IoT Device Provisioning via DNS Delegation Records

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The manual provisioning process for Internet of Things (IoT) devices to perform service discovery is time-consuming, costly, complex, and cannot be scaled effectively to accommodate the anticipated increase in the number of IoT devices, making it impractical for large deployments.

Innovation Solution

A computer-implemented method that generates a search domain name based on a manufacturer and deployment environment domain names, searches the DNS for a delegation record, verifies the manufacturer signature, and configures the device with service discovery information to facilitate service discovery operations, using the DNS and DHCP protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual provisioning is used to ensure configuration integrity, then security and trustworthiness are improved, but time consumption and operational complexity increase significantly

Engineering Contradiction:
Improveconfiguration integrityVSAvoidprovisioning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-configuring IoT devices with service discovery configuration information in a secure manufacturing environment before deployment. This ensures configuration integrity is established in advance while eliminating the need for time-consuming manual provisioning at deployment time. The device retrieves and verifies configuration information automatically from a secure server during manufacturing, then uses it independently in the final network environment.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If manual provisioning is performed for each device, then configuration security is maintained, but scalability and productivity deteriorate

Engineering Contradiction:
Improveconfiguration securityVSAvoiddeployment efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements self-service by enabling IoT devices to automatically retrieve, verify, and configure service discovery information without manual intervention. Each device autonomously queries a secure server for its configuration information, validates digital signatures, and applies settings automatically. This eliminates manual provisioning operations while maintaining security through cryptographic verification, thereby achieving both scalability and productivity improvement.

Inventive Principle:
Principle #25Self-service

3Manufacturing precision

If manual provisioning is used, then configuration accuracy is ensured, but operational complexity and cost increase

Engineering Contradiction:
Improveconfiguration accuracyVSAvoidprovisioning complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The patent replaces the mechanical manual provisioning process with an automated digital system. Instead of physical manual configuration, the system uses digital communication protocols, cryptographic authentication, and automatic configuration mechanisms. The device communicates with a secure server over a network, retrieves signed configuration information, verifies digital signatures, and applies settings automatically. This substitution maintains configuration accuracy while dramatically reducing operational complexity and cost.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Adaptability or versatility

If devices are exposed to final network environment during configuration, then deployment flexibility is improved, but security risks increase

Engineering Contradiction:
Improvedeployment flexibilityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by completing all configuration operations in a secure manufacturing environment before the device reaches the final network. Service discovery configuration information is retrieved and verified while the device is still in a controlled, secure state during manufacturing. Once configured, the device deploys to the final network environment without exposing itself to security risks during the configuration process, maintaining both deployment flexibility and security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12137026B1Identifying trusted configuration information to perform service discovery
Publication Date: 2024.11.05 VERISIGN INC
  • US12137026B1 patent drawing
  • US12137026B1 patent drawing
  • US12137026B1 patent drawing

AI summary

In one embodiment, a delegation engine automatically provisions a device connected to a network to securely identify and interact with external services. As a device boots in a deployment environment, the delegation engine generates a search domain name based on a manufacturer-supplied domain name and a domain name associated with the deployment environment. The delegation engine then searches a Domain Name System (DNS) to retrieve a delegation record stored at the search domain name. After verifying a manufacturer signature associated with the delegation record, the delegation engine configures the device based on service discovery information included in the delegation record. Because the delegation engine automates the provisioning process, the time required to provision devices is acceptable irrespective of the number of the devices. Further, because the delegation engine verifies the delegation record, the delegation engine does not expose the device to security risks during the provisioning process.