Signed Ownership Vouchers for Network Device Transfer Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for transferring network device ownership fail to securely validate ownership when end customers and purchasers are not the same entity, leading to potential security breaches and inefficiencies in transferring devices to intermediaries or sub-organizations within an end customer's network.

Innovation Solution

Implementing techniques for unmediated and mediated transfer of ownership, including enrolling certificates, validating ownership vouchers, and embedding PDCs to ensure secure transfer without reliance on manufacturer services, and using tokens for mediated transfers to manage intermediary ownership.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the manufacturer validates ownership through their service system, then security is improved, but transfer time and complexity increase

Engineering Contradiction:
Improveownership validation securityVSAvoidownership transfer time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The manufacturer service system pre-generates and stores authorization tokens for intermediary users before actual device transfers occur. When a transfer is needed, the system simply validates and uses the pre-prepared token, eliminating the need for time-consuming real-time manufacturer involvement while maintaining security through cryptographic validation.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If the manufacturer service system is involved in every transfer, then ownership validation accuracy is improved, but system complexity increases

Engineering Contradiction:
Improveownership validation accuracyVSAvoidtransfer system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

An intermediary user acts as a trusted mediator between the manufacturer and end customers. The intermediary receives authorization tokens from the manufacturer service system and uses these tokens to facilitate ownership transfers. This intermediary approach maintains validation accuracy by using manufacturer-issued cryptographic tokens while reducing overall system complexity by eliminating the need for direct manufacturer-end customer communication channels.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If direct manufacturer validation is required, then security against unauthorized transfer is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveunauthorized transfer preventionVSAvoidownership transfer convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The intermediary user performs ownership transfers independently using pre-obtained authorization tokens without requiring real-time manufacturer service involvement. The system enables self-service transfers through cryptographic token validation, maintaining security against unauthorized transfers while dramatically improving operational convenience by eliminating the need for manufacturer service center visits or real-time connections.

Inventive Principle:
Principle #25Self-service

4Adaptability or versatility

If the system supports both intermediaries and direct transfers, then versatility is improved, but device complexity increases

Engineering Contradiction:
Improvetransfer scenario flexibilityVSAvoidownership management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The manufacturer service system implements a universal authorization token mechanism that serves multiple functions: it enables both direct manufacturer-to-end-customer transfers and intermediary-mediated transfers. The same cryptographic token infrastructure supports different transfer scenarios, eliminating the need for separate complex systems for each transfer type while maintaining full versatility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12406269B2Unmediated and mediated transfer of ownership of devices
Publication Date: 2025.09.02 CISCO TECHNOLOGY INC
  • US12406269B2 patent drawing
  • US12406269B2 patent drawing
  • US12406269B2 patent drawing

AI summary

In one embodiment, methods for mediated transfer of ownership are described. The method may include receiving a request for an ownership voucher from a device, validating an identifier of the device, determining whether to issue the ownership voucher, generating a signed ownership voucher, and sending the signed ownership voucher to the device. In another embodiment, methods for unmediated transfer of ownership are described, including receiving, an ownership voucher associated with a first ownership certificate, determining whether the ownership voucher comprises a signature associated with a manufacturer, based at least in part on determining that the signature of the manufacturer is absent, determining that a second ownership certificate is stored in memory, determining that the second ownership certificate comprises a signature associated with a user, validating the ownership voucher; and based at least in part on the validating, enrolling the first ownership certificate on the network device.