IoT Gateway Onboarding via Mobile Relay
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing IoT device management systems face security risks and inefficiencies when administrators create and manage credentials for gateways, as it can be inconvenient and insecure for users to enter credentials each time a gateway is enrolled, and there is a risk of credential exposure.
Innovation Solution
A mobile device-based onboarding process securely enrolls gateways by using onboarding credentials to authenticate with the management service, concealing gateway credentials from users and allowing efficient multiple gateway enrollment, where an onboarding token is retrieved and used to create a gateway account, with credentials relayed to the gateway and stored temporarily on the client device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If administrators create and manage credentials for gateways manually, then security control is maintained, but the process becomes inefficient and credentials may be exposed to users
Solution Approach 1:
The patent introduces a management service as an intermediary between administrators and gateways. This service automatically generates credentials, enrolls gateways, and manages authentication without requiring administrators to manually handle credentials. The management service acts as a mediator that maintains security while improving enrollment efficiency through automation.
Solution Approach 2:
The gateway performs self-enrollment by automatically generating credentials and registering with the management service. This self-service mechanism eliminates the need for manual administrator intervention in credential management, thereby improving productivity while maintaining security through automated processes.
2Ease of operation
If administrators are considered end users for gateway authentication, then gateway enrollment is simplified, but security is compromised as administrators must know the credentials
Solution Approach 1:
The management service serves as an intermediary that handles authentication between gateways and the system. Instead of administrators directly knowing credentials, the management service manages credential verification, simplifying the enrollment process while maintaining security by preventing credential exposure to administrators.
Solution Approach 2:
The system uses token-based authentication where a temporary enrollment token is created for the enrollment process rather than using permanent administrator credentials. This copying mechanism allows simplified enrollment operations while protecting the security of actual authentication credentials.
3Productivity
If credentials are stored on the client device for multiple gateway enrollment, then enrollment efficiency improves, but the risk of credential exposure increases
Solution Approach 1:
The patent uses temporary enrollment tokens that are valid only for the enrollment process and are discarded afterward. These short-lived credentials enable efficient batch enrollment of multiple gateways without the long-term security risks associated with storing permanent credentials on client devices. The tokens are consumed during enrollment and cannot be reused.
Solution Approach 2:
The management service acts as an intermediary that securely manages credential distribution and validation. Instead of storing credentials locally on client devices, the system uses the management service to handle authentication, reducing the security risks of local credential storage while maintaining enrollment efficiency through automated credential management.
Data Source
AI summary
Disclosed are various examples for enrollment of gateways using a client device. In one example, a request is transmitted from a client device to a management service. The request comprises the gateway identifier. Gateway credentials are relayed through the client device from the management service to the gateway device. The gateway credentials are unexposed to users of the client device.


