Public Key Affixation for Constrained Device Enrollment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Constrained devices, such as IoT sensors and actuators, face delays and increased costs during enrollment due to the requirement of established power and network resources at installation sites, which are often unavailable upon delivery.
Innovation Solution
A method where a public key is affixed to the device, allowing system administrators to document and record it without power or network access, enabling enrollment when resources become available, using an initialization server to generate and store a public and private key pair, and an authorization server to issue tokens for network authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If constrained devices are enrolled using traditional methods requiring power and network resources at installation site, then secure authentication and network integration are achieved, but enrollment is delayed and costs increase when resources are unavailable
Solution Approach 1:
The system performs preliminary actions by affixing the public key to the device exterior and enabling offline documentation of this key. This allows the enrollment process to begin before power and network resources are available, with the actual network authentication occurring later when resources become available. The public key serves as a preliminary credential that can be captured and stored without requiring active device power or network connection.
Solution Approach 2:
The public key acts as an intermediary element that bridges the gap between offline device preparation and online network authentication. By affixing the public key to the device exterior, the system creates a portable credential that can be documented offline and later used for secure authentication when network resources become available, thus mediating between the two states.
2Reliability
If constrained devices wait for power and network resources before enrollment, then proper authentication can be established, but installation costs and time increase
Solution Approach 1:
The system performs preliminary enrollment actions by capturing and documenting the public key offline before network resources are available. This preliminary documentation enables the authentication process to proceed quickly once power and network become available, thus improving overall enrollment speed without compromising authentication reliability.
Solution Approach 2:
The device provides self-service capabilities by having its public key affixed to the exterior, allowing it to be documented and enrolled without requiring immediate power or network resources. The device can be prepared and identified for enrollment in advance, and the actual authentication process can occur later when resources are available, enabling the device to serve itself through the affixed identifier.
3Ease of operation
If public key is affixed to device exterior for offline documentation, then enrollment can proceed without power or network access, but device complexity increases
Solution Approach 1:
Instead of embedding complex cryptographic key management systems within the constrained device, the public key is copied onto an external medium (affixed to the device exterior). This external copy can be documented by the system administrator using standard equipment without requiring sophisticated device capabilities, thus improving ease of operation while avoiding increases in device complexity.
Solution Approach 2:
The solution moves the public key from an internal device component to an external dimension (device exterior surface). This dimensional relocation allows the key to be accessed and documented offline using simple tools, eliminating the need for complex device interfaces or power requirements during the documentation phase, thus improving ease of operation without adding device complexity.
Data Source
AI summary
A constrained device includes an exterior surface affixed with a public key associated with the constrained device. Alternatively, or in addition, the public key may be included in a container that stores the constrained device. The constrained device also includes memory, which stores a private key, wherein the private key corresponds to the public key that is affixed on the exterior surface of the constrained device. By displaying the public key on the constrained device, a system administrator may document the public key and related information about the device and its intended role in the network without requiring any human interface or any establishment of power or network at the installation site.


