Bootstrap Server Device Account Identifier Provisioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing bootstrapping processes for IoT devices are insecure and logistically burdensome, as they require pre-provisioning of device account identifiers and trust certificates, which can lead to security flaws and logistical challenges, especially when devices are deployed without prior knowledge of their assigned accounts.
Innovation Solution
A method and system for securely provisioning device account identifiers to IoT devices post-manufacture using an enrolment process that involves a bootstrap server, OEM certificate, and enrolment identifier, ensuring only authorized devices can obtain credentials to access services, thereby enhancing security and simplifying the deployment process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If device account identifiers are pre-provisioned on devices during manufacture, then devices can authenticate with service servers, but security flaws and logistical challenges arise when devices are deployed without prior knowledge of their assigned accounts
Solution Approach 1:
The patent applies preliminary action by pre-provisioning trust certificates on devices during manufacture, but delaying the assignment of device account identifiers until post-manufacture enrollment. This allows devices to have authentication credentials ready before deployment, while the actual account binding is established later through a secure enrollment process where the device presents its certificate to obtain its account identifier, thus resolving both security and deployment flexibility requirements
Solution Approach 2:
The patent introduces a bootstrap server as an intermediary between the device and the service server. The bootstrap server receives the device's certificate, verifies it, and provisions the device account identifier. This intermediary mechanism enables secure credential distribution without requiring direct pre-configuration between devices and service servers, addressing both security concerns and deployment simplicity
2Adaptability or versatility
If devices are deployed without pre-provisioned account identifiers, then deployment flexibility improves, but secure authentication becomes more difficult to implement
Solution Approach 1:
The patent applies preliminary action by pre-provisioning trust certificates on devices during manufacture, but delaying the assignment of device account identifiers until post-manufacture enrollment. This allows devices to have authentication credentials ready before deployment, while the actual account binding is established later through a secure enrollment process where the device presents its certificate to obtain its account identifier, thus resolving both security and deployment flexibility requirements
Solution Approach 2:
The patent enables self-service by allowing devices to autonomously obtain their device account identifiers through the enrollment process. The device presents its pre-provisioned certificate to the bootstrap server, which automatically verifies and provisions the account identifier without human intervention. This self-service mechanism maintains high security while providing deployment flexibility
Data Source
AI summary
A method of bootstrapping a device by a bootstrap server, the method comprising: receiving, at the bootstrap server from the device, bootstrap data to enable the bootstrap server to determine that the device is to be provisioned with a device account identifier; verifying, at the bootstrap server, that the device is eligible to obtain a device account identifier based on or in response to the bootstrap data; obtaining, at the bootstrap server, a device account identifier assigned to the device based on or in response to the determination that the device is eligible; provisioning, from the bootstrap server to the device, first credential data comprising the device account identifier assigned to the device.


