IoT Onboarding via Vendor Cloud Trust Extension

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IoT devices lack secure trust mechanisms, making it difficult for them to authenticate with cloud-based servers during the onboarding process, as they rely on upstream switches or routers for secure authentication, which are not directly accessible by cloud servers.

Innovation Solution

The proposed solution extends trust from secure trust mechanisms on upstream switches or routers to IoT devices by using a vendor cloud onboarding server to verify the connection of IoT devices to these switches or routers, leveraging hardware security modules like SUDI and ACT-2 chipsets for authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IoT devices rely on upstream switches or routers for secure authentication, then cloud servers can maintain security without implementing secure trust mechanisms on IoT devices, but cloud servers cannot directly access or verify the authentication status of these devices

Engineering Contradiction:
Improveauthentication securityVSAvoiddevice accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a vendor cloud onboarding server as an intermediary between the cloud server and upstream network devices. This mediator receives authentication data from switches or routers and provides verification services to the cloud server, enabling indirect access to authentication status without direct device access. The intermediary resolves the contradiction by maintaining security through trusted third-party verification while providing cloud servers with the ability to verify device authentication status.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If secure trust mechanisms are implemented on upstream switches or routers, then authentication reliability is improved, but the complexity of the onboarding system increases due to multiple verification components

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidonboarding system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the authentication verification functionality into the existing cloud-based onboarding infrastructure by integrating it with the vendor cloud onboarding server. Instead of creating separate complex verification systems, the solution combines multiple functions (authentication verification, device onboarding, and trust management) into a unified cloud-based process, reducing overall system complexity while maintaining high authentication reliability.

Inventive Principle:
Principle #5Merging (Combining)

3Speed

If cloud servers directly verify device identities, then authentication speed is improved, but security is compromised because IoT devices lack secure trust mechanisms

Engineering Contradiction:
Improveauthentication speedVSAvoidauthentication security
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent implements preliminary authentication actions by upstream switches or routers before devices connect to the cloud server. The network infrastructure pre- verifies device identities using secure trust mechanisms, and only authenticated devices are allowed to establish connections with cloud servers. This preliminary verification ensures both security and speed, as the actual cloud server authentication process becomes a formal verification of pre-established trust rather than a primary authentication challenge.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11528273B2Expended trust for onboarding
Publication Date: 2022.12.13 CISCO TECHNOLOGY INC
  • US11528273B2 patent drawing
  • US11528273B2 patent drawing
  • US11528273B2 patent drawing

AI summary

In one embodiment, an IoT server includes: processing circuitry, an I/O module operative to communicate with at least an IoT device and a vendor network server, and an onboarding application and operative to at least: receive an onboarding request from the IoT device via the I/O module, send a confirmation request to the vendor network server via the I/O module, where the confirmation request indicates a request to confirm an identity of the IoT device according to a connection to a network device authenticated by the vendor network server, receive a confirmation response from the vendor network server via the I/O module, where the confirmation response indicates whether the IoT device is connected to the network device, and if the confirmation response is a positive confirmation response that indicates that the IoT device is connected to the network device, onboard the IoT device for participation in an IoT-based system.