Configurator Key Package for DPP Interoperability
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current device provisioning protocols face challenges in efficiently sharing and managing configurator keys across multiple devices within a network, leading to complexity and reduced interoperability.
Innovation Solution
The protocol generates a configurator key package including a private signing key and public verification key, which is encrypted and stored for backup or shared among configurator devices, allowing secure decryption and use for configuring enrollee devices, utilizing bootstrapping techniques for trust establishment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If configurator keys are shared across multiple devices, then interoperability and ease of adding new devices is improved, but key management complexity and security risks increase
Solution Approach 1:
The patent creates a backup copy of the configurator key package and stores it in a separate location (such as a portable storage device or cloud storage). This copy can be used by additional configurator devices without requiring complex key sharing mechanisms. The backup copy serves as a simple replica that enables interoperability while avoiding the complexity of real-time key synchronization and management across multiple devices.
2Reliability
If configurator key package is encrypted and stored for backup, then security is improved, but ease of restoring and accessing keys is reduced
Solution Approach 1:
The patent performs preliminary encryption of the configurator key package before storing it in backup locations. By pre-encrypting the key package with appropriate encryption algorithms and storing it in secure formats, the system ensures that even if the backup storage is compromised, the keys remain protected. This preliminary security measure is designed to work seamlessly with automatic decryption protocols that occur during the restore process, minimizing user burden while maintaining high security standards.
3Productivity
If multiple configurator devices use shared keys, then device provisioning scalability is improved, but trust establishment complexity increases
Solution Approach 1:
The patent introduces a bootstrap device as an intermediary that facilitates trust establishment between multiple configurator devices and the network. The bootstrap device generates and distributes bootstrap keys that serve as a foundation for trust. When additional configurator devices need to be trusted, they can use the established bootstrap keys as a common reference point, avoiding the need for complex pairwise trust relationships between all configurator devices. This intermediary approach enables scalable trust establishment while maintaining security.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
This disclosure provides systems, methods, and apparatus, including computer programs encoded on computer storage media, for enhancing a device provisioning protocol (DPP) to support multiple configurators. In one aspect, a first configurator device can export a configurator key package. In one aspect, the configurator key package may be used for backup and restore of the configurator keys. The configurator key package may include a configurator private signing key and, optionally, a configurator public verification key. A second configurator device may obtain the configurator key package and also may obtain decryption information which can be used to decrypt the configurator key package. Thus, in another aspect, both the first configurator device and the second configurator device can use the same configurator keys with the device provisioning protocol to configure enrollees to a network.