IoT Credential Provisioning Hub Using Device Group Tokens

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing IoT device credential provisioning methods require earmarking at the beginning of the silicon production, limiting flexibility and scalability, especially for low-volume orders, and necessitate pre-specifying products for specific customers and cloud platforms.

Innovation Solution

A security device provisioning hub that uses a generic chip with a unique keypair injected at manufacture, allowing devices to connect to an IoT hub for service-specific credentials via a device group identification token, enabling flexible binding and authentication post-manufacture.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If credentials are injected in the factory or earmarked at the beginning of the supply chain, then device authentication trust is established, but product flexibility and scalability are limited

Engineering Contradiction:
Improvedevice authentication trustVSAvoidproduct flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The credential provisioning process is segmented into distinct phases: (1) Device manufacturer injects root credentials into security chips at factory, (2) Device vendor receives these credentials and issues device group identification tokens, (3) End customer devices receive service-specific credentials through the cloud platform. This segmentation allows each party to control credentials at appropriate stages without requiring pre-earmarked products.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The device group identification token acts as an intermediary between the device manufacturer and the end customer. It enables the cloud platform to bind devices to specific customers and services without requiring direct injection of service-specific credentials into devices at the factory level, thus maintaining flexibility while ensuring authentication trust.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If products are pre-customized for specific customers and cloud platforms, then authentication trust is ensured, but production scalability and cost efficiency are reduced

Engineering Contradiction:
Improveauthentication trustVSAvoidproduction scalability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The device manufacturer performs preliminary action by injecting root credentials into security chips during factory production. These credentials enable devices to later obtain service-specific credentials through the cloud platform without requiring pre-customization for specific customers or services, thus maintaining scalability while ensuring authentication trust.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system uses parameter changes in the form of device group identification tokens and service-specific credentials that can be dynamically assigned to devices. This allows the same hardware platform to be adapted to different customers and services by changing credential parameters rather than requiring physical reconfiguration or pre-customization.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If service-specific credentials are injected at the factory level, then authentication is secured, but device complexity and manufacturing cost increase

Engineering Contradiction:
Improveauthentication securityVSAvoidmanufacturing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the service-specific credential injection step from the factory-level manufacturing process. Instead of injecting service-specific credentials at the factory, the system extracts this operation to the cloud platform level, where credentials are provisioned dynamically based on device group identification tokens and service requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system enables self-service credential provisioning where devices automatically receive service-specific credentials through the cloud platform without requiring manual intervention or complex factory-level configuration. The cloud platform automatically binds devices to services based on device group identification tokens.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3709596B1Certificate provisioning and customer binding mechanisms using device group identification token
Publication Date: 2025.12.31 NXP BV
  • EP3709596B1 patent drawingFigure 1
  • EP3709596B1 patent drawingFigure 2

AI summary

A security device provisioning hub, including: a memory; and a processor configured to: receive a first secret token from a device manufacturer, wherein the first secret token is associated with a first service; receive a second secret token from a customer device having a security chip; verify that the first secret token and the second secret token are the same; and provide to the customer device access credentials to the first service .