Secure Auto-Provisioning Device Network via Digital Certificate

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Internet-connected devices face security breaches due to full Internet access, require laborious setup steps, and consume excessive power, making them costly to secure and inconvenient to relocate.

Innovation Solution

A digital certificate-based system that securely connects devices to specific servers, eliminating the need for passwords and setup steps, using a low-power wireless network to prevent unauthorized access and conserve battery life.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If devices connect to the Internet using wi-fi with full Internet access, then devices can communicate with any server, but security risk increases as hackers can breach devices to compromise the network

Engineering Contradiction:
Improvedevice connectivityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments Internet access by creating separate virtual interfaces (e.g., ibyte0, ibyte1) for different devices, each with restricted routing rules. This allows each device to have its own controlled network path to specific servers, preventing lateral movement if one device is compromised while maintaining connectivity to required services.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by assigning different security policies and network routes to individual devices based on their specific needs. Each device receives customized firewall rules and routing configurations that grant access only to the servers it requires, rather than applying a uniform full Internet access policy to all devices.

Inventive Principle:
Principle #3Local quality

2Object-affected harmful factors

If devices require initial setup steps to be paired to an Internet router, then security is improved, but the setup process becomes laborious and complex

Engineering Contradiction:
ImprovesecurityVSAvoidsetup complexity
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent implements preliminary action by pre-configuring devices with unique identifiers and cryptographic keys during manufacturing. The gateway device is pre-programmed with the ability to automatically discover and authenticate these devices, eliminating the need for manual pairing steps while maintaining strong security through cryptographic verification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables self-service through automatic device discovery and authentication mechanisms. When a device powers on, it automatically registers with the gateway using its embedded credentials, and the gateway automatically configures the appropriate security policies and network routes without requiring user intervention or complex setup procedures.

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If devices are paired to a particular Internet router, then security is improved, but relocating the device requires repeating the setup step

Engineering Contradiction:
ImprovesecurityVSAvoiddevice mobility
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent implements universality by designing a portable gateway device that can function as the security anchor in multiple locations. The gateway contains the device pairing information and security credentials, allowing it to be moved between locations while maintaining secure device connections. This makes the security infrastructure portable rather than location-bound.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses the gateway as an intermediary between devices and the Internet router. The gateway handles all authentication and security functions locally, while maintaining a flexible connection to the router. This intermediary role allows the security subsystem to be decoupled from any specific physical location, enabling easy relocation by simply moving the gateway device.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If standard wi-fi is used for device connectivity, then Internet access is achieved, but power consumption increases draining the device battery

Engineering Contradiction:
ImproveInternet connectivityVSAvoidpower consumption
Core Design Contradiction:
Adaptability or versatilityVSUse of energy by moving object

Solution Approach 1:

The patent applies partial action by implementing selective network interface activation. The system activates only the specific wireless interface and network route required for the device's current function, rather than maintaining full wi-fi connectivity to the Internet router at all times. This reduces power consumption by keeping the radio in lower-power states when full Internet access is not needed.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent implements periodic action through on-demand network connectivity. Instead of maintaining continuous wi-fi connections, the device establishes network connections only when data transmission is required, and enters low-power sleep modes between communications. The gateway manages connection lifecycles, activating network interfaces periodically only when necessary for device operation.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS10284524B2Secure auto-provisioning device network
Publication Date: 2019.05.07 DOMATIC INC
  • US10284524B2 patent drawing
  • US10284524B2 patent drawing
  • US10284524B2 patent drawing

AI summary

A system comprising a gateway capable of connecting to an Internet router, and at least one Internet-connected device, said Internet-connected device comprising a digital certificate limiting its Internet access to a particular server or servers, said gateway capable of verifying the certificate and connecting the Internet-connected device to its server or servers.