Secure Zero-Touch Network Device Provisioning via Local Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network device provisioning methods require substantial time and cost due to the need for onsite technicians to configure and update devices, and traditional zero-touch provisioning systems are vulnerable to external threats when exposed to untrusted networks.

Innovation Solution

The implementation of a secure zero-touch provisioning (ZTP) system that uses local or remote authenticated ZTP servers, where network devices are pre-configured with authentication information, such as a root of trust, to connect securely with a designated ZTP server, utilizing methods like DHCP, USB storage, or cloud-based services for secure provisioning.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If traditional zero-touch provisioning systems are exposed to external untrusted networks, then automated provisioning capability is improved, but security vulnerability increases

Engineering Contradiction:
Improveautomated provisioning capabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Extent of automationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a trusted intermediary component (secure enclave or hardware security module) that mediates between the external untrusted network and the internal provisioning processes. This intermediary verifies the identity of external entities and protects sensitive credentials, enabling automated provisioning while maintaining security by acting as a secure buffer between trusted and untrusted zones.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the provisioning architecture into distinct trusted and untrusted zones. The secure enclave contains sensitive credentials and authentication logic, separated from the external network interface. This segmentation allows the system to expose automated provisioning capabilities to external networks while isolating critical security functions in a protected environment.

Inventive Principle:
Principle #1Segmentation

2Reliability

If onsite technicians manually provision each device, then security control is improved, but time consumption and cost increase

Engineering Contradiction:
Improvesecurity controlVSAvoidprovisioning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables devices to self-provision automatically by implementing local authentication credentials and automated enrollment processes. Devices can autonomously authenticate with provisioning servers and receive configurations without human intervention, eliminating the time loss associated with manual technician deployment while maintaining security through cryptographic authentication mechanisms.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Security credentials and authentication information are pre-loaded into devices during manufacturing or initial setup. This preliminary action ensures that when devices are deployed, they already possess the necessary security credentials to authenticate and provision themselves automatically, eliminating the need for technicians to manually configure security settings while maintaining strong security controls.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11470075B2Systems and methods for provisioning network devices
Publication Date: 2022.10.11 ARISTA NETWORKS INC
  • US11470075B2 patent drawing
  • US11470075B2 patent drawing
  • US11470075B2 patent drawing

AI summary

Network devices are securely provisioned through authenticated ZTP servers. In some approaches, a storage device local to the network device includes information for connecting with and authenticating a local or remote ZTP server. This information may include a root of trust to use when connecting with a designated ZTP server. The ZTP server may be identified using either a dynamic host configuration protocol (DHCP) server or a network address specified in the local memory storage. In an approach, the local memory storage is a removable USB flash memory device inserted into the network device when the device is booted up. In another approach, the ZTP authentication information is stored within memory integrated within the network device. Once a ZTP server is connected to the network device, a secure connection may be established such as a secure transport layer session (TLS) utilizing the root of trust.