Edge Manager Device Enrollment for Cloud Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial Internet of Things (IIoT) systems face challenges in predicting asset failures and delivering consistent early warnings, leading to unplanned downtimes, and existing authentication methods are inefficient for secure data access in cloud-based services.

Innovation Solution

The implementation of an edge manager device that facilitates device enrollment with cloud-based services using OAuth2 tokens, enabling secure data access and predictive maintenance by authenticating devices and managing authentication certificates, thereby improving operational intelligence and reducing downtime.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional authentication methods are used for device enrollment in cloud services, then security may be maintained, but authentication efficiency and ease of operation deteriorate

Engineering Contradiction:
Improveauthentication efficiencyVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements preliminary action by pre-configuring devices with authentication certificates and enrolling them with cloud services before they need to access data. The edge manager device automatically handles certificate installation, cloud service enrollment, and credential provisioning in advance, eliminating the need for manual authentication setup when devices first connect to the network. This preliminary enrollment process stores authentication credentials securely in device vaults, enabling efficient automatic authentication later without compromising security.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If manual device enrollment processes are used, then security control is maintained, but device complexity and time consumption increase

Engineering Contradiction:
Improveenrollment speedVSAvoidenrollment process complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling devices to automatically enroll with cloud services without manual intervention. When a device connects to the network, the edge manager device automatically detects it, provisions authentication credentials, installs certificates, and completes cloud service enrollment in the background. The device itself participates in the process by presenting its device ID and receiving credentials, but no manual configuration or user interaction is required, significantly reducing enrollment time and complexity while maintaining security control.

Inventive Principle:
Principle #25Self-service

3Reliability

If devices are enrolled without pre-configuration, then adaptability is improved, but reliability of authentication deteriorates

Engineering Contradiction:
Improveauthentication reliabilityVSAvoiddevice compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements the intermediary principle by introducing an edge manager device as a mediator between devices and cloud services. The edge manager acts as a trusted intermediary that automatically enrolls devices with cloud services, provisions authentication credentials, and manages certificate installation. This intermediary approach ensures that all devices, regardless of their native capabilities or protocols, receive standardized authentication credentials through the edge manager, maintaining authentication reliability while accommodating diverse device types and manufacturers.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10719071B2Device enrollment in a cloud service using an authenticated application
Publication Date: 2020.07.21 GENERAL ELECTRIC CO
  • US10719071B2 patent drawing
  • US10719071B2 patent drawing
  • US10719071B2 patent drawing

AI summary

Approaches for using a device-based authentication certificate to obtain data access to a cloud-based destination application are provided. Using an edge manager device, a token and data access request is received from a machine. The edge manager device is configured to administer data access to one or more cloud-based applications.