IoT Device Onboarding via Approved Products List Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing IoT device onboarding processes lack sufficient information to assess the security, safety, and resiliency of IoT devices, as they only provide limited details such as device vendor, model, and version, which is insufficient for making informed decisions about network inclusion.
Innovation Solution
The implementation uses an Approved Products List (APL) and Platform Certificate to identify the building block configurations of IoT devices, allowing onboarding tools to verify compliance and compatibility by comparing the configuration used for conformance testing with the actual device configuration, and dynamically managing certification status through a blockchain.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional onboarding processes are used that only collect basic device information (vendor, model, version), then the onboarding process is simple and fast, but the security assessment and compliance verification are insufficient
Solution Approach 1:
The patent implements preliminary action by requiring device configuration information to be registered and verified before the actual onboarding process. The onboarding tool retrieves expected configuration information from the APL in advance, and compares it with the actual device configuration during onboarding. This preliminary preparation ensures that security and compliance are verified before device inclusion, resolving the contradiction between thorough assessment and process simplicity.
Solution Approach 2:
The patent introduces an intermediary mechanism - the APL (Approved Products List) and onboarding tool - that mediates between the device manufacturer and the IoT network. The APL stores pre-validated configuration information, and the onboarding tool acts as an intermediary to verify device compliance against this list. This intermediary layer enables comprehensive security verification without significantly complicating the end-user onboarding experience.
2Reliability
If detailed device configuration information is collected and verified during onboarding, then compliance and security are enhanced, but the onboarding time and processing overhead increase
Solution Approach 1:
The patent reduces onboarding time by performing configuration verification in advance. Device configuration information is registered and stored in the APL before the device needs to be onboarded. During the actual onboarding process, the onboarding tool simply retrieves the pre-stored expected configuration from the APL and compares it with the device's actual configuration, rather than performing complex verification from scratch. This preliminary action significantly reduces the time required during the critical onboarding moment.
Solution Approach 2:
The patent uses copying by storing copies of expected device configuration information in the APL. Instead of repeatedly accessing original configuration sources or performing complex real-time verification, the system creates and stores validated configuration copies in advance. The onboarding tool then compares device configurations against these pre-stored copies, enabling fast verification without sacrificing compliance accuracy.
3Reliability
If dynamic compliance status management is implemented using blockchain, then certification integrity and trust are improved, but the system complexity and implementation difficulty increase
Solution Approach 1:
The patent merges multiple functions into the blockchain system: it serves as both a distributed ledger for storing APL information and a verification mechanism for compliance status. The blockchain integrates device configuration verification, certification status tracking, and integrity validation into a single unified system. This merging reduces overall system complexity by eliminating the need for separate verification systems and centralized authorities, as the blockchain inherently provides all necessary functions for ensuring certification integrity.
Data Source
AI summary
Various systems and methods for testing devices, issuing certificates, and managing certified devices, are discussed herein. A system is configured for using platform certificates to verify compliance and compatibility of a device when onboarding the device into an internet of things (IoT) network. The system may use an approved product list to verify compliance and compatibility for the device. When the device is certified, the system may use an onboarding tool to onboard the device into the IoT network.


