Cloud Broker Mediates Device Enrollment Credentials

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud computing systems lack an efficient and secure mechanism for enrolling client computing devices, making them vulnerable to malicious access and control, which compromises system security and operation.

Innovation Solution

A method and system that utilize a trusted device to initiate enrollment of local devices with a cloud system through a secure communication process, involving authentication, credential generation, and provisioning, ensuring secure enrollment and operation within the cloud environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If cloud computing systems allow direct enrollment of client computing systems, then system functionality and ease of operation are improved, but system security and reliability deteriorate due to vulnerability to malicious access

Engineering Contradiction:
Improvedevice enrollment processVSAvoidsystem security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a cloud broker as an intermediary component that mediates between the cloud computing system and client computing systems during the enrollment process. The cloud broker receives enrollment requests, validates device identifiers, obtains credential information from the cloud system, and provisions credentials to client devices. This intermediary architecture enables secure enrollment by preventing direct unauthorized access to the cloud system while maintaining operational efficiency through automated credential management.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cloud computing systems implement secure enrollment mechanisms, then system security is improved, but device complexity and operational complexity increase

Engineering Contradiction:
Improvesystem securityVSAvoidenrollment system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service mechanisms where the cloud broker automatically performs credential validation, retrieval, and provisioning without requiring manual intervention. The system autonomously manages the enrollment process by automatically verifying device identifiers, obtaining credentials from the cloud computing system, and distributing them to client devices. This automation reduces operational complexity despite the enhanced security measures, as the system handles secure enrollment tasks independently without requiring complex manual security configurations.

Inventive Principle:
Principle #25Self-service

3Reliability

If cloud computing systems implement secure enrollment mechanisms, then system security is improved, but enrollment efficiency and processing time deteriorate

Engineering Contradiction:
Improvesystem securityVSAvoidenrollment efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary action by having the cloud broker pre-validate device identifiers and pre-obtain credential information before actual device enrollment occurs. The system performs preliminary security checks and credential retrieval in advance, so that when client devices need to enroll, the authentication process is already prepared and streamlined. This preliminary preparation maintains high enrollment efficiency while ensuring security requirements are met, as the computationally intensive validation and credential retrieval tasks are performed proactively rather than reactively during the enrollment moment.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10735966B2Cloud enrollment initiation via separate device
Publication Date: 2020.08.04 INNOVATEPRO MANAGEMENT USA LLC
  • US10735966B2 patent drawing
  • US10735966B2 patent drawing
  • US10735966B2 patent drawing

AI summary

Systems and methods for initiating enrollment of a local device in a cloud environment using a separate device are presented. In an example embodiment, a device identifier for the local device is received from the local device by a separate device that is trusted by a cloud computing system. The separate device causes the displaying of an indicator for the local device. In response to receiving an activation of the indicator for the local device, the separate device issues a request to the cloud computing system to receive credential information enabling the local device to enroll with the cloud computing system. The separate device receives the credential information from the cloud computing system and transmits the credential information to the local device.