Secure Device Onboarding via Pre-Provisioned Credentials

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current secure device onboarding processes face challenges in obtaining network access for computing devices, particularly in edge environments with limited control and varied operational parameters, where devices cannot operate on networks until authorized.

Innovation Solution

The implementation of a secure communication channel between computing devices and an onboarding system using zero touch provisioning, where devices receive credentials and authenticate through an authenticator to gain access, leveraging Fast ID Online (FIDO) Device Onboarding and TPM-based Integrity Measurement Architecture for secure boot and trust verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If devices are required to be authorized before obtaining network access, then network security is improved, but device onboarding complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice onboarding complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by pre-provisioning devices with unique identifiers and cryptographic credentials during manufacturing. This allows devices to automatically authenticate and join networks without manual configuration, resolving the contradiction by maintaining security through pre-established trust relationships while eliminating onboarding complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Devices are equipped with self-service capabilities including automatic network discovery, credential presentation, and authentication. The devices can independently obtain network access by presenting their pre-provisioned credentials to network controllers, thereby maintaining security while eliminating the need for manual authorization processes.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual device provisioning is performed, then device trustworthiness is improved, but provisioning time increases

Engineering Contradiction:
Improvedevice trustworthinessVSAvoidprovisioning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Trust credentials and cryptographic keys are provisioned into devices during manufacturing before deployment. This preliminary action ensures device trustworthiness is established in advance, eliminating the need for time-consuming manual verification processes while maintaining security requirements.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system uses cryptographic copying where a master key held by the manufacturer is used to generate and distribute device-specific credentials. This allows automated provisioning of trusted devices at scale, maintaining trustworthiness while dramatically reducing provisioning time compared to manual processes.

Inventive Principle:
Principle #26Copying

3Productivity

If automated onboarding is implemented, then provisioning efficiency is improved, but security requirements increase

Engineering Contradiction:
Improveprovisioning efficiencyVSAvoidsecurity requirements
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system replaces manual mechanical provisioning processes with automated cryptographic authentication. Devices automatically present cryptographic credentials and receive authentication decisions through machine-to-machine communication, achieving high provisioning efficiency while maintaining strong security through cryptographic verification.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

Network controllers and authentication servers serve as intermediaries that automatically verify device credentials and manage authentication. This intermediary layer enables automated high-volume provisioning while maintaining security through centralized cryptographic verification, resolving the contradiction between automation efficiency and security requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250023731A1Device onboarding on secure networks
Publication Date: 2025.01.16 DELL PROD LP
  • US20250023731A1 patent drawing
  • US20250023731A1 patent drawing
  • US20250023731A1 patent drawing

AI summary

An apparatus comprises at least one processing device configured to receive one or more credentials for at least one device from an onboarding management system, and to receive a request from at least one authenticator to authenticate the at least one device in response to the at least one device requesting access to a secure communication channel to communicate with the onboarding management system. The at least one processing device is further configured to transmit the one or more credentials to the at least one authenticator in response to the request. The at least one device is given the access to the secure communication channel responsive to verification of the one or more credentials by the authenticator. The one or more credentials comprise one or more keys.