provisioning of credentials, and in particular to provisioning of authentication credentials to a computer device for accessing a cloud platform computer system. The computer device obtains sensor data and sends a request including a device identifier to a provisioning server using a provisioning server network address. The computer device receives a response, from the provisioning server, including a platform credential and a platform server network address of a platform server. The computer device stores the platform credential. The computer device sends the sensor data and the platform credential to the platform server using the platform server network address.