Infrastructure Device Enrolment via Pre-provisioned Cryptographic Identity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for enrolling infrastructure devices, such as printers, into enterprise networks often rely on manual processes or insecure protocols due to the lack of pre-provisioned cryptographic identities, leading to security risks and difficulties in managing device ownership changes, especially in scenarios like Device-as-a-Service models.

Innovation Solution

The solution involves pre-provisioning devices with a cryptographic binding that includes a public/private key pair and a device identity, allowing for secure out-of-box authentication and enrollment, as well as the generation of proof-of-ownership certificates to manage ownership changes and secure communication channels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual input or pre-provisioned values are used for on-premises enrolment, then device enrollment can be completed, but security risks increase and automation is reduced

Engineering Contradiction:
ImprovesecurityVSAvoidmanual intervention required
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The device is pre-provisioned with a cryptographic identity (certificate and private key) during manufacturing, before deployment to the enterprise network. This preliminary action eliminates the need for manual security configuration during enrollment, allowing automated secure enrollment while maintaining high security standards. The pre-provisioned cryptographic identity enables the device to authenticate itself automatically to the device manager.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If devices are enrolled without pre-provisioned cryptographic identities, then enrollment process is simpler, but security parameters cannot be properly provisioned

Engineering Contradiction:
Improveenrollment process simplicityVSAvoidsecurity parameter provisioning
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

Cryptographic identities including certificates and private keys are pre-provisioned into devices during manufacturing. This allows devices to perform secure self-authentication during enrollment without requiring manual security configuration, thereby maintaining both ease of operation and proper security parameter provisioning.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The device uses its pre-provisioned cryptographic identity to autonomously authenticate itself to the device manager during enrollment. The device independently proves its identity through cryptographic verification without requiring manual intervention or external security configuration, achieving both simplicity and security.

Inventive Principle:
Principle #25Self-service

3Reliability

If manual enrollment processes are used, then security can be maintained, but productivity and enrollment speed decrease

Engineering Contradiction:
ImprovesecurityVSAvoidenrollment speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Security credentials are pre-configured during device manufacturing, enabling automated secure enrollment. The device can immediately authenticate itself to the device manager using pre-provisioned certificates, eliminating time-consuming manual security configuration steps while maintaining security integrity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The device autonomously performs security authentication using its pre-provisioned cryptographic identity. This self-service capability eliminates the need for manual security configuration by administrators, significantly accelerating enrollment speed while maintaining security through cryptographic verification.

Inventive Principle:
Principle #25Self-service

4Device complexity

If cryptographic identities are not pre-provisioned, then device complexity is reduced, but secure authentication cannot be achieved

Engineering Contradiction:
Improvecryptographic configurationVSAvoidauthentication security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

Cryptographic identities including private keys and certificates are pre-provisioned during device manufacturing. This preliminary configuration eliminates the need for complex cryptographic setup during deployment, reducing operational complexity while ensuring secure authentication capabilities are immediately available.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3850510B1Infrastructure device enrolment
Publication Date: 2023.12.27 HEWLETT PACKARD DEVELOPMENT COMPANY LP
  • EP3850510B1 patent drawingFigure 1~2
  • EP3850510B1 patent drawingFigure 3~4
  • EP3850510B1 patent drawingFigure 5

AI summary

According to aspects of the present disclosure, there is provided methods and devices for enrolling a device into a network, including a device comprising a secure storage comprising a device identifier and a public key, and a controller configured to: retrieve a proof-of-ownership certificate comprising a cryptographic binding between the device identifier and an owner identifier based on a secret key corresponding to the stored public key, authenticate the proof-of-ownership certificate based on the stored device identifier and public key, establish an authenticated communication channel with a device manager based on the authenticated proof-of-ownership certificate, and receive setup information from the device manager to enrol the device on the network.