Secure Over-the-Air Device Provisioning via PKI

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Enterprise solutions for provisioning and deploying services on mobile phones and desktops are prone to user errors, lack security, and do not provide an Enterprise-level of security and privacy, relying on shared keys, PINs, SMS, emails, or Active Directory authentication, which creates security risks and an unacceptable user experience.

Innovation Solution

A unified Enterprise Model for secure device provisioning and deployment that establishes an over-the-air connection for device posture validation, authentication, and authorization, using a secure key pair generation and certificate-based enrollment, ensuring secure connectivity and provisioning of services over encrypted links, suitable for any platform and type of secure connection based on public-key infrastructure (PKI).

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing Enterprise solutions use shared keys, PINs, SMS, emails, or Active Directory authentication for provisioning, then the provisioning process can be implemented, but security risks increase due to lack of device authorization, posture validation, eavesdropping vulnerabilities, keystroke hacks, and man-in-the-middle attacks

Engineering Contradiction:
ImprovesecurityVSAvoidsecurity risks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a provisioning server as an intermediary between the device and the network. This server acts as a trusted mediator that validates device posture, authorizes devices, and manages certificate-based authentication. The intermediary prevents direct exposure of authentication mechanisms to potential attackers, blocking eavesdropping and man-in-the-middle attacks by routing all authentication traffic through the secure provisioning server.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The device performs self-authentication by presenting its own certificate and proving its posture compliance to the provisioning server. The device generates and manages its own cryptographic key pairs and certificates, eliminating the need for manual credential distribution via SMS, email, or shared keys. This self-service approach removes vulnerabilities associated with human-operated authentication methods like keystroke capture and PIN sharing.

Inventive Principle:
Principle #25Self-service

2Ease of manufacture

If manual provisioning processes are used for activating and deploying services on mobile phones or desktops, then the provisioning can be performed, but user errors increase and productivity decreases

Engineering Contradiction:
Improveprovisioning capabilityVSAvoidprovisioning efficiency
Core Design Contradiction:
Ease of manufactureVSProductivity

Solution Approach 1:

The device autonomously completes the entire provisioning process by automatically generating cryptographic key pairs, requesting and receiving certificates from the provisioning server, and configuring security settings without user intervention. The system performs self-diagnosis of posture compliance and self-authentication, eliminating manual configuration steps that cause user errors and delays.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The provisioning server pre-generates and stores device certificates and authentication credentials before the device needs them. When a device connects, the credentials are already prepared and can be instantly deployed. This preliminary preparation eliminates the need for users to manually input or transfer provisioning data, dramatically increasing provisioning speed and eliminating user errors.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If certificate-based authentication with posture validation is implemented, then security is improved, but device complexity increases due to PKI infrastructure requirements

Engineering Contradiction:
ImprovesecurityVSAvoidprovisioning system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The provisioning server serves as a centralized intermediary that manages the complex PKI infrastructure, including certificate generation, validation, and revocation. By concentrating this complexity in a single server rather than distributing it across all devices, the system achieves high security through certificates while keeping individual device complexity low. The server handles all cryptographic operations and posture validation logic, simplifying the device side.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9450951B2Secure over-the-air provisioning solution for handheld and desktop devices and services
Publication Date: 2016.09.20 CISCO TECHNOLOGY INC
  • US9450951B2 patent drawing
  • US9450951B2 patent drawing
  • US9450951B2 patent drawing

AI summary

In one embodiment, a device and a services provisioning system establish an over-the-air connection with each other, and perform device posture validation to obtain a unique identification (ID) of the device at the provisioning system. The device and provisioning system then participate in device and user authentication in response to a confirmed unique ID by a backend access control system, where the device generates a secure key pair after successful user authentication. In response to the device being approved for services (e.g., checked by the provisioning system via a registration system), the provisioning system provides a root certificate to the device, and the device sends a certificate enrollment request back to the provisioning system. In response to a certificate authority signing the certificate request, the provisioning system returns a valid certificate to the device, and the valid certificate is installed on the device.