Network Node Provisioning with Segmented Application Credentials
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for provisioning node devices in networks with different types of applications and owners fail to securely manage application credentials, as they often require sharing these credentials across devices, compromising security.
Innovation Solution
A method involving an application provisioner that obtains device-specific network provisioning data and application credentials separately, distributing them directly to node devices via short-range communication interfaces, ensuring secure management and authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If application credentials are shared across devices in existing provisioning methods, then ease of operation is improved, but security is compromised
Solution Approach 1:
The patent segments the credential distribution process into separate phases: network-level credentials are distributed first, then application-specific credentials are distributed separately to specific node devices. This segmentation allows each credential type to be managed independently, preventing the security vulnerability of shared credentials while maintaining operational ease through automated distribution.
Solution Approach 2:
The patent introduces a provisioner as an intermediary system that automatically distributes credentials to node devices. The provisioner acts as a mediator between the credential authority and individual devices, enabling secure credential distribution without requiring manual intervention or sharing of credentials across devices.
2Object-affected harmful factors
If credentials are distributed directly to each node device, then security is improved, but device complexity increases
Solution Approach 1:
The patent implements self-service provisioning where node devices automatically receive and configure credentials without manual intervention. The provisioner system autonomously identifies target devices, retrieves appropriate credentials, and distributes them automatically, reducing provisioning complexity while maintaining strong security through direct credential distribution to each device.
3Object-affected harmful factors
If application credentials are kept separate from network credentials, then security is improved, but ease of operation deteriorates
Solution Approach 1:
The patent segments credential management into distinct layers: network credentials for basic connectivity and application credentials for specific services. The provisioner system handles both separately but integrates the process automatically, maintaining security through separation while preserving ease of operation through automated coordination between the two credential types.
Data Source
AI summary
A method of provisioning a particular type of node devices in a network is disclosed. The network comprises a plurality of operatively interconnected node devices of the particular type. Each of the particular type of node devices comprises a short range communication interface and configured for operating under control of a network backend server and an application backend server separate from the network backend server. The method performed by an application provisioner associated with the particular type of node devices, which first obtains device specific network provisioning data for the particular type of node devices from the network backend server, then obtains an application credential for the particular type of node devices; and thereafter provision the particular type of node devices by distributing the application credential to each of the particular type of node devices over a short range communication interface of the particular type of node device.


