Bootstrap Key Onboarding via Signed Vouchers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional technologies face challenges in establishing a secure trust relationship between devices and networks during the initial connection, particularly in verifying the correct network connection and proving device authenticity without pre-provisioning public keys, which is impractical and uneconomical.

Innovation Solution

The use of bootstrap keys (BSKs) within the bootstrapping remote secure key infrastructure (BRSKI) framework, where a manufacturer-authorized signing authority (MASA) issues signed vouchers to devices after verifying the registrar's knowledge of the device's authentication key, ensuring secure onboarding across various deployment models without relying on pre-provisioned keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If pre-provisioning public keys is used to establish trust relationship, then device authenticity verification is improved, but implementation cost and complexity increase significantly

Engineering Contradiction:
Improvedevice authenticity verificationVSAvoidimplementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a registrar as an intermediary entity that mediates the trust relationship between the device and network. Instead of direct pre-provisioning of public keys between device and network, the registrar verifies the device's authentication key and issues a signed voucher, acting as a trusted third party that simplifies the overall system complexity while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent uses a signed voucher as a copy or representation of the trust relationship. Rather than provisioning actual public keys, the system creates a verified copy (the voucher) that proves the device's authenticity. This voucher can be transmitted and validated without exposing the actual authentication keys, reducing complexity while preserving security.

Inventive Principle:
Principle #26Copying

2Reliability

If pre-provisioning public keys is used to establish trust relationship, then device authenticity verification is improved, but economic feasibility deteriorates

Engineering Contradiction:
Improvedevice authenticity verificationVSAvoideconomic feasibility
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The registrar serves as an economical intermediary that centralizes the verification process. Instead of each network needing to pre-provision keys for every device, the registrar performs verification once and issues reusable vouchers, significantly reducing the economic burden of key management while maintaining strong authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The signed voucher acts as a reusable copy of authentication proof. Once a device is verified by the registrar, the resulting voucher can be used multiple times without requiring repeated key provisioning, making the system economically feasible for large-scale device onboarding while maintaining security.

Inventive Principle:
Principle #26Copying

3Ease of operation

If conventional authentication methods are used, then network connection is established, but security against rogue networks deteriorates

Engineering Contradiction:
Improvenetwork connection establishmentVSAvoidsecurity against rogue networks
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent performs preliminary verification of the device's authentication key by the registrar before the device connects to the network. This preliminary action ensures that only authenticated devices receive signed vouchers, providing security against rogue networks while maintaining ease of operation during the actual connection process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The signed voucher provides feedback to the device about the authenticity of the network it should connect to. The device can verify the voucher's signature to confirm it is connecting to a legitimate network, creating a feedback mechanism that enhances security without complicating the connection process.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11601808B2Flexible device onboarding via bootstrap keys
Publication Date: 2023.03.07 CISCO TECHNOLOGY INC
  • US11601808B2 patent drawing
  • US11601808B2 patent drawing
  • US11601808B2 patent drawing

AI summary

This technology uses a bootstrap key (“BSK”) to securely onboard a computing device to a network. A unique BSK associated with an onboarding computing device is used to verify for various deployment models (1) that the computing device has proof the computing device is connecting to the correct wired or wireless network and (2) that the network has proof the computing device is trusted. The BSK may be an associated BSK or an embedded BSK. A computing device receives a signed voucher from the manufacturer authorized signing authority (“MASA”) before the computing device may onboard to a network. The MASA will issue a voucher to a Bootstrapping Remote Secure Key Infrastructure (“BRSKI”) registrar if the registrar proves knowledge of the computing device's BSK to the MASA or the registrar has an established trust relationship with the MASA.