Online Device Identity Provisioning Framework
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for updating identity data on network-enabled devices are cumbersome and require devices to be returned to a service center, especially when digital certificates expire or need to be replaced, leading to service disruptions and high operational costs.
Innovation Solution
A flexible identity management system that allows network operators to update or renew identity data, including PKI data, on deployed devices without recalling them, using a PKI/identity management system with sub-systems for generation and update, enabling secure and centralized management of identity data across multiple domains.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If identity data is provisioned manually at service centers, then security and authenticity are maintained, but device recall requirements cause service disruptions and high operational costs
Solution Approach 1:
The system enables devices to automatically request and receive identity data updates through the update server without requiring manual intervention at service centers. The automated workflow includes the device initiating an update request, receiving authentication, obtaining new identity data, and completing the update process independently, thereby eliminating service disruptions while maintaining security through controlled authentication mechanisms.
2Reliability
If identity data is updated manually through device recall, then security control is maintained, but operational costs and time consumption increase significantly
Solution Approach 1:
The system performs preliminary authentication and authorization actions before the actual identity data update. The update server maintains a whitelist of authorized devices and pre-establishes security credentials. When update requests are received, the authentication process is expedited because the preliminary security framework is already in place, enabling rapid secure updates without manual verification delays.
Solution Approach 2:
The patent replaces the mechanical process of physical device recall and manual updating with an electronic automated system. The update server communicates with devices through network connections, automatically authenticating devices against the whitelist, generating new identity data, and transmitting updates electronically. This substitution eliminates the time-consuming physical logistics of device recall while maintaining security through digital authentication mechanisms.
3Reliability
If large scale identity data updates are performed manually, then security can be monitored, but the process becomes cumbersome and requires extensive human resources
Solution Approach 1:
The update server performs multiple functions within a single centralized system: it maintains the whitelist of authorized devices, authenticates update requests, generates new identity data, manages the update process, and monitors security. This multi-functional approach consolidates what would otherwise require multiple separate manual processes and human resources into a single automated system that can handle large-scale updates efficiently while maintaining comprehensive security monitoring.
Solution Approach 2:
The system implements automated feedback mechanisms where the update server receives update requests from devices, processes them against the whitelist, and provides automated responses with new identity data or rejection reasons. The system continuously monitors the update process, tracking which devices have been updated and maintaining security logs. This automated feedback loop eliminates the need for manual tracking and monitoring while maintaining security oversight.
Data Source
Figure 1A
Figure 1B
Figure 2A
AI summary
A method for updating network-enabled devices with new identity data includes generating a plurality of new identity data records and loading the new identity data records onto an update server. A request is received at the update server for new identity data from at least one network-enabled device having a previously assigned identity linked to an identifier. The previously assigned identifier is linked to a new identifier that is linked to one of the new identity data records. One or more new identity data records are securely delivered to the network-enabled device.