SD-WAN Edge Device Onboarding With Pre-Join Identity Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network managers like VMware's SD-WAN Orchestrator are vulnerable to compromise when edge devices are added without secure identity validation, risking leakage of sensitive network configuration details.

Innovation Solution

A method involving a network manager providing a record to an activation service for edge device authentication, followed by verification from a network administrator, and subsequent configuration and authentication data transfer to establish a secure VPN tunnel with a partner gateway.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If edge devices are added to SD-WAN without secure identity validation, then device deployment is simplified and faster, but network security is compromised and sensitive configuration details may be leaked

Engineering Contradiction:
Improvedevice deployment speedVSAvoidnetwork security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary authentication and verification actions before allowing edge devices to join the SD-WAN network. The network manager authenticates device identities and verifies credentials in advance, ensuring security checks are completed before network access is granted, thus preventing security breaches while maintaining deployment efficiency

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The network manager acts as an intermediary between edge devices and the SD-WAN network. It mediates the authentication process by validating device identities and controlling access, preventing direct unsecured connections while enabling streamlined device onboarding through automated verification procedures

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a full-featured activation service is deployed to authenticate edge devices, then authentication capability is enhanced, but the service becomes a larger attack target and consumes more resources

Engineering Contradiction:
Improveauthentication capabilityVSAvoidattack surface
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The activation service is extracted to a minimal, slim implementation that performs only essential authentication functions. Non-essential features and data storage are removed, reducing the service's attack surface while maintaining core authentication capabilities through lightweight verification mechanisms

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system uses temporary, ephemeral authentication credentials and short-lived session tokens instead of persistent storage. This approach maintains strong authentication capabilities while minimizing the attack surface, as there is no permanent data repository for attackers to exploit

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Productivity

If all edge device records are immediately provided to the activation service, then device activation is faster, but security risks increase and unauthorized devices may be activated

Engineering Contradiction:
Improveactivation speedVSAvoiddevice authorization security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The network manager performs preliminary verification of edge device records and credentials before providing them to the activation service. This preliminary action ensures only authorized devices are activated while maintaining fast onboarding speeds through pre-validation of device identities and permissions

Inventive Principle:
Principle #10Preliminary action

4Device complexity

If the network manager directly communicates with edge devices on the public network, then device management is simpler, but the network manager becomes vulnerable to compromise

Engineering Contradiction:
Improvemanagement complexityVSAvoidnetwork manager security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The activation service serves as an intermediary between the network manager and edge devices on the public network. This intermediary handles direct communications and authentication operations, protecting the network manager from exposure to public network threats while maintaining simplified management through automated mediation

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12425395B2Method and system of securely adding an edge device operating in a public network to an SD-WAN
Publication Date: 2025.09.23 VELOCLOUD NETWORKS LLC
  • US12425395B2 patent drawing
  • US12425395B2 patent drawing
  • US12425395B2 patent drawing

AI summary

Some embodiments of the invention provide, for a network manager of a secure SD-WAN (software-defined wide-area network), a method of securely adding an edge device, which operates at a branch location in a public network, to the SD-WAN. The method provides, to an activation service hosted on the public network, a record for the edge device that is to be added to the SD-WAN securely, the record for use by the activation service to authenticate the edge device. The method receives a first notification from the activation service indicating the edge device has been authenticated. The method receives a second notification from a verification service indicating the authenticated edge device has been verified. Based on the first and second notifications, the method provides to the activation service (i) a set of configuration data for the edge device and (ii) a set of authentication data for the edge device. The activation service provides the set of configuration data and the set of authentication data to the edge device to use to join the SD-WAN.