IoT Device Provisioning via Secure Element Pre-configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional IoT device manufacturing faces challenges in securely provisioning electronic devices due to complex cybersecurity requirements, high costs, and the need for sophisticated cybersecurity expertise, especially when devices are deployed in multiple ecosystems with different secure elements and certificate management.

Innovation Solution

A method for registering and provisioning IoT devices involves inserting a keypair into a secure element, requesting credentials from a server, verifying the device, registering it, and transmitting a device certificate for installation, allowing for pre-provisioning during manufacturing and simplified management of PKI infrastructure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional PKI infrastructure is used for IoT device provisioning, then security is improved, but device complexity and manufacturing cost increase

Engineering Contradiction:
ImprovesecurityVSAvoidprovisioning process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-provisioning devices with a root of trust and initial credentials during manufacturing before deployment. This allows devices to securely authenticate and obtain additional certificates from certificate authorities without requiring complex post-deployment provisioning procedures, thus maintaining security while simplifying the actual deployment process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses an intermediary approach by introducing a trusted service provider or certificate authority that mediates between the device manufacturer and the final deployment environment. This intermediary issues certificates and manages credentials, allowing devices to be provisioned securely without requiring manufacturers to implement complex PKI infrastructure themselves.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If PKI credentials are inserted at manufacturing level, then security is improved, but ease of manufacture deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidmanufacturing implementation difficulty
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent introduces an intermediary credential management system that simplifies manufacturing by handling the complex PKI operations externally. Instead of requiring manufacturers to directly implement certificate insertion and management, the system uses intermediaries (trusted service providers or online certificate authorities) that can issue credentials through simplified protocols, making manufacturing easier while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent enables self-service by allowing devices to automatically obtain and manage their own credentials after initial root of trust provisioning. Devices can autonomously authenticate with certificate authorities and retrieve necessary certificates without requiring manual intervention during manufacturing or deployment, reducing the burden on manufacturers while maintaining strong security.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If multiple secure elements are implemented in a single device, then adaptability is improved, but device complexity increases

Engineering Contradiction:
Improvecross-ecosystem deployment capabilityVSAvoidsecure element management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies universality by creating a unified root of trust architecture that can serve multiple ecosystems and purposes from a single secure element. Instead of requiring separate secure elements for different ecosystems, the system uses one secure element containing a universal root of trust that can authenticate across multiple environments, reducing device complexity while maintaining cross-ecosystem adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses preliminary action by pre-configuring the secure element with a universal root of trust certificate during manufacturing that is designed to work across multiple ecosystems. This preliminary configuration eliminates the need for multiple ecosystem-specific secure elements, as the single pre-configured root of trust can derive or authenticate multiple ecosystem credentials, simplifying device architecture while maintaining versatility.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If conventional certificate management is used, then security is improved, but loss of time in provisioning increases

Engineering Contradiction:
ImprovesecurityVSAvoidprovisioning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-provisioning devices with root of trust credentials during manufacturing before deployment. This allows devices to skip time-consuming certificate registration steps during actual deployment, as the root of trust is already established and can quickly authenticate with certificate authorities to obtain operational certificates, thus reducing provisioning time while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables self-service by allowing devices to automatically manage their own credential lifecycle after initial provisioning. Devices can autonomously authenticate, retrieve certificates, and renew credentials without requiring manual intervention or lengthy administrative processes, significantly reducing provisioning time while maintaining strong security through automated credential management.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11743029B1Provisioning systems and methods
Publication Date: 2023.08.29 CABLE TELEVISION LAB INC
  • US11743029B1 patent drawing
  • US11743029B1 patent drawing
  • US11743029B1 patent drawing

AI summary

A method for registering and provisioning an electronic device is provided. The method includes a step of inserting a first keypair into a secure element of the electronic device. The first keypair includes a public key and a private key. The method further includes a step of requesting, from a server configured to register and provision connected devices, a provisioning of credentials of the electronic device. The method further includes a step of verifying, by the server, the electronic device credentials. The method further includes a step of registering, by the server, the electronic device. The method further includes a step of transmitting, from the server to the electronic device, a device certificate. The method further includes steps of installing the transmitted device certificate within the secure element of the electronic device, and provisioning the electronic device according to the installed device certificate.