Over-the-Air Client Device Onboarding via Asymmetric Key Pair
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for onboarding devices to a key management infrastructure require physical staging and manual intervention, making them non-scalable for secure voice and data communications.
Innovation Solution
A process that generates an asymmetric key pair on the client device, obtains an access token from an identity management server, and uses this key pair to securely transmit and decrypt bootstrap information over-the-air from a key management server, eliminating the need for physical staging with key delivery devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If physical staging with key delivery devices is used, then secure key provisioning is achieved, but scalability and automation are reduced
Solution Approach 1:
The patent replaces the mechanical/physical staging process with cryptographic operations. Instead of physically connecting devices to key delivery devices, the system uses asymmetric cryptography where the client device generates its own key pair, and the key management server uses the public key to securely provision bootstrap information over-the-air. This substitution of mechanical processes with cryptographic ones enables both security and scalability.
Solution Approach 2:
The client device performs self-service by generating its own asymmetric key pair locally. The device does not require external physical intervention for key generation, and it can autonomously establish secure communication with the key management server using its public key. This self-service capability eliminates the need for manual staging and enables automated, scalable onboarding.
2Reliability
If physical staging with key delivery devices is used, then secure key provisioning is achieved, but manual intervention is required
Solution Approach 1:
The patent replaces the manual mechanical process of physical staging with automated cryptographic operations. The client device automatically generates its key pair, and the key management server automatically provisions bootstrap information using the public key. This eliminates the need for administrators to manually stage devices while maintaining security through cryptographic mechanisms.
Solution Approach 2:
The system enables automated self-service onboarding where the client device independently generates its asymmetric key pair and establishes secure communication with the key management server. The server automatically validates the public key and provisions bootstrap information without requiring manual administrator intervention,从而实现 scalable automated onboarding.
3Productivity
If over-the-air provisioning is implemented, then scalability is improved, but security during key transmission may be compromised
Solution Approach 1:
The client device performs preliminary action by generating its asymmetric key pair before any bootstrap information is transmitted. This pre-established cryptographic infrastructure (public-private key pair) is used to secure the subsequent over-the-air transmission of bootstrap information. The public key is made available in advance to the key management server, enabling secure transmission without requiring physical staging.
Solution Approach 2:
The patent substitutes physical secure transmission channels with cryptographic protection over public networks. Instead of requiring secure physical connections for key provisioning, the system uses asymmetric cryptography to protect over-the-air transmissions. The bootstrap information is encrypted or authenticated using the cryptographic key pair, enabling secure scalable provisioning over standard communication channels.
Data Source
AI summary
A system and process for onboarding client devices to a key management server. In operation, a device generates an asymmetric key pair including a public key and a private key. The device obtains an access token from an identity management server after successfully authenticating with the identity management server. The device transmits a request including the access token and the public key to the key management server to onboard the client device. The device receives a response including encrypted bootstrap information from the key management server. The bootstrap information included in the response is encrypted using the public key of the asymmetric key pair. The device decrypts the encrypted bootstrap information using the private key of the asymmetric key pair to obtain the bootstrap information and then uses the bootstrap information for encrypting communications transmitted to the key management server or for decrypting communications received from the key management server.


