IoT Onboarding via Standardized Bootstrapping Profiles

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Limited connectivity devices, such as IoT devices, face challenges in onboarding onto private LTE networks without a side channel like Wi-Fi or Bluetooth, and without a Mobile Network Operator (MNO) to provide a bootstrapping profile.

Innovation Solution

The implementation of a standardized bootstrapping profile that is not associated with any MNO, allowing limited access to private LTE networks for IoT devices. This involves an access point detecting a standardized identifier in a connection request from a wireless device, disabling authentication protocols, and limiting access to a provisioning server to obtain an operational profile.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional authentication protocols are used for device onboarding, then network security is maintained, but unprovisioned IoT devices cannot access the network to obtain profiles

Engineering Contradiction:
Improvedevice onboarding capabilityVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the network access process into two distinct phases: a bootstrapping phase for unprovisioned devices using standardized identifiers, and a normal operation phase for provisioned devices using authentication protocols. This segmentation allows unprovisioned IoT devices to access the network for profile download without requiring traditional authentication, while provisioned devices continue to use secure authentication, thus resolving the contradiction between ease of onboarding and network security.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If side channels like Wi-Fi or Bluetooth are used for bootstrapping, then device provisioning is enabled, but device complexity and additional hardware requirements increase

Engineering Contradiction:
Improveprovisioning capabilityVSAvoidhardware requirements
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements a universal bootstrapping mechanism using standardized identifiers that work across all LTE devices without requiring additional side channel hardware. The same cellular radio interface used for normal network communication is also used for bootstrapping unprovisioned devices, eliminating the need for separate Wi-Fi or Bluetooth modules and reducing device complexity while maintaining provisioning capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If standardized identifiers are used for bootstrapping, then access to provisioning server is enabled, but network access control is relaxed

Engineering Contradiction:
Improveaccess to provisioning serverVSAvoidaccess control mechanism
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-configuring unprovisioned devices with standardized identifiers before network access. These identifiers are predetermined and recognized by the network as indicating bootstrapping intent, allowing devices to automatically gain access to provisioning servers without complex real-time authentication or access control decisions, thereby simplifying the access control mechanism while enabling provisioning access.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12335731B2Onboarding wireless devices to private networks
Publication Date: 2025.06.17 CISCO TECHNOLOGY INC
  • US12335731B2 patent drawing
  • US12335731B2 patent drawing
  • US12335731B2 patent drawing

AI summary

A wireless device provides a connection request to an access point for a private network. The connection request includes a standardized identifier that corresponds to an unprovisioned wireless device. The connection response from the access point indicates that the wireless device is provided access to the private network only for communications with a provisioning server. The wireless device provides a provisioning request to the provisioning server and obtains a provisioning response that include an operational profile to enable access to the private network when the wireless device is configured according to the operational profile.