IoT Device Provisioning via DNSSEC Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing provisioning solutions for networked devices in M2M and IoT applications face security issues due to limited access control, lack of monitoring, and manual configuration, which can lead to unauthorized device activation and exposure of proprietary data during multi-tier deployment.

Innovation Solution

A secure cloud-based multi-tier provisioning method that uses a provisioning server to manage configuration parameters, enforce access controls, and establish authenticated connections between networked devices and data collection servers, utilizing DNSSEC for secure authentication and authorization, ensuring only authorized entities can access and configure devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual configuration and limited access control are used in provisioning, then device deployment is simplified, but security risks increase due to unauthorized device activation and exposure of proprietary data

Engineering Contradiction:
Improveprovisioning process simplicityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a provisioning server as an intermediary between devices and the network. This server acts as a trusted mediator that verifies device credentials, manages authentication, and controls access to proprietary data. The provisioning server implements security policies and authorization rules, enabling simplified device deployment while maintaining strong security controls through the intermediary's mediation of all provisioning operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multi-tier provisioning involving multiple entities is implemented, then device configuration and activation capabilities are enhanced, but security control and monitoring become more difficult

Engineering Contradiction:
Improveprovisioning flexibilityVSAvoidprovisioning system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the provisioning system into distinct functional components: a provisioning server that handles authentication and authorization, domain name servers that manage device identification, and individual devices that receive configuration. Each entity has clearly defined responsibilities and access rights. This segmentation allows multiple entities to participate in provisioning with enhanced capabilities while maintaining manageable complexity through modular architecture and centralized policy enforcement at the provisioning server.

Inventive Principle:
Principle #1Segmentation

3Reliability

If centralized provisioning management is implemented, then security control and access authorization are improved, but provisioning process time increases

Engineering Contradiction:
Improveaccess controlVSAvoidprovisioning duration
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-configuring devices with security credentials, authentication certificates, and authorization tokens before deployment. The provisioning server pre-establishes security policies, access control rules, and device permissions in advance. This preliminary configuration enables rapid device activation and provisioning while maintaining strong centralized security control, as the authentication and authorization frameworks are already in place and devices can be quickly integrated into the network without time-consuming security setup during deployment.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9762392B2System and method for trusted provisioning and authentication for networked devices in cloud-based IoT/M2M platforms
Publication Date: 2017.09.12 EUROTECH SPA
  • US9762392B2 patent drawing
  • US9762392B2 patent drawing
  • US9762392B2 patent drawing

AI summary

Systems and methods for trusted provisioning and authentication for networked devices in a cloud-based IoT/M2M platform is disclosed. In one embodiment, a fully qualified domain name and public key is registered in a domain name server for each networked device during device configuration. A network device establishes its trustworthiness to a data collection and processing server by providing credentials to the data collection and processing server. The data collection and processing server deduces the username, the device's fully qualified domain name, and encrypted password from the credentials. The domain name server is queried for the fully qualified domain name and the public key is returned. The encrypted password is decrypted using the public key and an attempt is made to verify the password. When the password is verified, the username is provided to the data collection and processing server to authorize a network connection between the networked device and the data collection and processing server.