Automated IoT Device Registration via Secure Provisioning Service

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional methods for provisioning Internet-of-Things (IoT) devices are inefficient and ineffective in scaling to meet the demands of billions of devices, requiring manual processes that are neither efficient nor effective for registration and access control.

Innovation Solution

An automated registration method using a secured provisioning service that verifies IoT device credentials, queries a rules registry for applicable rules, and dynamically provisions devices with connection credentials and a device ID, allowing for flexible and secure access to IoT platforms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual provisioning methods are used for IoT device registration, then security control and access management can be implemented, but the process becomes inefficient and cannot scale to meet the demands of billions of devices

Engineering Contradiction:
Improvedevice registration efficiencyVSAvoidmanual provisioning process
Core Design Contradiction:
ProductivityVSExtent of automation

Solution Approach 1:

The system enables self-service automation where IoT devices automatically register themselves with the network by transmitting device information and credentials without human intervention. The provisioning service automatically processes registration requests, verifies credentials, and provisions devices based on rules from the rules registry, eliminating the need for manual provisioning while maintaining security control.

Inventive Principle:
Principle #25Self-service

2Extent of automation

If automated registration is implemented to improve efficiency, then scalability to billions of devices is achieved, but security verification and access control may be compromised

Engineering Contradiction:
Improveautomated device registrationVSAvoidsecurity credential verification
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

The provisioning service acts as an intermediary between IoT devices and the network. It receives registration requests from devices, verifies their credentials against stored credentials, queries the rules registry for applicable security rules, and provisions devices according to those rules. This intermediary layer ensures that automated registration maintains security verification and access control while achieving scalability.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If dynamic rule-based provisioning is used to provide flexibility, then adaptability to changing requirements is improved, but system complexity increases

Engineering Contradiction:
Improveflexible access controlVSAvoidrules registry system
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system segments the provisioning logic into separate components: the provisioning service handles registration and credential verification, the rules registry stores and manages security rules, and the provisioning logic applies rules to specific devices. This segmentation allows dynamic rule-based provisioning with flexible adaptability while managing system complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11356440B2Automated IoT device registration
Publication Date: 2022.06.07 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11356440B2 patent drawing
  • US11356440B2 patent drawing
  • US11356440B2 patent drawing

AI summary

Automated registration of one or more IoT devices seeking connection to one or more IoT platforms using a secure provisioning service. The secured provisioning service verifies and administers connection credentials to each IoT device, ensuring legitimate devices cannot be impersonated or controlled by unauthorized personnel. The provisioning service matches the IoT devices and metadata of each IoT device to the provisioning rules. Connection credentials and/or rules defining each IoT device's access to IoT platforms are based on the provisioning rules of the rules registry. Matching each IoT device to one or more provisioning rules offers flexibility to dynamically add, delete or amend one or more rules in a complex rules-based system, allowing for automatic updates to the connection credentials of each IoT device, wherein each IoT device can be provisioned or re-provisioned using the most up to date set of new or amended rules.