Endpoint Device Onboarding with Tags for Secure Customization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing onboarding processes for endpoint devices lack customization and security, particularly during the transition to secured operating modes, limiting the ability to manage endpoint devices effectively.
Innovation Solution
The use of tags that convey information to facilitate communication with a control plane for customized onboarding, involving a rendezvous system and cryptographically verifiable data structures to manage security and redirect devices to the control plane.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If endpoint devices operate in secured operating modes during onboarding, then security is improved, but the ability to customize onboarding processes deteriorates
Solution Approach 1:
The patent introduces a control plane as an intermediary between the endpoint device and the onboarding customization process. The control plane receives customization requests, processes them with cryptographic verification, and manages the onboarding workflow, allowing customization without compromising the secured operating mode of the endpoint device.
Solution Approach 2:
The onboarding process is segmented into distinct phases: initial secured mode operation, control plane interaction for customization, and final configuration. This segmentation allows the device to maintain security constraints while enabling customization through controlled interfaces at specific stages.
2Reliability
If a rendezvous system with cryptographic verification is implemented, then security is improved, but device complexity increases
Solution Approach 1:
The control plane serves as an intermediary that handles cryptographic verification and rendezvous system complexity, preventing these complex operations from being implemented directly in the endpoint device. This externalizes the computational burden and simplifies the device architecture.
Solution Approach 2:
The endpoint device is equipped with self-identifying tags that automatically provide necessary information to the rendezvous system and control plane, reducing the need for complex manual configuration and verification processes at the device level.
3Adaptability or versatility
If tags are used to convey device information, then onboarding customization is enabled, but information security requirements increase
Solution Approach 1:
The patent uses tags that contain copied or referenced information about the endpoint device, such as device identifiers and configuration parameters. These tags serve as lightweight copies that enable customization without requiring the device to store or process large amounts of sensitive information locally.
Data Source
AI summary
Methods and systems for managing onboarding of endpoint devices are disclosed. Customized onboarding processes may be performed depending on roles for different endpoint devices. During onboarding, the endpoint devices may operate in secure modes of operation which may limit customization of onboarding. To facilitate customization of onboarding, the endpoint device may include tags. The tags may convey information usable to operably connected to intermediary devices that may allow for operable connections to control planes that manage the onboarding processes to be established. The control planes may not be limited by the secure modes of operation and allow for greater customization of onboarding.


