Dynamic IoT Onboarding via Environmental Credential Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current onboarding methods for wireless devices, such as mesh access points and IoT devices, rely on simple and insecure static information for network configuration, which is inadequate for modern enterprise or carrier deployments.

Innovation Solution

A method that dynamically generates credentials using a combination of static and dynamically generated information, including GPS data, reset button patterns, and environmental parameters, to secure the connection during the onboarding process, enhancing security by varying SSIDs and passwords for each installation attempt and location.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If static information (MAC address, etc.) is used for onboarding wireless devices, then the onboarding process is simple and easy to implement, but the security of the network connection is insufficient

Engineering Contradiction:
Improveonboarding process simplicityVSAvoidnetwork connection security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent transforms static onboarding credentials into dynamic ones by incorporating environmental parameters (GPS location, timestamp, device identifiers) that change with each installation attempt. This allows the system to maintain operational simplicity while significantly enhancing security, as each device receives unique credentials tailored to its specific installation context rather than reusable static credentials

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameters used for authentication from fixed static values (MAC address only) to dynamic composite values that include multiple variables such as GPS coordinates, timestamp, device serial number, and random identifiers. This parameter transformation enables both ease of operation through automated generation and improved security through uniqueness and unpredictability of each credential set

Inventive Principle:
Principle #35Parameter changes

2Reliability

If dynamic credentials are generated using multiple parameters, then the security of the onboarding process is significantly improved, but the complexity of the onboarding system increases

Engineering Contradiction:
Improveonboarding securityVSAvoidonboarding system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling the onboarding system to automatically generate, manage, and rotate credentials without requiring manual intervention for each credential creation. The system autonomously collects environmental parameters, generates unique credentials, and manages their lifecycle, thereby reducing operational complexity despite the enhanced security mechanisms in place

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent creates a universal onboarding framework that handles multiple functions through a single integrated system: credential generation, environmental parameter collection, security validation, and device registration. This multi-functional approach consolidates what could be separate complex systems into one cohesive process, managing complexity while delivering comprehensive security

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Object-affected harmful factors

If unique credentials are generated for each device installation, then the risk of brute-force attacks is reduced, but the time required for credential generation and verification increases

Engineering Contradiction:
Improvebrute-force attack riskVSAvoidcredential generation time
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-establishing the framework for dynamic credential generation during system initialization, including setting up the algorithms and parameter collection mechanisms in advance. This preparation enables rapid credential generation during actual onboarding operations, as the heavy computational and structural work has already been performed beforehand

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces manual or mechanical credential generation processes with automated computational systems that use algorithms to rapidly generate unique credentials based on environmental parameters. This substitution eliminates time-consuming manual steps while maintaining security, using computational efficiency to offset the increased complexity of dynamic credential management

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11611874B2Thincloud mesh access point (AP) and internet of things (IoT) device onboarding
Publication Date: 2023.03.21 CISCO TECHNOLOGY INC
  • US11611874B2 patent drawing
  • US11611874B2 patent drawing
  • US11611874B2 patent drawing

AI summary

A computing device determines an onboarding algorithm to use for onboarding a wireless device. The computing device determines, based on the onboarding algorithm, a first set of predefined information and a second set of dynamically generated information to use as inputs to the onboarding algorithm. The computing device generates, via the onboarding algorithm, a set of credentials based on the first set of predefined information and the second set of dynamically generated information, and uses the set of credentials to secure a connection for onboarding the wireless device.