Hosted Device Provisioning With Encrypted Credential Relay
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing device provisioning protocols, such as DPPv1.0, face challenges in securely and efficiently configuring devices with limited user interfaces, managing PKI key bootstrapping, ensuring secure communication through insecure initiators, selecting appropriate access points, and protecting responder bootstrap public keys, while supporting devices with potential for multiple provisioning instances.
Innovation Solution
A networked initiator system with a device database, DPP server, and discovery server facilitates secure device provisioning by managing PKI keys, enabling mutual authentication, selecting preferred networks, and encrypting credentials, using a combination of cryptographic algorithms and secure communication protocols to ensure secure and efficient device configuration.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If manual configuration methods are used to upload network access credentials to devices, then device provisioning can be performed, but the process becomes time-consuming and error-prone especially for devices with limited user interfaces
Solution Approach 1:
The device autonomously provisions itself by scanning QR codes or NFC tags that contain embedded credentials, eliminating the need for manual configuration through limited user interfaces. The device automatically extracts and applies network access credentials from the scanned data, enabling self-service provisioning that is both fast and error-free.
Solution Approach 2:
The patent replaces manual mechanical configuration operations with optical (QR code scanning) and electromagnetic (NFC) fields to transmit credentials. This substitution eliminates the need for users to manually type credentials through limited interfaces, thereby reducing provisioning time and errors.
2Extent of automation
If Device Provisioning Protocol v1.0 is implemented, then device configuration can be automated, but security vulnerabilities remain including exposure of responder bootstrap public keys and inability to securely reuse bootstrapping keys across multiple provisioning instances
Solution Approach 1:
The system pre-generates multiple unique credential sets and securely stores them in the device's secure element before provisioning. Each credential set is uniquely tied to a specific provisioning instance, preventing key reuse across multiple instances and eliminating the security vulnerability of exposing responder bootstrap public keys.
Solution Approach 2:
The patent segments the provisioning process into distinct cryptographic operations where each provisioning instance uses a dedicated key pair. The responder bootstrap public key is never exposed; instead, ephemeral key pairs are generated for each instance, isolating security contexts and preventing cross-instance key reuse attacks.
3Ease of operation
If credentials are transmitted through an initiator device, then device provisioning can be performed, but the credentials may be exposed if the initiator is compromised or insecure
Solution Approach 1:
The patent introduces a secure element or hardware security module as an intermediary that holds the credentials in isolation. The initiator device never actually possesses the credentials; instead, it facilitates the transfer of credential references or encrypted wrappers that can only be decrypted and applied by the target device's secure element, eliminating credential exposure risk even if the initiator is compromised.
Solution Approach 2:
The system accepts that initiator devices may be insecure but converts this potential harm into a benefit by designing a protocol where the initiator's insecurity is irrelevant. Credentials are transmitted in an encrypted format that requires the target device's private key for decryption, turning the initiator's lack of security into a non-issue since it never handles plaintext credentials.
4Adaptability or versatility
If multiple provisioning instances are supported, then device versatility is improved, but secure key management becomes more complex
Solution Approach 1:
The device pre-generates and securely stores multiple unique credential sets in its secure element during manufacturing or initial setup. Each credential set is tagged with a unique identifier corresponding to a specific provisioning instance. This preliminary preparation eliminates the need for complex runtime key management decisions, as the device simply selects the pre-configured credentials matching the current provisioning context.
Solution Approach 2:
The patent creates isolated cryptographic copies of credential material for each provisioning instance, stored separately in the secure element. Each copy is independently manageable and can be activated or deactivated without affecting other instances, simplifying key management through spatial and logical separation rather than complex hierarchical structures.
Data Source
AI summary
A network can operate a WiFi access point with credentials. An unconfigured device can (i) support a Device Provisioning Protocol (DPP), (ii) record responder bootstrap public and private keys, and (iii) be marked with a tag. The network can record initiator bootstrap public and private keys, as well as derived initiator ephemeral public and private keys. An initiator can (i) operate a DPP application, (ii) read the tag, (iii) establish a secure and mutually authenticated connection with the network, and (iv) send the network data within the tag. The network can record the responder bootstrap public key and derive an encryption key with the (i) recorded responder bootstrap public key and (ii) derived initiator ephemeral private key. The network can encrypt credentials using the derived encryption key and send the encrypted credentials to the initiator, which can forward the encrypted credentials to the device, thereby supporting a device configuration.


