IoT Credential Provisioning Hub Using Device Group Tokens
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing IoT device credential provisioning methods require earmarking at the beginning of the silicon production, limiting flexibility and scalability, especially for low-volume orders, and necessitate pre-specifying products for specific customers and cloud platforms.
Innovation Solution
A security device provisioning hub that uses a generic chip with a unique keypair injected at manufacture, allowing devices to connect to an IoT hub for service-specific credentials via a device group identification token, enabling flexible binding and authentication post-manufacture.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If credentials are injected in the factory or earmarked at the beginning of the supply chain, then device authentication trust is established, but product flexibility and scalability are limited
Solution Approach 1:
The credential provisioning process is segmented into distinct phases: (1) Device manufacturer injects root credentials into security chips at factory, (2) Device vendor receives these credentials and issues device group identification tokens, (3) End customer devices receive service-specific credentials through the cloud platform. This segmentation allows each party to control credentials at appropriate stages without requiring pre-earmarked products.
Solution Approach 2:
The device group identification token acts as an intermediary between the device manufacturer and the end customer. It enables the cloud platform to bind devices to specific customers and services without requiring direct injection of service-specific credentials into devices at the factory level, thus maintaining flexibility while ensuring authentication trust.
2Reliability
If products are pre-customized for specific customers and cloud platforms, then authentication trust is ensured, but production scalability and cost efficiency are reduced
Solution Approach 1:
The device manufacturer performs preliminary action by injecting root credentials into security chips during factory production. These credentials enable devices to later obtain service-specific credentials through the cloud platform without requiring pre-customization for specific customers or services, thus maintaining scalability while ensuring authentication trust.
Solution Approach 2:
The system uses parameter changes in the form of device group identification tokens and service-specific credentials that can be dynamically assigned to devices. This allows the same hardware platform to be adapted to different customers and services by changing credential parameters rather than requiring physical reconfiguration or pre-customization.
3Reliability
If service-specific credentials are injected at the factory level, then authentication is secured, but device complexity and manufacturing cost increase
Solution Approach 1:
The patent extracts the service-specific credential injection step from the factory-level manufacturing process. Instead of injecting service-specific credentials at the factory, the system extracts this operation to the cloud platform level, where credentials are provisioned dynamically based on device group identification tokens and service requirements.
Solution Approach 2:
The system enables self-service credential provisioning where devices automatically receive service-specific credentials through the cloud platform without requiring manual intervention or complex factory-level configuration. The cloud platform automatically binds devices to services based on device group identification tokens.
Data Source
Figure 1
Figure 2
AI summary
A security device provisioning hub, including: a memory; and a processor configured to: receive a first secret token from a device manufacturer, wherein the first secret token is associated with a first service; receive a second secret token from a customer device having a security chip; verify that the first secret token and the second secret token are the same; and provide to the customer device access credentials to the first service .