IoT Device Certificate Issuance via User-Code Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Issuing certificates for edge devices in IoT systems requires significant labor on the user side, complicating secure communication with application servers.

Innovation Solution

A communication system involving a communication device, terminal device, and certificate authority, where the device requests authorization and information, receives access tokens and codes, and issues certificates for secure communication with an application server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a certificate is issued to ensure security for communication between edge device and application server, then security is improved, but labor required on user side increases

Engineering Contradiction:
ImprovesecurityVSAvoiduser labor
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a certificate authority as an intermediary that automatically issues certificates. The edge device communicates with the certificate authority which verifies device information and issues certificates without requiring manual user intervention for each certificate issuance, thus maintaining security while reducing user labor

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The edge device is equipped with automatic certificate issuance functionality where it can request and receive certificates from the certificate authority autonomously. The device stores device information in advance and uses it to automatically obtain certificates, eliminating the need for manual user operation in the certificate issuance process

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250374050A1Communication system, terminal device, communication device, certificate authority, and method
Publication Date: 2025.12.04 KK TOSHIBA
  • US20250374050A1 patent drawing
  • US20250374050A1 patent drawing
  • US20250374050A1 patent drawing

AI summary

According to one embodiment, a communication device sends a device authorization request and device information to a certificate authority. The certificate authority sends access information, user code and a device code to the communication device. The communication device sends the access information and the user code to a terminal device. The terminal device requests issuance of an access token to the certificate authority based on the device information in association with the user code. The communication device sends the certificate signing request and the access token to the certificate authority. The certificate authority issues the certificate.