Bootstrap Server Device Account Identifier Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing bootstrapping processes for IoT devices are insecure and logistically burdensome, as they require pre-provisioning of device account identifiers and trust certificates, which can lead to security flaws and logistical challenges, especially when devices are deployed without prior knowledge of their assigned accounts.

Innovation Solution

A method and system for securely provisioning device account identifiers to IoT devices post-manufacture using an enrolment process that involves a bootstrap server, OEM certificate, and enrolment identifier, ensuring only authorized devices can obtain credentials to access services, thereby enhancing security and simplifying the deployment process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If device account identifiers are pre-provisioned on devices during manufacture, then devices can authenticate with service servers, but security flaws and logistical challenges arise when devices are deployed without prior knowledge of their assigned accounts

Engineering Contradiction:
Improveauthentication securityVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies preliminary action by pre-provisioning trust certificates on devices during manufacture, but delaying the assignment of device account identifiers until post-manufacture enrollment. This allows devices to have authentication credentials ready before deployment, while the actual account binding is established later through a secure enrollment process where the device presents its certificate to obtain its account identifier, thus resolving both security and deployment flexibility requirements

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a bootstrap server as an intermediary between the device and the service server. The bootstrap server receives the device's certificate, verifies it, and provisions the device account identifier. This intermediary mechanism enables secure credential distribution without requiring direct pre-configuration between devices and service servers, addressing both security concerns and deployment simplicity

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If devices are deployed without pre-provisioned account identifiers, then deployment flexibility improves, but secure authentication becomes more difficult to implement

Engineering Contradiction:
Improvedeployment flexibilityVSAvoidauthentication security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-provisioning trust certificates on devices during manufacture, but delaying the assignment of device account identifiers until post-manufacture enrollment. This allows devices to have authentication credentials ready before deployment, while the actual account binding is established later through a secure enrollment process where the device presents its certificate to obtain its account identifier, thus resolving both security and deployment flexibility requirements

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables self-service by allowing devices to autonomously obtain their device account identifiers through the enrollment process. The device presents its pre-provisioned certificate to the bootstrap server, which automatically verifies and provisions the account identifier without human intervention. This self-service mechanism maintains high security while providing deployment flexibility

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11475134B2Bootstrapping a device
Publication Date: 2022.10.18 ARM LTD
  • US11475134B2 patent drawing
  • US11475134B2 patent drawing
  • US11475134B2 patent drawing

AI summary

A method of bootstrapping a device by a bootstrap server, the method comprising: receiving, at the bootstrap server from the device, bootstrap data to enable the bootstrap server to determine that the device is to be provisioned with a device account identifier; verifying, at the bootstrap server, that the device is eligible to obtain a device account identifier based on or in response to the bootstrap data; obtaining, at the bootstrap server, a device account identifier assigned to the device based on or in response to the determination that the device is eligible; provisioning, from the bootstrap server to the device, first credential data comprising the device account identifier assigned to the device.