Secure Element Registration via Deferred PKI Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional IoT devices face challenges in securely managing and provisioning Public Key Infrastructure (PKI) due to high costs, complex key management, and difficulties in auditing, especially when deployed across multiple ecosystems, leading to increased costs for manufacturers without adequate revenue recoupment.

Innovation Solution

A method for registering and provisioning electronic devices by inserting a keypair into a secure element, requesting credentials from a remote server, verifying and registering the device, and transmitting a device certificate for installation, allowing for deferred provisioning and monetization at the vendor level, reducing the burden on manufacturers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional PKI is implemented at manufacturing level, then device security is improved, but manufacturing cost increases

Engineering Contradiction:
Improvedevice securityVSAvoidmanufacturing cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent applies preliminary action by pre-provisioning secure elements with unique identifiers and public keys during manufacturing, but deferring the actual PKI certificate issuance until activation. This allows manufacturers to prepare security infrastructure in advance without incurring full PKI costs for all devices, reducing manufacturing costs while maintaining security readiness.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts the PKI certificate issuance process from the manufacturing stage and relocates it to the activation stage. By separating these processes, manufacturers only incur PKI costs for devices that are actually activated and deployed, reducing unnecessary spending on devices that may not be sold or used.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If PKI is provisioned for all manufactured devices, then security coverage is improved, but cost recovery difficulty increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidcost recovery
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent enables self-service by allowing activated devices to automatically obtain their own PKI certificates from remote certificate authorities using their pre-provisioned public keys. This automated process eliminates manual intervention and reduces operational costs, improving cost recovery efficiency while maintaining comprehensive security coverage for all activated devices.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If multiple secure elements are used in a device, then security versatility is improved, but key management complexity increases

Engineering Contradiction:
Improvesecurity versatilityVSAvoidkey management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies universality by creating a unified key management system that can handle multiple secure elements and different types of cryptographic keys through a common interface. The system provides standardized procedures for provisioning, managing, and revoking keys across diverse secure elements, reducing management complexity while maintaining security versatility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Ease of operation

If secure elements are provisioned at manufacturing, then device readiness is improved, but production line cost increases

Engineering Contradiction:
Improvedevice readinessVSAvoidproduction line cost
Core Design Contradiction:
Ease of operationVSEase of manufacture

Solution Approach 1:

The patent applies preliminary action by provisioning only essential security infrastructure (unique identifiers and public keys) during manufacturing, rather than complete PKI certificates. This preliminary provisioning ensures device readiness for security operations while minimizing production line costs, with full certificate issuance occurring later during activation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11899756B1Systems and methods for secure element registration and provisioning
Publication Date: 2024.02.13 CABLE TELEVISION LAB INC
  • US11899756B1 patent drawing
  • US11899756B1 patent drawing
  • US11899756B1 patent drawing

AI summary

A method for registering and provisioning an electronic device is provided. The method includes a step of inserting a first keypair into a secure element of the electronic device. The first keypair includes a public key and a private key. The method further includes a step of requesting, from a remote server configured to register and provision connected devices, a provisioning of credentials of the electronic device. The method further includes a step of verifying, by the remote server, the electronic device credentials. The method further includes a step of registering, by the remote server, the electronic device. The method further includes a step of transmitting, from the remote server to the electronic device, a device certificate. The method further includes steps of installing the transmitted device certificate within the secure element of the electronic device, and provisioning the electronic device according to the installed device certificate.