Primary Routing Module Authentication for Zero Touch Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In Zero Touch Provisioning (ZTP) for network devices, the lack of direct communication between the bootstrap device and redundant routing modules allows bad actors to spoof or mimic these modules, leading to potential malicious attacks and security compromises, as the bootstrap device cannot verify the authenticity of redundant routing modules, resulting in resource wastage in identifying and rectifying such attacks.

Innovation Solution

A primary routing module verifies the authenticity of redundant routing modules by obtaining a redundant identifier certificate, sending it to a bootstrap device, and verifying a signed certificate chain to ensure authorization before provisioning, thereby preventing unauthorized access and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If the bootstrap device does not directly communicate with redundant routing modules, then the system structure is simpler, but security is compromised as bad actors can spoof modules

Engineering Contradiction:
Improvesystem structureVSAvoidsecurity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent introduces a certificate verification mechanism as an intermediary between the bootstrap device and redundant routing modules. The primary routing module obtains certificates from redundant routing modules and verifies them against a certificate authority before allowing communication, preventing spoofing without requiring direct bootstrap-device-to-redundant-module connections.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If redundant routing modules are provisioned without authentication, then provisioning is faster and simpler, but unauthorized access and malicious attacks increase

Engineering Contradiction:
Improveprovisioning speedVSAvoidmalicious attacks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary authentication action before provisioning. The primary routing module obtains and verifies certificates from redundant routing modules prior to establishing communication and provisioning. This preliminary verification ensures only authorized modules receive bootstrap information, preventing malicious attacks while maintaining efficient automated provisioning.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If the bootstrap device verifies all routing modules directly, then security is improved, but the verification process becomes more complex and resource-intensive

Engineering Contradiction:
ImprovesecurityVSAvoidverification process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the verification process by assigning different roles: the primary routing module handles certificate verification for redundant routing modules, while the bootstrap device maintains simplified communication with the primary module. This segmentation reduces the bootstrap device's verification burden while maintaining comprehensive security through the primary module's verification function.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11811951B2Facilitating authentication of routing modules associated with one or more network devices to allow zero touch provisioning
Publication Date: 2023.11.07 JUNIPER NETWORKS INC
  • US11811951B2 patent drawing
  • US11811951B2 patent drawing
  • US11811951B2 patent drawing

AI summary

A network device may receive a redundant identifier certificate associated with a redundant routing module, and may provide, to a bootstrap device, a primary identifier certificate associated with a primary routing module associated with the network device. The network device may establish a secure connection with the bootstrap device based on the bootstrap device verifying an authenticity of the primary routing module via the primary identifier certificate. The network device may provide, to the bootstrap device via the secure connection, a redundant routing module identifier associated with the redundant routing module and may receive, from the bootstrap device via the secure connection, a signed certificate chain associated with the redundant routing module. The network device may verify the signed certificate chain and may verify the redundant identifier certificate, associated with the redundant routing module, based on verifying the signed certificate chain.