IoT Device Onboarding via Approved Products List Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing IoT device onboarding processes lack sufficient information to assess the security, safety, and resiliency of IoT devices, as they only provide limited details such as device vendor, model, and version, which is insufficient for making informed decisions about network inclusion.

Innovation Solution

The implementation uses an Approved Products List (APL) and Platform Certificate to identify the building block configurations of IoT devices, allowing onboarding tools to verify compliance and compatibility by comparing the configuration used for conformance testing with the actual device configuration, and dynamically managing certification status through a blockchain.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional onboarding processes are used that only collect basic device information (vendor, model, version), then the onboarding process is simple and fast, but the security assessment and compliance verification are insufficient

Engineering Contradiction:
Improvesecurity assessment capabilityVSAvoidonboarding process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by requiring device configuration information to be registered and verified before the actual onboarding process. The onboarding tool retrieves expected configuration information from the APL in advance, and compares it with the actual device configuration during onboarding. This preliminary preparation ensures that security and compliance are verified before device inclusion, resolving the contradiction between thorough assessment and process simplicity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism - the APL (Approved Products List) and onboarding tool - that mediates between the device manufacturer and the IoT network. The APL stores pre-validated configuration information, and the onboarding tool acts as an intermediary to verify device compliance against this list. This intermediary layer enables comprehensive security verification without significantly complicating the end-user onboarding experience.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If detailed device configuration information is collected and verified during onboarding, then compliance and security are enhanced, but the onboarding time and processing overhead increase

Engineering Contradiction:
Improvecompliance verification accuracyVSAvoidonboarding time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent reduces onboarding time by performing configuration verification in advance. Device configuration information is registered and stored in the APL before the device needs to be onboarded. During the actual onboarding process, the onboarding tool simply retrieves the pre-stored expected configuration from the APL and compares it with the device's actual configuration, rather than performing complex verification from scratch. This preliminary action significantly reduces the time required during the critical onboarding moment.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses copying by storing copies of expected device configuration information in the APL. Instead of repeatedly accessing original configuration sources or performing complex real-time verification, the system creates and stores validated configuration copies in advance. The onboarding tool then compares device configurations against these pre-stored copies, enabling fast verification without sacrificing compliance accuracy.

Inventive Principle:
Principle #26Copying

3Reliability

If dynamic compliance status management is implemented using blockchain, then certification integrity and trust are improved, but the system complexity and implementation difficulty increase

Engineering Contradiction:
Improvecertification integrityVSAvoidsystem implementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple functions into the blockchain system: it serves as both a distributed ledger for storing APL information and a verification mechanism for compliance status. The blockchain integrates device configuration verification, certification status tracking, and integrity validation into a single unified system. This merging reduces overall system complexity by eliminating the need for separate verification systems and centralized authorities, as the blockchain inherently provides all necessary functions for ensuring certification integrity.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11683685B2Trusted IoT device configuration and onboarding
Publication Date: 2023.06.20 INTEL CORP
  • US11683685B2 patent drawing
  • US11683685B2 patent drawing
  • US11683685B2 patent drawing

AI summary

Various systems and methods for testing devices, issuing certificates, and managing certified devices, are discussed herein. A system is configured for using platform certificates to verify compliance and compatibility of a device when onboarding the device into an internet of things (IoT) network. The system may use an approved product list to verify compliance and compatibility for the device. When the device is certified, the system may use an onboarding tool to onboard the device into the IoT network.