Endpoint Device Onboarding with Tags for Secure Customization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing onboarding processes for endpoint devices lack customization and security, particularly during the transition to secured operating modes, limiting the ability to manage endpoint devices effectively.

Innovation Solution

The use of tags that convey information to facilitate communication with a control plane for customized onboarding, involving a rendezvous system and cryptographically verifiable data structures to manage security and redirect devices to the control plane.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If endpoint devices operate in secured operating modes during onboarding, then security is improved, but the ability to customize onboarding processes deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidcustomization capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a control plane as an intermediary between the endpoint device and the onboarding customization process. The control plane receives customization requests, processes them with cryptographic verification, and manages the onboarding workflow, allowing customization without compromising the secured operating mode of the endpoint device.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The onboarding process is segmented into distinct phases: initial secured mode operation, control plane interaction for customization, and final configuration. This segmentation allows the device to maintain security constraints while enabling customization through controlled interfaces at specific stages.

Inventive Principle:
Principle #1Segmentation

2Reliability

If a rendezvous system with cryptographic verification is implemented, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The control plane serves as an intermediary that handles cryptographic verification and rendezvous system complexity, preventing these complex operations from being implemented directly in the endpoint device. This externalizes the computational burden and simplifies the device architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The endpoint device is equipped with self-identifying tags that automatically provide necessary information to the rendezvous system and control plane, reducing the need for complex manual configuration and verification processes at the device level.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If tags are used to convey device information, then onboarding customization is enabled, but information security requirements increase

Engineering Contradiction:
Improveonboarding customizationVSAvoidinformation management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent uses tags that contain copied or referenced information about the endpoint device, such as device identifiers and configuration parameters. These tags serve as lightweight copies that enable customization without requiring the device to store or process large amounts of sensitive information locally.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS12438770B2System and method for customization of onboarding process
Publication Date: 2025.10.07 DELL PROD LP
  • US12438770B2 patent drawing
  • US12438770B2 patent drawing
  • US12438770B2 patent drawing

AI summary

Methods and systems for managing onboarding of endpoint devices are disclosed. Customized onboarding processes may be performed depending on roles for different endpoint devices. During onboarding, the endpoint devices may operate in secure modes of operation which may limit customization of onboarding. To facilitate customization of onboarding, the endpoint device may include tags. The tags may convey information usable to operably connected to intermediary devices that may allow for operable connections to control planes that manage the onboarding processes to be established. The control planes may not be limited by the secure modes of operation and allow for greater customization of onboarding.