Multi-Tenant SCMS Provisioning to Reduce System Redundancy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems require separate Security Credential Management Systems (SCMS) for each tenant or client, leading to redundancies and high costs, and struggle with securely provisioning digital assets across multiple locations without compromising security.

Innovation Solution

A multi-tenant secure provisioning system using a Certificate Authority, SCMS host platform, and virtual registration authorities, enabling secure provisioning of digital assets across multiple tenants by linking devices to specific entities and managing multi-stage provisioning processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate Security Credential Management Systems are deployed for each tenant, then security and compliance requirements are met, but system redundancy and costs increase

Engineering Contradiction:
ImprovesecurityVSAvoidsystem redundancy
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple separate SCMS instances into a single multi-tenant SCMS platform. The system uses virtualization to create isolated virtual SCMS environments for each tenant within a shared physical infrastructure, eliminating the need for separate hardware deployments while maintaining security boundaries through virtual isolation mechanisms.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal SCMS platform that can serve multiple tenants simultaneously. The system implements a common infrastructure with multi-tenant support capabilities, allowing a single deployment to provide security credential management services to numerous clients through configurable virtual environments and standardized interfaces.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If separate Security Credential Management Systems are deployed for each tenant, then security isolation is maintained, but deployment costs increase

Engineering Contradiction:
Improvesecurity isolationVSAvoiddeployment costs
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent consolidates multiple SCMS deployments into a single shared platform with virtualized tenant environments. By merging infrastructure resources (hardware, software, networking) while maintaining logical isolation through virtualization, the system reduces duplicate costs while preserving security boundaries.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent uses virtualization to create virtual copies of SCMS environments for each tenant rather than deploying physical copies. These virtual instances are lightweight representations that share underlying infrastructure, significantly reducing hardware and software licensing costs while maintaining the appearance of separate systems.

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If digital assets are provisioned across multiple locations, then device manufacturing flexibility is improved, but security provisioning complexity increases

Engineering Contradiction:
Improvemanufacturing flexibilityVSAvoidprovisioning complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the provisioning system into distributed components that can operate independently at different locations. The multi-tenant SCMS architecture allows provisioning functions to be distributed across multiple sites while maintaining centralized coordination, enabling manufacturing flexibility without proportionally increasing overall system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a centralized multi-tenant SCMS platform as an intermediary that coordinates provisioning across distributed locations. This mediator manages security credential distribution, device registration, and provisioning workflows, simplifying the complexity of multi-location operations by providing a single point of control.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Device complexity

If a single SCMS serves multiple tenants, then redundancy and costs are reduced, but security isolation challenges arise

Engineering Contradiction:
Improvesystem redundancyVSAvoidsecurity isolation
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent implements a nested architecture where virtual SCMS environments for each tenant are contained within the broader multi-tenant platform. Each tenant's virtual environment is a self-contained unit nested within the shared infrastructure, providing security isolation through hierarchical containment while sharing underlying resources.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent uses virtualization layers and security management components as intermediaries between tenants and the shared infrastructure. These intermediary layers enforce security policies, manage access controls, and isolate tenant workloads, enabling secure multi-tenant operation without requiring physical separation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250286736A1Systems, methods, and devices for multi-stage provisioning and multi-tenant operation for a security credential management system
Publication Date: 2025.09.11 INTEGRITY SECURITY SERVICES LLC
  • US20250286736A1 patent drawing
  • US20250286736A1 patent drawing
  • US20250286736A1 patent drawing

AI summary

A system for securely provisioning a plurality of computerized devices of a tenant. The system includes a certificate authority operable to generate digital assets for onboard units and roadside units of the tenant in response to provisioning requests from the plurality of computerized devices, where each of the provisioning requests includes a device identifier. The system includes a security credential management system (SCMS) host platform, operably connected to the certificate authority, where the SCMS host platform is configured to perform operations that may include receiving the provisioning requests for the digital assets for the plurality of computerized devices, each of the provisioning requests including the device identifier, and routing at least some of the provisioning requests to the certificate authority based on the device identifier.