Supplemental Cryptographic Identity for Resilient Device Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing device provisioning systems tie smart devices to a single manufacturer's identity, leading to risks such as unsupported devices, expired credentials, and limited flexibility, which can hinder cross-solution compatibility and security.

Innovation Solution

Implementing a supplemental cryptographic identity system where a device provisioning service manages both an initial and a supplemental cryptographic identity, allowing devices to transition from a manufacturer's identity to a buyer-managed identity, enhancing security and flexibility by enabling access to multiple service systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a smart device is tied to a single manufacturer's DPS for provisioning, then the device can be initially provisioned and operated, but the device becomes non-functional if the manufacturer goes out of business or terminates support

Engineering Contradiction:
Improvedevice functionalityVSAvoidDPS flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The provisioning system is segmented into multiple independent DPS entities (manufacturer DPS and enterprise DPS), each capable of independently provisioning the device. The device holds multiple credentials corresponding to different DPS, allowing it to operate with any single DPS, thereby eliminating single-point failure and improving reliability while maintaining adaptability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The device is designed with universal provisioning capability by storing multiple cryptographic credentials that are valid across different DPS systems. This multi-functionality allows the device to be provisioned and operated by any DPS (manufacturer or enterprise), ensuring continued functionality regardless of which DPS remains active, thus resolving the contradiction between reliability and adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If manufacturer credentials are used for device provisioning, then initial device operation is enabled, but the credentials may expire, be hacked, or be otherwise lost

Engineering Contradiction:
Improvedevice provisioningVSAvoidcredential security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The device is pre-provisioned with multiple cryptographic credentials before deployment. This prior cushioning ensures that if one credential expires, is compromised, or is lost, the device already has backup credentials ready to use, maintaining both ease of operation and credential security without requiring re-provisioning events.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Solution Approach 2:

The system changes the cryptographic identity parameter by allowing the device to switch between multiple different credentials (initial manufacturer credential and supplemental enterprise credential). This parameter change capability enables the device to move from one credential state to another, maintaining operational ease while improving security through credential diversity and rotation.

Inventive Principle:
Principle #35Parameter changes

3Device complexity

If a device uses a single cryptographic identity from the manufacturer, then provisioning is simplified, but cross-solution compatibility and enhanced security features are limited

Engineering Contradiction:
Improveprovisioning systemVSAvoidcross-solution compatibility
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The provisioning system is divided into separate manufacturer DPS and enterprise DPS components, each with their own enrollment records and credentials. This segmentation allows the device to interact with multiple independent systems, enhancing cross-solution compatibility while keeping each individual DPS relatively simple and manageable.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The device itself acts as an intermediary that holds and manages multiple cryptographic credentials, enabling it to mediate between different DPS systems (manufacturer and enterprise). This intermediary role allows the device to access multiple solutions and enhanced security features while each DPS remains independently simple, resolving the contradiction between system complexity and adaptability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12542709B2Device provisioning using a supplemental cryptographic identity
Publication Date: 2026.02.03 MICROSOFT TECHNOLOGY LICENSING LLC
  • US12542709B2 patent drawing
  • US12542709B2 patent drawing
  • US12542709B2 patent drawing

AI summary

A device provisioning service provisions a network-connected device to access one or more service systems using a supplemental cryptographic identity of the network-connected device. An initial enrollment record (associated with an initial cryptographic identity) and a supplemental enrollment record are stored in a device provisioning service. An identity issuance request is received from the network-connected device at the device provisioning service. The identity issuance request includes the initial cryptographic identity. The supplemental cryptographic identity is requested from a supplemental cryptographic identity issuer identified in the initial enrollment record based on the identity issuance request. The requested supplemental cryptographic identity is received at the device provisioning service from the supplemental cryptographic identity issuer. The network-connected device is provisioned to access the one or more service systems according to the supplemental enrollment record. The supplemental cryptographic identity is communicated to the network-connected device.