Network Device Authentication via Certificate-Based Redirection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network device authentication methods require manual intervention and are inefficient, especially in zero-touch provisioning (ZTP), where network devices need to be provisioned without administrator input, and existing systems struggle to manage large numbers of devices securely and efficiently.

Innovation Solution

A method where an OEM server authenticates network devices based on certificates and redirects them to third-party servers for provisioning, allowing for secure, scalable, and efficient ZTP without managing end-user records, thereby offloading processing power and communication bandwidth.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the OEM server directly manages authentication and provisioning for all network devices, then security and control are maintained, but processing power and communication bandwidth are overwhelmed, and provisioning time increases

Engineering Contradiction:
Improveauthentication securityVSAvoidprovisioning throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the authentication and provisioning system into multiple independent third-party servers that each handle specific device batches or regions. The OEM server divides its workload by delegating authentication requests to these distributed servers, allowing parallel processing of device provisioning while maintaining centralized security policies. This segmentation enables the system to scale horizontally, handling larger volumes of devices without overwhelming the OEM server's processing capacity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces third-party servers as intermediaries between the OEM server and network devices. These intermediary servers receive authentication requests from devices, perform initial verification using certificates, and then redirect authorized devices to appropriate provisioning servers. This intermediary layer offloads processing from the OEM server while maintaining security through certificate-based authentication, effectively resolving the contradiction between maintaining security and increasing throughput.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If the OEM server handles all authentication requests, then centralized control is maintained, but provisioning time and processing overhead increase

Engineering Contradiction:
Improvecentralized controlVSAvoidprovisioning time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent implements preliminary action by having third-party servers pre-configured with authentication credentials and provisioning templates before devices arrive. Certificate authorities pre-issue certificates to devices, and provisioning servers pre-prepare configuration packages. When devices connect, authentication and provisioning occur rapidly because the heavy preparation work was done in advance, significantly reducing actual provisioning time while maintaining centralized control through pre-planned authentication policies.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables self-service authentication where network devices automatically present their certificates for verification without requiring manual administrator intervention. The third-party servers autonomously perform certificate validation, device authentication, and provisioning based on pre-configured policies. This self-service mechanism eliminates time-consuming manual operations while maintaining centralized control through automated policy enforcement, thereby reducing provisioning time without sacrificing operational ease.

Inventive Principle:
Principle #25Self-service

3Reliability

If manual intervention is used for device authentication, then security can be verified, but the process becomes inefficient and cannot scale to large numbers of devices

Engineering Contradiction:
Improveauthentication verificationVSAvoidprovisioning automation
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The patent replaces manual mechanical authentication processes with automated electronic certificate-based verification. Instead of administrators manually verifying device identities through physical presence or manual credential checking, the system uses digital certificates and cryptographic verification mechanisms. Third-party servers automatically validate device certificates, perform authentication, and initiate provisioning without human intervention. This substitution maintains high security through cryptographic verification while enabling full automation, allowing the system to scale to large numbers of devices efficiently.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11777742B2Network device authentication
Publication Date: 2023.10.03 CISCO TECHNOLOGY INC
  • US11777742B2 patent drawing
  • US11777742B2 patent drawing
  • US11777742B2 patent drawing

AI summary

A method of authenticating a network device may include receiving an authentication message from a third party server, the authentication message identifying a network device. The method may also include receiving a zero touch provisioning request comprising a certificate from the network device. The method may additionally include, determining the network device is associated with a third party that manages the third party server based on the certificate. The method may include transmitting a redirect message comprising a root certificate chain indicating that the network device is to send the zero touch provisioning request to the third party server.