IoT Device Provisioning via Shared Credentials and Intermediary Switchboard
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network-connected devices deployed in the field often lack the necessary credentials for secure software updates, making them vulnerable to malicious updates and tampering, as existing security measures require pre-deployment credentials for verification and authentication.
Innovation Solution
A method using a Globally Available Shared Provisioning Device (GASPD) with a secondary electronic apparatus to create device-specific credentials, allowing network-connected devices to securely join an IoT platform for updates, involving an intermediary OTA switchboard and authentication service to manage secure provisioning and identity creation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security measures require pre-deployment credentials for verification and authentication, then security is improved, but deployed devices without credentials become vulnerable to malicious updates
Solution Approach 1:
The patent applies preliminary action by pre-configuring devices with a provisioning application and basic credentials before deployment. This allows devices to perform self-provisioning operations after deployment without requiring pre-existing device-specific credentials, resolving the contradiction between security and provisioning capability.
Solution Approach 2:
The patent implements self-service through automated provisioning processes where devices can independently obtain credentials by interacting with provisioning servers. The provisioning application on the device automatically performs authentication, credential retrieval, and configuration without manual intervention, enabling deployed devices to secure themselves autonomously.
2Reliability
If device-specific credentials are generated and distributed before deployment, then security is improved, but the complexity of credential management increases
Solution Approach 1:
The patent introduces a provisioning server as an intermediary that manages credential generation and distribution. This centralizes credential management infrastructure, reducing the complexity burden on individual devices while maintaining security through server-side control of credential issuance and validation.
Solution Approach 2:
The patent uses copying by distributing a provisioning application template that can be deployed to multiple devices. This application template contains the logic for self-provisioning, allowing each device to generate its own credentials through automated processes rather than requiring complex pre-configured credential management on each device.
3Ease of operation
If updates are provided without verification, then ease of operation is improved, but malicious code may be introduced to devices
Solution Approach 1:
The patent implements feedback mechanisms where devices automatically verify update credentials against provisioning servers before applying updates. The provisioning application monitors the update process, validates cryptographic signatures, and provides feedback to ensure authenticity, maintaining ease of operation while preventing malicious code through automated verification loops.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method at a computing device for provisioning a network-connected device within a security platform, the method including receiving a first connection request, the first connection request being from an electronic apparatus and including a network-connected device identifier; authenticating the first connection request, thereby creating a first connection; receiving a second connection request, the second connection request being from the network-connected device and including the network-connected device identifier and a shared platform credential; receiving a request from the network-connected device to add the network-connected device to the security platform; and adding the network-connected device to the security platform based on a concurrent first connection and the request from the network-connected device to add the network-connected device to the security platform.