IoT Device Provisioning via Shared Credentials and Intermediary Switchboard

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network-connected devices deployed in the field often lack the necessary credentials for secure software updates, making them vulnerable to malicious updates and tampering, as existing security measures require pre-deployment credentials for verification and authentication.

Innovation Solution

A method using a Globally Available Shared Provisioning Device (GASPD) with a secondary electronic apparatus to create device-specific credentials, allowing network-connected devices to securely join an IoT platform for updates, involving an intermediary OTA switchboard and authentication service to manage secure provisioning and identity creation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security measures require pre-deployment credentials for verification and authentication, then security is improved, but deployed devices without credentials become vulnerable to malicious updates

Engineering Contradiction:
ImprovesecurityVSAvoidprovisioning capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies preliminary action by pre-configuring devices with a provisioning application and basic credentials before deployment. This allows devices to perform self-provisioning operations after deployment without requiring pre-existing device-specific credentials, resolving the contradiction between security and provisioning capability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements self-service through automated provisioning processes where devices can independently obtain credentials by interacting with provisioning servers. The provisioning application on the device automatically performs authentication, credential retrieval, and configuration without manual intervention, enabling deployed devices to secure themselves autonomously.

Inventive Principle:
Principle #25Self-service

2Reliability

If device-specific credentials are generated and distributed before deployment, then security is improved, but the complexity of credential management increases

Engineering Contradiction:
ImprovesecurityVSAvoidcredential management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a provisioning server as an intermediary that manages credential generation and distribution. This centralizes credential management infrastructure, reducing the complexity burden on individual devices while maintaining security through server-side control of credential issuance and validation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent uses copying by distributing a provisioning application template that can be deployed to multiple devices. This application template contains the logic for self-provisioning, allowing each device to generate its own credentials through automated processes rather than requiring complex pre-configured credential management on each device.

Inventive Principle:
Principle #26Copying

3Ease of operation

If updates are provided without verification, then ease of operation is improved, but malicious code may be introduced to devices

Engineering Contradiction:
Improveupdate deliveryVSAvoidmalicious code risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements feedback mechanisms where devices automatically verify update credentials against provisioning servers before applying updates. The provisioning application monitors the update process, validates cryptographic signatures, and provides feedback to ensure authenticity, maintaining ease of operation while preventing malicious code through automated verification loops.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3512227B1Method and system for securely provisioning a remote device
Publication Date: 2022.03.09 BLACKBERRY LTD
  • EP3512227B1 patent drawingFigure 1
  • EP3512227B1 patent drawingFigure 2
  • EP3512227B1 patent drawingFigure 3

AI summary

A method at a computing device for provisioning a network-connected device within a security platform, the method including receiving a first connection request, the first connection request being from an electronic apparatus and including a network-connected device identifier; authenticating the first connection request, thereby creating a first connection; receiving a second connection request, the second connection request being from the network-connected device and including the network-connected device identifier and a shared platform credential; receiving a request from the network-connected device to add the network-connected device to the security platform; and adding the network-connected device to the security platform based on a concurrent first connection and the request from the network-connected device to add the network-connected device to the security platform.