IoT Gateway Onboarding via Mobile Relay

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing IoT device management systems face security risks and inefficiencies when administrators create and manage credentials for gateways, as it can be inconvenient and insecure for users to enter credentials each time a gateway is enrolled, and there is a risk of credential exposure.

Innovation Solution

A mobile device-based onboarding process securely enrolls gateways by using onboarding credentials to authenticate with the management service, concealing gateway credentials from users and allowing efficient multiple gateway enrollment, where an onboarding token is retrieved and used to create a gateway account, with credentials relayed to the gateway and stored temporarily on the client device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If administrators create and manage credentials for gateways manually, then security control is maintained, but the process becomes inefficient and credentials may be exposed to users

Engineering Contradiction:
ImprovesecurityVSAvoidenrollment efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces a management service as an intermediary between administrators and gateways. This service automatically generates credentials, enrolls gateways, and manages authentication without requiring administrators to manually handle credentials. The management service acts as a mediator that maintains security while improving enrollment efficiency through automation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The gateway performs self-enrollment by automatically generating credentials and registering with the management service. This self-service mechanism eliminates the need for manual administrator intervention in credential management, thereby improving productivity while maintaining security through automated processes.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If administrators are considered end users for gateway authentication, then gateway enrollment is simplified, but security is compromised as administrators must know the credentials

Engineering Contradiction:
Improveenrollment simplicityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The management service serves as an intermediary that handles authentication between gateways and the system. Instead of administrators directly knowing credentials, the management service manages credential verification, simplifying the enrollment process while maintaining security by preventing credential exposure to administrators.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system uses token-based authentication where a temporary enrollment token is created for the enrollment process rather than using permanent administrator credentials. This copying mechanism allows simplified enrollment operations while protecting the security of actual authentication credentials.

Inventive Principle:
Principle #26Copying

3Productivity

If credentials are stored on the client device for multiple gateway enrollment, then enrollment efficiency improves, but the risk of credential exposure increases

Engineering Contradiction:
Improvebatch enrollment efficiencyVSAvoidcredential exposure risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent uses temporary enrollment tokens that are valid only for the enrollment process and are discarded afterward. These short-lived credentials enable efficient batch enrollment of multiple gateways without the long-term security risks associated with storing permanent credentials on client devices. The tokens are consumed during enrollment and cannot be reused.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The management service acts as an intermediary that securely manages credential distribution and validation. Instead of storing credentials locally on client devices, the system uses the management service to handle authentication, reducing the security risks of local credential storage while maintaining enrollment efficiency through automated credential management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11902268B2Secure gateway onboarding via mobile devices for internet of things device management
Publication Date: 2024.02.13 VMWARE INC
  • US11902268B2 patent drawing
  • US11902268B2 patent drawing
  • US11902268B2 patent drawing

AI summary

Disclosed are various examples for enrollment of gateways using a client device. In one example, a request is transmitted from a client device to a management service. The request comprises the gateway identifier. Gateway credentials are relayed through the client device from the management service to the gateway device. The gateway credentials are unexposed to users of the client device.