Secure Device Onboarding via Pre-Provisioned Credentials
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current secure device onboarding processes face challenges in obtaining network access for computing devices, particularly in edge environments with limited control and varied operational parameters, where devices cannot operate on networks until authorized.
Innovation Solution
The implementation of a secure communication channel between computing devices and an onboarding system using zero touch provisioning, where devices receive credentials and authenticate through an authenticator to gain access, leveraging Fast ID Online (FIDO) Device Onboarding and TPM-based Integrity Measurement Architecture for secure boot and trust verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If devices are required to be authorized before obtaining network access, then network security is improved, but device onboarding complexity increases
Solution Approach 1:
The system performs preliminary actions by pre-provisioning devices with unique identifiers and cryptographic credentials during manufacturing. This allows devices to automatically authenticate and join networks without manual configuration, resolving the contradiction by maintaining security through pre-established trust relationships while eliminating onboarding complexity.
Solution Approach 2:
Devices are equipped with self-service capabilities including automatic network discovery, credential presentation, and authentication. The devices can independently obtain network access by presenting their pre-provisioned credentials to network controllers, thereby maintaining security while eliminating the need for manual authorization processes.
2Reliability
If manual device provisioning is performed, then device trustworthiness is improved, but provisioning time increases
Solution Approach 1:
Trust credentials and cryptographic keys are provisioned into devices during manufacturing before deployment. This preliminary action ensures device trustworthiness is established in advance, eliminating the need for time-consuming manual verification processes while maintaining security requirements.
Solution Approach 2:
The system uses cryptographic copying where a master key held by the manufacturer is used to generate and distribute device-specific credentials. This allows automated provisioning of trusted devices at scale, maintaining trustworthiness while dramatically reducing provisioning time compared to manual processes.
3Productivity
If automated onboarding is implemented, then provisioning efficiency is improved, but security requirements increase
Solution Approach 1:
The system replaces manual mechanical provisioning processes with automated cryptographic authentication. Devices automatically present cryptographic credentials and receive authentication decisions through machine-to-machine communication, achieving high provisioning efficiency while maintaining strong security through cryptographic verification.
Solution Approach 2:
Network controllers and authentication servers serve as intermediaries that automatically verify device credentials and manage authentication. This intermediary layer enables automated high-volume provisioning while maintaining security through centralized cryptographic verification, resolving the contradiction between automation efficiency and security requirements.
Data Source
AI summary
An apparatus comprises at least one processing device configured to receive one or more credentials for at least one device from an onboarding management system, and to receive a request from at least one authenticator to authenticate the at least one device in response to the at least one device requesting access to a secure communication channel to communicate with the onboarding management system. The at least one processing device is further configured to transmit the one or more credentials to the at least one authenticator in response to the request. The at least one device is given the access to the secure communication channel responsive to verification of the one or more credentials by the authenticator. The one or more credentials comprise one or more keys.


