Supplemental Cryptographic Identity for Resilient Device Provisioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing device provisioning systems tie smart devices to a single manufacturer's identity, leading to risks such as unsupported devices, expired credentials, and limited flexibility, which can hinder cross-solution compatibility and security.
Innovation Solution
Implementing a supplemental cryptographic identity system where a device provisioning service manages both an initial and a supplemental cryptographic identity, allowing devices to transition from a manufacturer's identity to a buyer-managed identity, enhancing security and flexibility by enabling access to multiple service systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a smart device is tied to a single manufacturer's DPS for provisioning, then the device can be initially provisioned and operated, but the device becomes non-functional if the manufacturer goes out of business or terminates support
Solution Approach 1:
The provisioning system is segmented into multiple independent DPS entities (manufacturer DPS and enterprise DPS), each capable of independently provisioning the device. The device holds multiple credentials corresponding to different DPS, allowing it to operate with any single DPS, thereby eliminating single-point failure and improving reliability while maintaining adaptability.
Solution Approach 2:
The device is designed with universal provisioning capability by storing multiple cryptographic credentials that are valid across different DPS systems. This multi-functionality allows the device to be provisioned and operated by any DPS (manufacturer or enterprise), ensuring continued functionality regardless of which DPS remains active, thus resolving the contradiction between reliability and adaptability.
2Ease of operation
If manufacturer credentials are used for device provisioning, then initial device operation is enabled, but the credentials may expire, be hacked, or be otherwise lost
Solution Approach 1:
The device is pre-provisioned with multiple cryptographic credentials before deployment. This prior cushioning ensures that if one credential expires, is compromised, or is lost, the device already has backup credentials ready to use, maintaining both ease of operation and credential security without requiring re-provisioning events.
Solution Approach 2:
The system changes the cryptographic identity parameter by allowing the device to switch between multiple different credentials (initial manufacturer credential and supplemental enterprise credential). This parameter change capability enables the device to move from one credential state to another, maintaining operational ease while improving security through credential diversity and rotation.
3Device complexity
If a device uses a single cryptographic identity from the manufacturer, then provisioning is simplified, but cross-solution compatibility and enhanced security features are limited
Solution Approach 1:
The provisioning system is divided into separate manufacturer DPS and enterprise DPS components, each with their own enrollment records and credentials. This segmentation allows the device to interact with multiple independent systems, enhancing cross-solution compatibility while keeping each individual DPS relatively simple and manageable.
Solution Approach 2:
The device itself acts as an intermediary that holds and manages multiple cryptographic credentials, enabling it to mediate between different DPS systems (manufacturer and enterprise). This intermediary role allows the device to access multiple solutions and enhanced security features while each DPS remains independently simple, resolving the contradiction between system complexity and adaptability.
Data Source
AI summary
A device provisioning service provisions a network-connected device to access one or more service systems using a supplemental cryptographic identity of the network-connected device. An initial enrollment record (associated with an initial cryptographic identity) and a supplemental enrollment record are stored in a device provisioning service. An identity issuance request is received from the network-connected device at the device provisioning service. The identity issuance request includes the initial cryptographic identity. The supplemental cryptographic identity is requested from a supplemental cryptographic identity issuer identified in the initial enrollment record based on the identity issuance request. The requested supplemental cryptographic identity is received at the device provisioning service from the supplemental cryptographic identity issuer. The network-connected device is provisioned to access the one or more service systems according to the supplemental enrollment record. The supplemental cryptographic identity is communicated to the network-connected device.


