Zero-Touch IoT Device Provisioning via Unified Signing Authority

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current IoT device provisioning methods are complex and inconsistent due to independent and uncoordinated protocols for bootstrapping, authorization, and access control, leading to potential security risks and increased server bandwidth costs.

Innovation Solution

A unified process that integrates an authorized signing authority server and a device provisioning server to manage authenticity and network security policies for IoT devices, using protocols like BRSKI and MUD to ensure secure zero-touch provisioning without human intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If independent protocols are used for bootstrapping, authorization, and access control, then device provisioning can be achieved, but the configuration becomes complicated and inconsistent

Engineering Contradiction:
Improvedevice provisioningVSAvoidconfiguration
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent combines multiple independent protocols (bootstrapping, authorization, access control) into a unified zero-touch provisioning process. The system integrates these separate functions into a coordinated workflow where a single provisioning request triggers all necessary steps in sequence, eliminating the need for manual configuration of each protocol separately and ensuring consistent state management across all components.

Inventive Principle:
Principle #5Merging (Combining)

2Adaptability or versatility

If multiple independent protocols are coordinated separately, then device functionality can be achieved, but security risks increase

Engineering Contradiction:
Improvedevice functionalityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system implements feedback mechanisms where each protocol step reports its state to a central coordinator. The bootstrapping process, authorization decisions, and access control configurations continuously exchange status information, allowing the system to detect inconsistencies or security violations and correct them automatically. This coordinated feedback loop ensures that security policies are consistently applied across all device functions.

Inventive Principle:
Principle #23Feedback

3Reliability

If multiple server interactions are required for provisioning, then comprehensive security can be achieved, but server bandwidth costs increase

Engineering Contradiction:
ImprovesecurityVSAvoidserver bandwidth
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system performs preliminary actions by pre-configuring security policies and authorization rules on the server side before device connection. The provisioning process retrieves these pre-prepared configurations rather than generating them dynamically during interaction, reducing the computational and bandwidth overhead of multiple server requests. Security credentials and policies are prepared in advance and delivered in a single coordinated exchange.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10298581B2Zero-touch IoT device provisioning
Publication Date: 2019.05.21 CISCO TECHNOLOGY INC
  • US10298581B2 patent drawing
  • US10298581B2 patent drawing
  • US10298581B2 patent drawing

AI summary

In one embodiment, an authorized signing authority server receives an authenticity request from a security registrar to vouch for authenticity of a particular device. Based on receiving the authenticity request, the authorized signing authority server may then determine an authenticity state of the particular device, and may also request a device provisioning file for the particular device from a device provisioning server, the device provisioning file defining one or more network security policies for the particular device. Upon receiving the device provisioning file from the device provisioning server, the authorized signing authority server may then return the authenticity state and the device provisioning file for the particular device to the security registrar, causing the security registrar to complete authentication of the particular device based on the authenticity state and the device provisioning file.