Device Identity Provisioning via External Trust Authority

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital security systems for devices lack the ability to obtain and update identity data from external trust authorities, particularly in scenarios where digital certificates expire or need replacement, often requiring device recall for updates, which disrupts services and lacks secure encryption mechanisms.

Innovation Solution

A flexible identity data management system that allows device vendors and network operators to update identity data on devices before or after deployment by using a One Time Programmable Key (OTP Key) bound to a component identifier, enabling secure encryption and decryption of new identity data through an External Trust Authority, ensuring only authorized devices can access and install the updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If identity data is provisioned on devices before deployment in factory, then device security is established, but device recall is required for updates which disrupts service

Engineering Contradiction:
Improvedevice securityVSAvoidservice continuity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary actions by provisioning devices with cryptographic materials (OTP keys, component identifiers) and establishing update infrastructure before deployment. This allows seamless over-the-air updates without service disruption, as the device recall problem is preemptively solved by preparing the update mechanism in advance.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

An external trust authority acts as an intermediary between device vendors and deployed devices. This intermediary provides secure identity data and updates over-the-air, eliminating the need for physical device recall while maintaining security. The intermediary enables updates to be pushed remotely to deployed devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If identity data is updated after device deployment, then service continuity is maintained, but secure encryption mechanism is lacking

Engineering Contradiction:
Improveservice continuityVSAvoidencryption security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

Each device is provisioned with unique local cryptographic materials including OTP keys and component identifiers that are specific to that device. This local quality ensures that encryption security is device-specific and cannot be compromised by updates to other devices, maintaining security while enabling post-deployment updates.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

Cryptographic materials are preliminarily provisioned on devices before deployment, including OTP keys and component identifiers. This preliminary setup establishes a secure foundation that enables encrypted over-the-air updates later, combining the benefits of pre-deployment security with post-deployment update capability.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If external trust authority is used to provide identity data, then identity data freshness is improved, but device complexity increases

Engineering Contradiction:
Improveidentity data freshnessVSAvoidsystem architecture
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

An external trust authority serves as a centralized intermediary that manages identity data for multiple devices. This approach improves identity data freshness and adaptability while avoiding the need for each device to have complex self-management capabilities. The complexity is centralized in the trust authority rather than distributed to devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9160723B2Framework for provisioning devices with externally acquired component-based identity data
Publication Date: 2015.10.13 ARRIS ENTERPRISES LLC
  • US9160723B2 patent drawing
  • US9160723B2 patent drawing
  • US9160723B2 patent drawing

AI summary

A method is provided for updating identity data on devices. The method provides for acquiring a device comprising a component associated with a component identifier and having a One Time Programmable Key installed on the component, submitting the component identifier and the One Time Programmable Key to an External Trust Authority, receiving new identity data tied to the component identifier from the External Trust Authority that is encrypted with the One Time Programmable Key, loading the new identity data onto an Update Server, receiving a request at the Update Server from the device that requests new identity data, and providing the new identity data upon receipt of the request, upon which the device decrypts and installs the identity data using the One Time Programmable Key installed on the component within the device.