Endpoint Onboarding with Proxy Certificates for Authority Delegation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing device onboarding systems face challenges in establishing authority over endpoint devices without proliferating cryptographic information, leading to security risks and complexity in managing large numbers of devices.

Innovation Solution

A framework that utilizes proxy certificates to extend cryptographic chains of delegation, allowing endpoint devices to verify authority without requiring orchestrators to have access to private keys, thereby reducing the risk of key compromise.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If orchestrators are given access to private keys to establish authority over endpoint devices, then onboarding can be performed, but key proliferation increases and security risks worsen

Engineering Contradiction:
Improveonboarding capabilityVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a proxy certificate as an intermediary mechanism that allows orchestrators to establish authority without accessing private keys. The proxy certificate acts as a mediator between the key holder and the orchestrator, enabling authority delegation while maintaining security. This resolves the contradiction by providing onboarding capability through the intermediary proxy certificate without requiring orchestrators to hold sensitive cryptographic material.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If private keys are distributed to multiple orchestrators, then authority can be established, but key proliferation increases

Engineering Contradiction:
Improveauthority establishmentVSAvoidkey proliferation
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent extracts the sensitive private key material from the onboarding process by using proxy certificates. Instead of distributing private keys to multiple orchestrators, the system extracts only the necessary authority delegation information into proxy certificates that can be shared without exposing the underlying private keys. This reduces key proliferation while maintaining the ability to establish authority across multiple orchestrators.

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of operation

If cryptographic information is made accessible to orchestrators, then onboarding can proceed, but the system becomes more vulnerable to compromises

Engineering Contradiction:
Improveonboarding processVSAvoidcompromise risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The proxy certificate serves as a protective intermediary that enables the onboarding process without exposing orchestrators to sensitive cryptographic information. The intermediary mechanism allows orchestrators to perform onboarding operations while the private keys remain protected with the original key holder, thereby reducing the system's vulnerability to compromises.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If proxy certificates are used to extend delegation chains, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddelegation chain
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses proxy certificates as copies that contain simplified delegation information. Instead of replicating the entire complex cryptographic delegation chain, the system creates copy-like proxy certificates that encapsulate the essential authority delegation information. This reduces the complexity burden on endpoint devices while maintaining security through the proxy certificate mechanism.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS12627511B2Device onboarding in distributed systems
Publication Date: 2026.05.12 DELL PROD LP
  • US12627511B2 patent drawing
  • US12627511B2 patent drawing
  • US12627511B2 patent drawing

AI summary

Methods and systems for managing endpoint devices are disclosed. The endpoint devices may be managed by onboarding them. To onboarding the endpoint devices, ownership vouchers and proxy certificates may be used to cryptographically verify to which entities authority over the endpoint devices have been delegated. The proxy certificates may extend certificate and/or delegation chains in ownership vouchers to other devices. The extended chains may eliminate the need for proliferation of keys used to demonstrate authority over endpoint devices.