IoT Device Zero-Touch Provisioning via Pre-Configured Credentials

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing IoT device provisioning methods require significant manual effort, including determining the correct cloud backend connection and updating firmware, which can be time-consuming and insecure, especially for devices sitting in warehouses for extended periods.

Innovation Solution

An automated process where IoT devices send identification information upon initial boot to a provisioning service, receive cryptographic information, and automatically connect to an appropriate IoT hub for configuration and firmware updates without user association, enabling zero-touch or low-touch provisioning across multiple hardware and OS combinations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual provisioning methods are used for IoT devices, then device configuration and firmware updates can be performed, but significant manual effort and time are required, and security is compromised

Engineering Contradiction:
ImprovesecurityVSAvoidprovisioning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-configuring devices with a provisioning service endpoint URL and cryptographic credentials during manufacturing. This allows devices to automatically authenticate and provision themselves when first powered on, eliminating the need for manual security configuration while maintaining strong security through pre-established cryptographic relationships between devices, provisioning services, and IoT hubs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements self-service by enabling IoT devices to autonomously perform provisioning operations including automatic authentication with the provisioning service, selection and connection to appropriate IoT hubs, and firmware updates without human intervention. The device uses its embedded credentials to self-verify and self-provision, dramatically reducing manual effort while maintaining security through automated cryptographic verification.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If automated provisioning is implemented, then manual labor is reduced and security is enhanced, but devices must store and manage cryptographic information securely

Engineering Contradiction:
Improveprovisioning operationVSAvoidcryptographic management
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-configuring devices with a provisioning service endpoint URL and cryptographic credentials during manufacturing. This allows devices to automatically authenticate and provision themselves when first powered on, eliminating the need for manual security configuration while maintaining strong security through pre-established cryptographic relationships between devices, provisioning services, and IoT hubs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The provisioning service acts as an intermediary that mediates between the IoT device and the IoT hub. It verifies the device's cryptographic credentials, authenticates the device, and facilitates secure connection to the appropriate IoT hub. This intermediary approach simplifies device complexity by offloading complex cryptographic verification and hub selection logic from the device to the cloud-based provisioning service.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If devices are provisioned manually, then cryptographic security can be maintained, but the process becomes time-consuming and labor-intensive

Engineering Contradiction:
Improveprovisioning throughputVSAvoidmanual configuration time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent implements self-service by enabling IoT devices to autonomously perform provisioning operations including automatic authentication with the provisioning service, selection and connection to appropriate IoT hubs, and firmware updates without human intervention. The device uses its embedded credentials to self-verify and self-provision, dramatically reducing manual effort while maintaining security through automated cryptographic verification.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent applies preliminary action by pre-configuring devices with a provisioning service endpoint URL and cryptographic credentials during manufacturing. This allows devices to automatically authenticate and provision themselves when first powered on, eliminating the need for manual security configuration while maintaining strong security through pre-established cryptographic relationships between devices, provisioning services, and IoT hubs.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3526713B1Automatic provisioning of IoT devices
Publication Date: 2021.12.01 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3526713B1 patent drawingFigure 1
  • EP3526713B1 patent drawingFigure 2
  • EP3526713B1 patent drawingFigure 3

AI summary

The disclosed technology is generally directed to IoT communications. For example, such technology is usable in provisioning IoT devices in an automatic manner with no manual steps. In one example of the technology, upon initial boot, identification information is automatically sent to a provisioning service endpoint stored in the IoT device. The identification information includes an identification (ID) of the first IoT device. Cryptographic information is received from the provisioning service. The cryptographic information is associated with an IoT hub selected from a plurality of IoT hubs based, in part, on the ID of the first IoT device. A message is automatically sent to the IoT hub in response to receiving the cryptographic information. A new configuration file and a firmware update are received from the IoT hub without requiring a user association. The new configuration file and the firmware update are automatically installed.