Secure Computer Provisioning via Firmware Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In insecure network environments, existing automated provisioning protocols for computer servers are vulnerable to eavesdropping and tampering, as they rely on untrusted local configuration servers for software provisioning, lacking secure authentication and control over the provisioning process.

Innovation Solution

Customizing the firmware of computer devices to pre-configure a trusted global provisioning server, using cryptographic authentication to ensure secure communication and provisioning from that server, bypassing local server instructions, and utilizing secure protocols for communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If automated provisioning protocols are used with local configuration servers, then provisioning efficiency is improved, but security and trust are worsened due to vulnerability to eavesdropping and tampering

Engineering Contradiction:
Improveprovisioning efficiencyVSAvoidsecurity and trust
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-configuring the firmware with a trusted global provisioning server identifier before the actual provisioning occurs. This allows the device to autonomously establish secure communication with the pre-trusted server without relying on potentially untrusted local configuration servers, thus maintaining both automated provisioning efficiency and security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary approach by using firmware as a trusted mediator between the device and the provisioning server. The firmware contains pre-configured authentication information that acts as a mediator to verify the identity of the global provisioning server, enabling secure communication without requiring trust in local network infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If local configuration servers are used for software provisioning, then ease of operation is improved, but harmful factors increase due to potential eavesdropping and tampering in insecure networks

Engineering Contradiction:
Improveease of provisioningVSAvoideavesdropping and tampering
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies the extraction principle by removing the provisioning trust dependency from the local network environment and extracting it to a pre-configured trusted source in the device's firmware. This allows the device to perform provisioning operations autonomously without relying on potentially harmful local configuration servers, thus eliminating eavesdropping and tampering risks while maintaining operational ease.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements preliminary anti-action by pre-configuring authentication information in the firmware to counteract potential malicious actions from untrusted local servers. The device uses this pre-established trust mechanism to reject unauthorized provisioning attempts and authenticate only trusted global provisioning servers, thereby preventing eavesdropping and tampering before they can occur.

Inventive Principle:
Principle #9Preliminary anti-action

3Device complexity

If untrusted local configuration servers are used, then device complexity is reduced, but reliability worsens due to lack of secure authentication

Engineering Contradiction:
Improveconfiguration server complexityVSAvoidsecure authentication
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent applies self-service by enabling the device to autonomously perform provisioning operations using pre-configured authentication information stored in its own firmware. The device independently authenticates with the global provisioning server without requiring complex configuration server infrastructure, thus reducing device complexity while maintaining reliable secure authentication through the self-contained trust mechanism.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8707402B1Secure computer provisioning
Publication Date: 2014.04.22 AMAZON TECH INC
  • US8707402B1 patent drawing
  • US8707402B1 patent drawing
  • US8707402B1 patent drawing

AI summary

A networked computer device can be provisioned by customizing the computer device to contain a specification of a particular provisioning server. For example, a network interface device can be pre-configured and installed in the computer device. The pre-configuration of the network interface device may include embedding a provisioning service identification in the network interface device. The network interface device may be further configured to perform provisioning from a provisioning service indicated by the embedded provisioning service identification. In addition, or alternatively, the network interface device, or the computer within which it is installed, may be configured to authenticate with a provisioning server based on authentication information that has been embedded within firmware of the computer or network interface device.