Network Device Trust Establishment via Registration Entity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network devices, such as customer premises equipment (CPE), may lack or have outdated, incomplete, or corrupted electronic certificates, preventing users from accessing networks due to untrusted status.
Innovation Solution
A system and method for establishing or re-establishing trust for untrusted devices by sending a provisioning request to a registration entity, which uses a trust-assigning entity to authenticate and assign a cryptographically-unique trust token based on user verification, ensuring the device's identity and network address are validated.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network devices store electronic certificates for authentication, then network security and trust are improved, but device complexity and certificate management overhead increase
Solution Approach 1:
The patent introduces a registration entity as an intermediary that manages electronic certificates on behalf of network devices. The registration entity stores and manages the certificates, while devices simply reference them by identifier. This mediator approach resolves the contradiction by maintaining high network trust (through proper certificate management) while eliminating device complexity (devices don't need to store or manage certificates themselves).
Solution Approach 2:
The patent extracts the certificate management function from the network device and places it in a separate registration entity. The device complexity related to certificate storage, validation, and management is taken out and centralized in the registration entity, while the device retains only the essential function of referencing certificates by identifier, thus resolving the contradiction between maintaining trust and reducing complexity.
2Reliability
If network devices require valid electronic certificates for access, then network security is improved, but ease of operation deteriorates when certificates are outdated or corrupted
Solution Approach 1:
The system implements self-service through automated certificate validation and provisioning. When a device presents a certificate identifier, the registration entity automatically validates the certificate, detects if it's outdated or corrupted, and provisions a new certificate without user intervention. This resolves the contradiction by maintaining network security through automated validation while preserving ease of operation by eliminating manual certificate management tasks.
Solution Approach 2:
The registration entity implements feedback mechanisms where it continuously monitors certificate status (valid, outdated, corrupted) and automatically responds by provisioning new certificates when needed. This feedback loop ensures network security is maintained while preventing operational disruptions, as the system self-corrects certificate issues without requiring user action.
3Ease of operation
If manual certificate provisioning is used for untrusted devices, then ease of operation is improved, but time consumption and productivity increase
Solution Approach 1:
The system performs preliminary action by automatically validating certificates and provisioning new certificates before devices need them. When a device connects, the registration entity proactively checks certificate status and completes provisioning in advance, eliminating delays. This resolves the contradiction by maintaining ease of operation (automatic process) while reducing time consumption (no waiting for manual intervention).
Solution Approach 2:
The registration entity maintains continuous operation by automatically handling certificate validation and provisioning without interruption. The system continuously monitors device connections and certificate status, ensuring uninterrupted service. This resolves the contradiction by keeping the provisioning process continuous and automatic (ease of operation) while eliminating idle time and delays (time loss).
Data Source
AI summary
Systems, apparatuses, and methods are described for establishing, or re-establishing, trust for a network device. A user device may send, via a network device, a service request to establish trust for the network device in a network. The service request may comprise, or may allow look up of, identifying information for the network device, such as a network address. Trust of the network device may be established, at least in part, by confirming the network address (or other identifying information) associated with the network device, and/or by confirming certain devices that are in communication with the network device. An authentication token may be sent to the network device for reconnecting to the network.


