Device Provisioning Service Zero-Touch Setup via Unique Codes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The complexity of configuring new electronic devices, especially those without human interfaces, poses challenges in setting up network connections securely, as they often require manual configuration and can expose networks to security risks due to unsecured communications.

Innovation Solution

A zero-touch setup (ZTS) process is implemented, where devices can automatically obtain network credentials by connecting to a secure server, using a device provisioning service (DPS) that authenticates both the device and the network, allowing seamless and secure provisioning without user interaction.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If devices are configured with security information manually, then security is improved, but device complexity and ease of operation deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-configuring devices with unique identification codes (such as QR codes or NFC tags) during manufacturing. These codes contain embedded security credentials and network information that enable automatic authentication and provisioning when the device is first activated, eliminating the need for manual security configuration by the end user.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary provisioning server that acts as a mediator between the new device and the network. The server receives the unique device code, authenticates the device, retrieves appropriate security credentials, and automatically provisions the device with network credentials and security certificates, thereby resolving the contradiction between security and ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If devices connect to networks without security credentials, then ease of operation is improved, but security deteriorates

Engineering Contradiction:
Improvesetup simplicityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements self-service by enabling devices to automatically obtain and configure their own security credentials without user intervention. When a device is activated, it autonomously presents its unique code to the provisioning server, receives authenticated security credentials, and configures itself to connect securely to the network, thereby maintaining both ease of operation and security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Security credentials are prepared in advance as unique codes on devices during manufacturing. This preliminary preparation allows the device to immediately authenticate and connect to secured networks upon activation without requiring real-time manual security configuration, thus maintaining operational simplicity while ensuring security.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If manual configuration processes are used, then security is improved, but productivity deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidprovisioning speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent replaces manual mechanical configuration processes with automated electronic provisioning. Instead of requiring users to manually input security credentials, configure network settings, and authenticate devices, the system uses automated electronic exchange of unique device codes (via QR scanning or NFC) and programmatic credential distribution, dramatically increasing provisioning speed while maintaining security through automated authentication protocols.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

All security credentials and network configuration data are prepared in advance as unique codes during device manufacturing. This preliminary action eliminates the need for time-consuming manual configuration during deployment, allowing devices to be rapidly provisioned automatically while maintaining security through pre-configured authenticated credentials.

Inventive Principle:
Principle #10Preliminary action

4Device complexity

If devices without human interfaces are used, then device complexity is reduced, but ease of operation deteriorates

Engineering Contradiction:
Improveinterface simplicityVSAvoidconfiguration ease
Core Design Contradiction:
Device complexityVSEase of operation

Solution Approach 1:

The patent introduces a smartphone application as an intermediary that bridges the gap between devices without human interfaces and the provisioning process. The app uses the device camera to scan QR codes or read NFC tags on the target device, extract the unique code, and automatically complete the provisioning process through the provisioning server, thereby maintaining interface simplicity while restoring ease of operation through the intermediary mobile application.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional mechanical interfaces (buttons, keyboards, displays) with contactless optical and electromagnetic communication methods. QR codes provide visual identification that can be scanned by cameras, and NFC tags enable contactless data exchange, eliminating the need for physical interaction with the device interface while maintaining ease of operation through familiar mobile phone technologies.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10547613B1Simplified association of devices with a network using unique codes on the devices and side channel communication
Publication Date: 2020.01.28 AMAZON TECH INC
  • US10547613B1 patent drawing
  • US10547613B1 patent drawing
  • US10547613B1 patent drawing

AI summary

A device provisioning service (DPS) fields requests from unprovisioned devices so that those unprovisioned devices can obtain network credentials or other data used in provisioning the unprovisioned device. The DPS can identify the device securely and associate with a known user account, or the user provisioning the device can supply network credentials over a side channel after supplying a provision code indicative of possession of the unprovisioned device. The provision code can be unique to the unprovisioned device or a short-sequence code that is not necessarily unique, but that is sufficiently uncommon that a specific short-sequence code would not likely be used more than once at a time. In order to communicate with the DPS, a provisioning device might connect the unprovisioned device and the DPS. If the provisioning device is a trusted device, it can perform some of the steps otherwise required by the DPS.