Autonomic Network Device Enrollment via Cryptographic Token Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in securely configuring new devices to join autonomic networks without manual intervention, particularly in large or minimally administered entities, as they lack automatic configuration with robust security mechanisms and often rely on physical proximity or unsecured assumptions.

Innovation Solution

A system that enables unconfigured devices to securely join an autonomic network by using a registration server and a signing authority to create and validate authorization tokens, leveraging device credentials and audit histories to establish trust, allowing zero-touch, automated configuration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual configuration methods are used for new devices, then security can be maintained, but administrative burden increases significantly

Engineering Contradiction:
ImprovesecurityVSAvoidadministrative burden
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service through automated device enrollment where devices automatically generate cryptographic credentials and register with the network without manual configuration. The device autonomously completes the enrollment process by receiving configuration parameters from existing devices, eliminating the need for administrators to manually secure each device while maintaining security through cryptographic verification.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent applies preliminary action by pre-configuring devices with cryptographic credentials (such as public keys or certificates) before deployment. This allows devices to automatically authenticate and enroll in the network upon first connection without requiring manual security configuration, thus maintaining security while reducing administrative burden.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If automated configuration is implemented, then administrative burden is reduced, but security mechanisms become weaker

Engineering Contradiction:
Improveadministrative burdenVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary cryptographic verification mechanism where existing trusted devices mediate the enrollment of new devices. Instead of direct trust establishment, the system uses cryptographic signatures and verification of device credentials as an intermediary layer, allowing automated configuration while maintaining security through mathematical verification rather than physical proximity requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces mechanical security mechanisms (such as physical proximity requirements or manual configuration steps) with cryptographic verification systems. Devices use public key infrastructure and digital signatures to automatically verify identities and establish trust, substituting physical security measures with mathematical ones that enable automation without compromising security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If physical proximity requirements are enforced for device joining, then security is improved, but device complexity and deployment difficulty increase

Engineering Contradiction:
ImprovesecurityVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces mechanical proximity-based security with cryptographic verification mechanisms. Instead of requiring devices to be physically close for secure pairing, the system uses digital credentials and cryptographic signatures that can be verified remotely, eliminating the need for complex proximity management while maintaining security through mathematical verification.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS9774452B2System and method for enabling unconfigured devices to join an autonomic network in a secure manner
Publication Date: 2017.09.26 CISCO TECHNOLOGY INC
  • US9774452B2 patent drawing
  • US9774452B2 patent drawing
  • US9774452B2 patent drawing

AI summary

A method in an example embodiment includes creating an initial information package for a device attempting to join a network domain of a network environment; communicating the initial information package to a signing authority; sending an authorization token generated by the signing authority to the device, wherein the device validates the authorization token based on a credential in the device; and receiving an audit history report of the device, wherein the audit history report comprises information regarding previous attempts by the device to join the network environment. The method may also include applying a policy to the device based on the audit history report; generating a completed information package, wherein the completed information package includes an authorization token; applying a second signature to the completed information package; and sending the authorization token and the completed information package to the device, the device validating the second signature on the completed information package.