Network Device Trust Establishment via Registration Entity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network devices, such as customer premises equipment (CPE), may lack or have outdated, incomplete, or corrupted electronic certificates, preventing users from accessing networks due to untrusted status.

Innovation Solution

A system and method for establishing or re-establishing trust for untrusted devices by sending a provisioning request to a registration entity, which uses a trust-assigning entity to authenticate and assign a cryptographically-unique trust token based on user verification, ensuring the device's identity and network address are validated.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network devices store electronic certificates for authentication, then network security and trust are improved, but device complexity and certificate management overhead increase

Engineering Contradiction:
Improvenetwork trustVSAvoidcertificate management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a registration entity as an intermediary that manages electronic certificates on behalf of network devices. The registration entity stores and manages the certificates, while devices simply reference them by identifier. This mediator approach resolves the contradiction by maintaining high network trust (through proper certificate management) while eliminating device complexity (devices don't need to store or manage certificates themselves).

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the certificate management function from the network device and places it in a separate registration entity. The device complexity related to certificate storage, validation, and management is taken out and centralized in the registration entity, while the device retains only the essential function of referencing certificates by identifier, thus resolving the contradiction between maintaining trust and reducing complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If network devices require valid electronic certificates for access, then network security is improved, but ease of operation deteriorates when certificates are outdated or corrupted

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements self-service through automated certificate validation and provisioning. When a device presents a certificate identifier, the registration entity automatically validates the certificate, detects if it's outdated or corrupted, and provisions a new certificate without user intervention. This resolves the contradiction by maintaining network security through automated validation while preserving ease of operation by eliminating manual certificate management tasks.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The registration entity implements feedback mechanisms where it continuously monitors certificate status (valid, outdated, corrupted) and automatically responds by provisioning new certificates when needed. This feedback loop ensures network security is maintained while preventing operational disruptions, as the system self-corrects certificate issues without requiring user action.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If manual certificate provisioning is used for untrusted devices, then ease of operation is improved, but time consumption and productivity increase

Engineering Contradiction:
Improvecertificate provisioningVSAvoidprovisioning time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system performs preliminary action by automatically validating certificates and provisioning new certificates before devices need them. When a device connects, the registration entity proactively checks certificate status and completes provisioning in advance, eliminating delays. This resolves the contradiction by maintaining ease of operation (automatic process) while reducing time consumption (no waiting for manual intervention).

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The registration entity maintains continuous operation by automatically handling certificate validation and provisioning without interruption. The system continuously monitors device connections and certificate status, ensuring uninterrupted service. This resolves the contradiction by keeping the provisioning process continuous and automatic (ease of operation) while eliminating idle time and delays (time loss).

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS11805113B2Establishing trust with network device
Publication Date: 2023.10.31 COMCAST CABLE COMM LLC
  • US11805113B2 patent drawing
  • US11805113B2 patent drawing
  • US11805113B2 patent drawing

AI summary

Systems, apparatuses, and methods are described for establishing, or re-establishing, trust for a network device. A user device may send, via a network device, a service request to establish trust for the network device in a network. The service request may comprise, or may allow look up of, identifying information for the network device, such as a network address. Trust of the network device may be established, at least in part, by confirming the network address (or other identifying information) associated with the network device, and/or by confirming certain devices that are in communication with the network device. An authentication token may be sent to the network device for reconnecting to the network.