Serialized Application Enrollment for Secure Offline IoT Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for enrolling devices in IoT systems are insecure and inflexible, often relying on default passwords or requiring internet access for configuration.

Innovation Solution

A method involving a first device obtaining and deserializing an enrollment application associated with a second device, transmitting enrollment information to initiate the enrollment process without requiring internet access, using representations like QR-codes or barcodes to encode enrollment information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If devices are preconfigured with security credentials during manufacturing, then enrollment is simplified and can be done en masse, but security is compromised because default passwords are often left unchanged enabling tampering

Engineering Contradiction:
Improvedevice enrollmentVSAvoidsecurity
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent divides the configuration data into separate segments: identity information is stored in read-only memory during manufacturing, while authorization information is obtained separately during the enrollment process. This segmentation allows mass production with pre-configured identities while maintaining security by requiring separate authorization credentials that are not predictable or reusable.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary configuration of device identity information during manufacturing by storing it in read-only memory. This preliminary action simplifies production while the actual enrollment and authorization happens later during deployment, separating the manufacturing simplicity from the security-critical authorization step.

Inventive Principle:
Principle #10Preliminary action

2Extent of automation

If devices bootstrapped to phone home to receive configuration parameters, then enrollment can be automated, but Internet access or access to pre-determined address is required which limits flexibility

Engineering Contradiction:
Improvedevice enrollmentVSAvoidenrollment flexibility
Core Design Contradiction:
Extent of automationVSAdaptability or versatility

Solution Approach 1:

The patent introduces a portable computing device as an intermediary that mediates the enrollment process. Instead of devices directly communicating with remote servers (requiring Internet access), the portable device acts as a local mediator that transfers configuration data via physical connection, enabling automated enrollment without Internet dependency.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the network-based mechanical system (Internet access, IP communication) with a local physical connection system. The enrollment process substitutes remote digital communication with local physical interfacing between the portable device and target device, eliminating the need for Internet access while maintaining automation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Productivity

If devices are configured with all necessary information before deployment, then enrollment is faster, but security is reduced as devices become vulnerable to man-in-the-middle attacks

Engineering Contradiction:
Improveenrollment speedVSAvoidsecurity against attacks
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments configuration data into identity information (pre-configured in read-only memory during manufacturing) and authorization information (obtained during enrollment). This segmentation enables fast enrollment by having identity ready in advance while maintaining security by obtaining authorization credentials through a secure enrollment process that protects against man-in-the-middle attacks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary configuration of identity information in read-only memory during manufacturing, which speeds up enrollment by having this data ready in advance. However, the security-critical authorization information is obtained later during the enrollment process through secure protocols that prevent man-in-the-middle attacks, thus maintaining both speed and security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250254525A1Device Enrollment using Serialized Application
Publication Date: 2025.08.07 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20250254525A1 patent drawing
  • US20250254525A1 patent drawing
  • US20250254525A1 patent drawing

AI summary

Disclosed herein is a method of a first device for initiating and assisting an enrollment process of a second device to an Internet of Things (IoT) environment. The method comprising obtaining a representation of an enrollment function associated with the second device, wherein the enrollment function is associated with at least one serialized enrollment application comprising enrollment information associated with the first and second device and deserializing the enrollment application such that enrollment information associated with the first device is separated from enrollment information associated with the second device. The method also comprises transmitting the enrollment information associated with the second device to the second device for initiating execution by the second device of the enrollment process of the second device by configuration of the second device based the enrollment information associated with the second device and receiving from the second device configuration information associated with the second device.