SD-WAN Edge Device Onboarding With Pre-Join Identity Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network managers like VMware's SD-WAN Orchestrator are vulnerable to compromise when edge devices are added without secure identity validation, risking leakage of sensitive network configuration details.
Innovation Solution
A method involving a network manager providing a record to an activation service for edge device authentication, followed by verification from a network administrator, and subsequent configuration and authentication data transfer to establish a secure VPN tunnel with a partner gateway.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If edge devices are added to SD-WAN without secure identity validation, then device deployment is simplified and faster, but network security is compromised and sensitive configuration details may be leaked
Solution Approach 1:
The system performs preliminary authentication and verification actions before allowing edge devices to join the SD-WAN network. The network manager authenticates device identities and verifies credentials in advance, ensuring security checks are completed before network access is granted, thus preventing security breaches while maintaining deployment efficiency
Solution Approach 2:
The network manager acts as an intermediary between edge devices and the SD-WAN network. It mediates the authentication process by validating device identities and controlling access, preventing direct unsecured connections while enabling streamlined device onboarding through automated verification procedures
2Reliability
If a full-featured activation service is deployed to authenticate edge devices, then authentication capability is enhanced, but the service becomes a larger attack target and consumes more resources
Solution Approach 1:
The activation service is extracted to a minimal, slim implementation that performs only essential authentication functions. Non-essential features and data storage are removed, reducing the service's attack surface while maintaining core authentication capabilities through lightweight verification mechanisms
Solution Approach 2:
The system uses temporary, ephemeral authentication credentials and short-lived session tokens instead of persistent storage. This approach maintains strong authentication capabilities while minimizing the attack surface, as there is no permanent data repository for attackers to exploit
3Productivity
If all edge device records are immediately provided to the activation service, then device activation is faster, but security risks increase and unauthorized devices may be activated
Solution Approach 1:
The network manager performs preliminary verification of edge device records and credentials before providing them to the activation service. This preliminary action ensures only authorized devices are activated while maintaining fast onboarding speeds through pre-validation of device identities and permissions
4Device complexity
If the network manager directly communicates with edge devices on the public network, then device management is simpler, but the network manager becomes vulnerable to compromise
Solution Approach 1:
The activation service serves as an intermediary between the network manager and edge devices on the public network. This intermediary handles direct communications and authentication operations, protecting the network manager from exposure to public network threats while maintaining simplified management through automated mediation
Data Source
AI summary
Some embodiments of the invention provide, for a network manager of a secure SD-WAN (software-defined wide-area network), a method of securely adding an edge device, which operates at a branch location in a public network, to the SD-WAN. The method provides, to an activation service hosted on the public network, a record for the edge device that is to be added to the SD-WAN securely, the record for use by the activation service to authenticate the edge device. The method receives a first notification from the activation service indicating the edge device has been authenticated. The method receives a second notification from a verification service indicating the authenticated edge device has been verified. Based on the first and second notifications, the method provides to the activation service (i) a set of configuration data for the edge device and (ii) a set of authentication data for the edge device. The activation service provides the set of configuration data and the set of authentication data to the edge device to use to join the SD-WAN.


