Decoupled Device Provisioning via State Containers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Establishing secure states for managed devices to join a centralized authority is cumbersome, requiring direct connection to the private network and is prone to failures due to transient network states, especially when dealing with large sets of devices.
Innovation Solution
A decoupled provisioning and configuration framework that packages arbitrary state information into a container, allowing managed devices to be provisioned and configured without active communication with the central authority, enabling secure connection over any network, including public networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If managed devices establish secure states by directly connecting to the centralized authority, then the state establishment is reliable, but the load on the centralized authority becomes heavy and network failures increase
Solution Approach 1:
The patent introduces a configuration framework as an intermediary between managed devices and the centralized authority. This framework caches state information locally on devices, allowing them to operate independently of continuous network connectivity to the authority, thereby reducing the authority's load while maintaining provisioning reliability
Solution Approach 2:
The system performs preliminary action by pre-establishing and caching state information (trust relationships, certificates, policies) before devices need to operate. This allows devices to be provisioned in advance with all necessary configuration data stored locally, eliminating the need for real-time communication with the centralized authority during device operation
2Ease of operation
If managed devices require active communication with the central authority for configuration, then the configuration is up-to-date, but the device must be running and connected which increases failure risk
Solution Approach 1:
The configuration framework acts as a local intermediary that stores configuration data independently of the centralized authority. This allows devices to access and apply configurations without requiring active network connections or running states, significantly improving provisioning reliability while maintaining configuration accessibility
Solution Approach 2:
The system creates local copies of configuration data and state information on managed devices. These copies allow devices to retrieve and apply configurations independently of the centralized authority, eliminating dependency on continuous network connectivity and improving overall system reliability
Data Source
AI summary
Described is a technology by which a target machine (managed device) is provisioned with arbitrary states for subsequent communication with a central authority, in which the configuration provisioning of the device is decoupled from the collection of the provisioning data. In a provisioning phase, arbitrary state information for provisioning the managed device is obtained and packaged in a container. In a configuration phase, the container is accessed, and the arbitrary state information is unpackaged to apply state to the managed device. The target machine thus may be provisioned with arbitrary states without actively communicating with the central authority.


