Central Provisioning Authority for IoT Security Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The exponential growth of IoT devices has led to a lack of a unified authority for securing and managing provisioning across disparate devices, making it difficult to create a ubiquitous secure environment, as conventional solutions like Active Directory and PKI were designed for human-device interactions and are not sustainable for IoT machines with custom provisioning bodies.

Innovation Solution

A central provisioning authority (CPA) is introduced to securely store and manage applications, keys, and certificates for devices, allowing automatic updates and re-provisioning, and providing a bridge for interoperability between IoT devices through a trusted connection, using a central repository and multi-factor authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional solutions like Active Directory and PKI are used, then human-device security management is achieved, but IoT device provisioning becomes unsustainable and complex

Engineering Contradiction:
Improvesecurity managementVSAvoidprovisioning complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a central provisioning authority (CPA) as an intermediary between IoT devices and existing security infrastructure. The CPA translates device provisioning requests into formats compatible with conventional systems like Active Directory and PKI, while managing device credentials, certificates, and security policies centrally. This mediator resolves the incompatibility between simple device provisioning needs and complex existing security systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The CPA is designed as a universal provisioning system that handles multiple device types (IoT devices, personal devices, enterprise devices) through a single interface. It provides multi-functional capabilities including device registration, credential issuance, certificate management, and security policy enforcement, replacing the need for multiple specialized provisioning systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If devices are replaced without a centralized system, then device mobility is maintained, but users must remember multiple provisioning bodies and applications

Engineering Contradiction:
Improvedevice replacement easeVSAvoidprovisioning information
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The CPA maintains centralized copies of all device provisioning information, including applications, credentials, certificates, and security policies. When a device is replaced, the system automatically retrieves and reproduces the necessary provisioning data from the central repository, eliminating the need for users to manually remember or transfer information between devices.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system performs preliminary provisioning by pre-configuring replacement devices with necessary credentials, certificates, and applications before actual device replacement occurs. The CPA anticipates device replacement scenarios and prepares provisioning packages in advance, so that when replacement is needed, the new device is already configured and ready for immediate deployment.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If IoT devices create custom provisioning bodies, then device autonomy is increased, but interoperability and unified security management decrease

Engineering Contradiction:
Improvedevice autonomyVSAvoidprovisioning landscape complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges custom device-specific provisioning bodies with a centralized provisioning authority. Devices maintain their autonomous provisioning capabilities while also registering with the CPA, which consolidates management of all provisioning bodies. This combination allows devices to operate independently while benefiting from unified security management and interoperability through the central authority.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10470014B2Central and security access control provisioning
Publication Date: 2019.11.05 INTEL CORP
  • US10470014B2 patent drawing
  • US10470014B2 patent drawing
  • US10470014B2 patent drawing

AI summary

Embodiments of systems, apparatuses and methods may provide for technology to provision data associated with a plurality of devices, detect a first machine-to-machine update request with respect to a first device in the plurality of devices, and automatically update at least a portion of the provisioned data in response to the first machine-to-machine update request. In one example, the provisioned data includes one or more of applications, encryption keys or digital certificates. Other embodiments are disclosed and claimed.