Network Device Security Profile Configuration via Ownership Voucher

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Original equipment manufacturers (OEMs) face challenges in shipping network devices with varying security profiles due to conflicting user requirements, geographical differences, and changing security measures, leading to manual and inefficient changes of security knobs, which are often numerous and require interaction between engineers and technicians.

Innovation Solution

Utilizing an extended ownership voucher mechanism with bit-field extensions to enable secure configuration and customization of security profiles, allowing OEMs to pre-configure devices based on user needs, and enabling users to efficiently change or maintain security postures through a manufacturer-authorized signing authority (MASA).

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If OEMs ship network devices with different security profiles to meet diverse user requirements, then user satisfaction and compliance with geographical regulations improve, but device complexity and manufacturing costs increase

Engineering Contradiction:
Improvesecurity profile adaptabilityVSAvoiddevice complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal ownership voucher mechanism that can configure multiple security profiles within a single device. The voucher contains configurable parameters that enable the same hardware platform to adapt to different security requirements (e.g., FIPS mode, encryption settings, authentication protocols) without requiring physical modifications or different hardware variants. This multi-functional approach allows one device design to serve multiple security compliance needs across different geographical regions and user requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The ownership voucher system enables dynamic parameter changes by storing security configuration data in a configurable format. The voucher contains parameters that can be set to different values to enable or disable specific security features (such as FIPS mode enforcement, cryptographic algorithm selections, and security protocol configurations). This allows the same device to be reconfigured for different security profiles through parameter modification rather than hardware changes.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If security knobs are changed manually one by one with engineer interaction, then security profile customization is possible, but productivity and time efficiency deteriorate

Engineering Contradiction:
Improvesecurity profile configuration easeVSAvoidproductivity
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The ownership voucher is prepared in advance with all necessary security configuration parameters embedded within it. Instead of requiring engineers to manually configure each security setting after device deployment, the voucher contains pre-configured security profiles that are automatically applied when the device boots or when the voucher is processed. This preliminary configuration action eliminates the need for time-consuming manual engineer intervention for each security knob.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The device is empowered to self-configure its security profile by automatically processing the ownership voucher and applying the contained security parameters. The system performs self-service configuration without requiring continuous human intervention, thereby dramatically improving productivity while maintaining the ability to customize security profiles according to user requirements and geographical regulations.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If multiple security profiles are supported in the same product SKU, then user requirements and geographical regulations are met, but manufacturing and security management complexity increase

Engineering Contradiction:
Improvesecurity profile versatilityVSAvoidmanufacturing ease
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The patent extracts security profile configuration data from the manufacturing process and places it into a separate, configurable ownership voucher. This extraction allows the manufacturing process to remain simple and standardized, producing a single product SKU, while the security profile versatility is achieved through the configurable voucher content. The security parameters are taken out as a separate configurable element rather than being hard-coded into the hardware or firmware.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The ownership voucher introduces dynamic configurability to an otherwise static manufacturing process. The same physical device can be configured with different security profiles by changing the voucher parameters, enabling manufacturing of a single standardized product that can dynamically adapt to different security requirements through software/configuration changes rather than requiring multiple manufacturing lines or hardware variants.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20250112921A1Security profile selection and configuration of network devices via ownership voucher extension
Publication Date: 2025.04.03 CISCO TECHNOLOGY INC
  • US20250112921A1 patent drawing
  • US20250112921A1 patent drawing
  • US20250112921A1 patent drawing

AI summary

Techniques and architecture are described for providing a configurable security posture for a network device using an extended ownership artifact, e.g., an ownership voucher, an ownership certificate, etc., and a security profile mechanism that scales to user needs and desires for security profiles on network devices, i.e., easily and securely customizable on thousands of nodes of a network. The configurable security posture may be achieved using the manufacturer authorized signing authority (MASA) to issue an ownership voucher with a security bit extension to support security profile additions. Using the MASA service, a user may explicitly decide on various security postures of a given network device and may apply that profile across the fixed or modular chassis of a network of network devices.