Cryptographic Device Authentication for Zero-Touch Onboarding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computing devices deployed at remote sites face challenges in obtaining network access for secure onboarding due to limited control over devices and networks, particularly in edge environments, where devices cannot operate on the network until authorized.

Innovation Solution

A system for authenticating computing devices using cryptographically attested digital documents, such as ownership vouchers, to verify device credentials and enable secure communication channels for zero-touch provisioning, leveraging Fast ID Online (FIDO) Device Onboarding (FDO) and Trusted Computing Group (TCG) protocols for secure boot and integrity measurement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If devices are deployed remotely to edge sites, then device deployment flexibility and coverage are improved, but network access control and security management deteriorate

Engineering Contradiction:
Improvedevice deployment flexibilityVSAvoidnetwork access control
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The system performs preliminary authentication by verifying cryptographically attested device credentials (such as TPM-based attestation) before granting network access. This preliminary verification ensures that only authorized devices can join the network, resolving the security management challenge while maintaining deployment flexibility.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

An onboarding system acts as an intermediary between remote devices and the network. This intermediary validates device credentials and mediates access control, enabling secure remote device integration without requiring direct manual configuration at the network side.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual authentication processes are used for device onboarding, then security verification is improved, but onboarding time and operational complexity deteriorate

Engineering Contradiction:
Improvesecurity verificationVSAvoidonboarding time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Devices perform self-authentication by presenting cryptographically attested credentials (such as FIDO-based device keys) to the onboarding system. This automated self-service mechanism eliminates manual authentication steps while maintaining strong security verification, significantly reducing onboarding time.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical authentication processes with cryptographic verification mechanisms. Instead of physical credential verification, the system uses digital signatures and cryptographic proof to validate device identity, achieving both high security and automation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If cryptographic authentication is implemented for secure onboarding, then device trustworthiness is improved, but system complexity and implementation difficulty deteriorate

Engineering Contradiction:
Improvedevice trustworthinessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The onboarding system implements a universal cryptographic authentication framework that handles multiple device types and credential formats (TPM, FIDO, certificates) through a single standardized interface. This multi-functional approach ensures device trustworthiness while abstracting away cryptographic complexity from individual implementation components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12452226B2Device authentication for onboarding
Publication Date: 2025.10.21 DELL PROD LP
  • US12452226B2 patent drawing
  • US12452226B2 patent drawing
  • US12452226B2 patent drawing

AI summary

An apparatus comprises at least one processing device configured to receive a cryptographically attested digital document from an onboarding management system, wherein the cryptographically attested digital document comprises one or more credentials for at least one device requesting access to a secure communication channel to communicate with the onboarding management system. The at least one processing device is further configured to verify whether the cryptographically attested digital document is valid, and identify the one or more credentials in response to verifying that the cryptographically attested digital document is valid. The one or more credentials are transmitted to at least one authenticator in response to a request from the at least one authenticator to authenticate the at least one device. The at least one device is given the access to the secure communication channel responsive to verification of the one or more credentials by the at least one authenticator.