M2M VPN Credential Provisioning via Device Management Server
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Establishing a virtual private network (VPN) for machine-to-machine (M2M) devices is cumbersome and insecure due to the manual distribution of pre-shared keys and the requirement for an enterprise PKI and Microsoft Active Directory, which is not suitable for M2M devices without Active Directory support and incurs significant overhead.
Innovation Solution
A system using a device management server that interacts with a VPN server via a network application programming interface (API) to provision M2M devices with VPN credentials, enabling secure communication and VPN setup, even for unattended and hardware-limited devices, utilizing General Bootstrapping Architecture (GBA) for enhanced security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual distribution of pre-shared keys is used, then VPN can be established between M2M devices and VPN server, but the process is cumbersome and insecure
Solution Approach 1:
The patent introduces a Device Management (DM) server as an intermediary between the VPN server and M2M devices. The DM server automatically enrolls devices into the PKI, obtains device certificates, and provisions VPN credentials without manual intervention. This mediator resolves the contradiction by automating the secure key distribution process that would otherwise be cumbersome and insecure when done manually.
Solution Approach 2:
The system performs preliminary actions by establishing the PKI infrastructure and enrolling devices into it before VPN connection is needed. The DM server pre-provisions M2M devices with VPN credentials and maintains an updated credential store, so that when a device needs to connect to the VPN, the authentication credentials are already in place and ready, eliminating the need for manual key distribution at the time of VPN setup.
2Extent of automation
If Microsoft Active Directory and enterprise PKI are implemented, then automated certificate enrollment is supported, but the system is not suitable for M2M devices without Active Directory support and incurs significant overhead
Solution Approach 1:
The patent extracts the essential functionality of automated certificate enrollment from the Microsoft Active Directory ecosystem and implements it as a standalone Device Management server. This DM server provides PKI integration and certificate management capabilities independently of Active Directory, allowing M2M devices without Active Directory support to benefit from automated enrollment while avoiding the significant overhead and complexity of implementing a full enterprise Active Directory infrastructure.
3Adaptability or versatility
If M2M devices are joined to domain at build time within company premises, then domain integration is achieved, but devices activated in the field away from enterprise premises cannot be properly enrolled
Solution Approach 1:
The patent implements self-service enrollment where M2M devices can automatically register themselves with the DM server and obtain VPN credentials without requiring manual domain joining at company premises. The devices perform preliminary actions by autonomously enrolling into the PKI through the DM server, which then provisions them with necessary credentials. This enables field-activated devices to integrate into the VPN infrastructure automatically, regardless of their activation location.
4Ease of operation
If pre-shared keys are sent to M2M devices remotely, then key distribution is enabled, but security is compromised due to lack of end-to-end secure connection
Solution Approach 1:
The system performs preliminary secure enrollment actions where the DM server establishes secure communication channels with M2M devices before VPN connection is attempted. The server enrolls devices into the PKI, obtains their certificates, and provisions VPN credentials through these pre-established secure channels. This preliminary secure provisioning ensures that subsequent remote operations can distribute keys securely without requiring ad-hoc secure connection setup.
Solution Approach 2:
The DM server acts as a trusted intermediary that manages the secure distribution of VPN credentials. It maintains an updated credential store with device-specific credentials and distributes them through secure communication channels to the appropriate M2M devices. This intermediary approach replaces insecure direct key distribution with a managed, authenticated process that ensures security while enabling remote distribution.
Data Source
AI summary
System and method for providing secure machine to machine, M2M, communications comprising a device management, DM, server configured to obtain credentials of one or more M2M devices and provision the one or more M2M devices with credentials of a virtual private network, VPN. An application programming interface, API. A VPN server comprising a first communications interface configured to communicate API requests and API responses with the API. A second communications interface configured to provide a VPN for the one or more M2M devices. Logic configured to issue an API request, wherein the request includes the credentials of the VPN. Receive an API response from the DM server including an indication of the one or more M2M devices provisioned with the credentials of the VPN. Initiate a VPN over the second interface between the one or more M2M devices and the VPN server.


