Supplemental Cryptographic Identity for Flexible Device Provisioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing device provisioning systems for network-connected devices are limited by reliance on a single manufacturer's identity, which can become untrustworthy or unsupported, leading to security risks and lack of flexibility.
Innovation Solution
Implementing a supplemental cryptographic identity system where a device provisioning service manages both an initial and a supplemental cryptographic identity, allowing devices to transition from a manufacturer's identity to a buyer-managed identity, enhancing security and flexibility.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a device uses a manufacturer-given cryptographic identity for provisioning, then the device can be securely provisioned initially, but the device becomes forever tied to a single DPS and loses flexibility when the manufacturer goes out of business or terminates support
Solution Approach 1:
The cryptographic identity is segmented into two parts: an initial cryptographic identity issued by the manufacturer for initial provisioning, and a supplemental cryptographic identity issued by a supplemental DPS for continued access. This segmentation allows the device to maintain initial security while gaining flexibility to switch DPS providers.
Solution Approach 2:
The device performs preliminary action by requesting and obtaining a supplemental cryptographic identity from a supplemental DPS during the initial provisioning process. This preliminary action ensures that the device is prepared in advance to switch to a different DPS if needed, without requiring re-provisioning from scratch.
2Ease of operation
If the manufacturer's cryptographic credentials are used for device provisioning, then the device can access service systems, but the credentials may expire, be hacked, or be lost, leaving the device non-functional
Solution Approach 1:
The system provides beforehand cushioning by issuing a supplemental cryptographic identity that acts as a backup to the manufacturer's credentials. This supplemental identity is obtained in advance and stored in the device, cushioning against the possibility that the manufacturer's credentials may expire, be hacked, or be lost.
Solution Approach 2:
The supplemental cryptographic identity acts as an intermediary between the device and the service systems. Instead of relying directly on the manufacturer's credentials, the device uses the supplemental identity as a mediator that is issued and managed by a supplemental DPS, providing an additional layer of trust.
3Adaptability or versatility
If an enterprise DPS provides enhanced provisioning features and coordination, then cross-manufacturer provisioning and enhanced security are enabled, but the device must transition from a manufacturer-managed identity system
Solution Approach 1:
The identity management structure is segmented into two independent parts: the initial cryptographic identity managed by the manufacturer for basic provisioning, and the supplemental cryptographic identity managed by the enterprise DPS for enhanced features. This segmentation allows the device to access both manufacturer and enterprise services without creating a single complex unified system.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A device provisioning service provisions a network-connected device to access one or more service systems using a supplemental cryptographic identity of the network-connected device. An initial enrollment record (associated with an initial cryptographic identity) and a supplemental enrollment record are stored in a device provisioning service. An identity issuance request is received from the network-connected device at the device provisioning service. The identity issuance request includes the initial cryptographic identity. The supplemental cryptographic identity is requested from a supplemental cryptographic identity issuer identified in the initial enrollment record based on the identity issuance request. The requested supplemental cryptographic identity is received at the device provisioning service from the supplemental cryptographic identity issuer. The network-connected device is provisioned to access the one or more service systems according to the supplemental enrollment record. The supplemental cryptographic identity is communicated to the network-connected device.