Subordinate Certificate Authority for IoT Device Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Securing network connections for Internet of Things (IoT) devices, particularly voice devices, is challenging due to their limited human-machine interfaces and the need for reliable, easy-to-set-up networking safeguards in enterprise environments.

Innovation Solution

Implementing a subordinate certificate authority system that provides device certificates chained off a root certificate, enabling secure access to enterprise networks and remote services while allowing flexibility in security protocols, using a setup system to establish point-to-point connections and manage certificate signing requests.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network security protocols are implemented for IoT devices, then network security is improved, but device complexity and ease of operation deteriorate due to limited HMI capabilities

Engineering Contradiction:
Improvenetwork securityVSAvoidease of setup
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables self-service provisioning where IoT devices automatically obtain certificates and establish secure connections without manual HMI interaction. The device generates certificate signing requests, receives signed certificates from a CA, and configures security credentials autonomously, eliminating the need for users to manually configure complex security settings on devices with limited interfaces.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

A certificate authority system acts as an intermediary between the enterprise network and IoT devices. The CA receives signing requests from devices, issues signed certificates, and manages credential distribution centrally. This intermediary handles the complexity of security protocol management, allowing devices with limited HMI to participate in secure enterprise networks through simplified automated processes.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual certificate provisioning is used for IoT devices, then security control is improved, but productivity and ease of operation worsen due to time-consuming setup processes

Engineering Contradiction:
Improvesecurity controlVSAvoidsetup efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary actions by pre-configuring certificate authorities and establishing trust relationships before IoT devices need to connect to the enterprise network. The CA is pre-provisioned with enterprise security policies and root certificates, enabling it to automatically issue signed certificates to devices as they join the network, eliminating the need for manual security configuration at the point of deployment.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

IoT devices autonomously initiate the certificate provisioning process by generating and sending signing requests to the CA. The devices self-configure their security credentials by receiving and installing signed certificates automatically. This self-service approach maintains security control through centralized CA management while dramatically improving setup efficiency by eliminating manual intervention.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If standardized security protocols are implemented across all devices, then adaptability to enterprise networks is improved, but device complexity increases for devices with limited HMI

Engineering Contradiction:
Improvenetwork compatibilityVSAvoidprovisioning complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The certificate authority serves as an intermediary that translates standardized enterprise security requirements into device-specific credential configurations. The CA receives signing requests from diverse IoT devices with varying capabilities, applies enterprise security policies uniformly, and issues appropriate certificates. This intermediary layer enables standardized security protocol implementation across the enterprise network while shielding individual devices from provisioning complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

IoT devices with limited HMI perform self-provisioning by automatically generating certificate signing requests and installing received certificates without user intervention. The automated process handles the complexity of security protocol adaptation, allowing devices to conform to enterprise network standards through autonomous credential management rather than requiring users to navigate complex security configurations.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11240043B1Issuance of certificates for secure enterprise wireless network access
Publication Date: 2022.02.01 AMAZON TECH INC
  • US11240043B1 patent drawing
  • US11240043B1 patent drawing
  • US11240043B1 patent drawing

AI summary

This disclosure is directed to computing services that provide secure network connections using public-private key-based security for Internet of Things (IoT) devices, such as voice devices, that may have more than a predefined set of users. Device certificates that authorize IoT devices to access a secure network, such as an enterprise network and/or services eternal to an enterprise network are provided. A setup system may cooperate with an IoT device and a subordinate CA to generate a device certificate that allows the IoT device to access a secure enterprise network and services outside of the secure enterprise network. The IoT device may generate a certificate signing request (CSR) which may be signed by a remote subordinate CA to generate the device certificate using a root certificate of an enterprise CA. Systems are also disclosed that renew certificates for the IoT devices prior to their expiration.