Supplemental Cryptographic Identity for Flexible Device Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing device provisioning systems for network-connected devices are limited by reliance on a single manufacturer's identity, which can become untrustworthy or unsupported, leading to security risks and lack of flexibility.

Innovation Solution

Implementing a supplemental cryptographic identity system where a device provisioning service manages both an initial and a supplemental cryptographic identity, allowing devices to transition from a manufacturer's identity to a buyer-managed identity, enhancing security and flexibility.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a device uses a manufacturer-given cryptographic identity for provisioning, then the device can be securely provisioned initially, but the device becomes forever tied to a single DPS and loses flexibility when the manufacturer goes out of business or terminates support

Engineering Contradiction:
Improveprovisioning securityVSAvoidcross-solution compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The cryptographic identity is segmented into two parts: an initial cryptographic identity issued by the manufacturer for initial provisioning, and a supplemental cryptographic identity issued by a supplemental DPS for continued access. This segmentation allows the device to maintain initial security while gaining flexibility to switch DPS providers.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The device performs preliminary action by requesting and obtaining a supplemental cryptographic identity from a supplemental DPS during the initial provisioning process. This preliminary action ensures that the device is prepared in advance to switch to a different DPS if needed, without requiring re-provisioning from scratch.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If the manufacturer's cryptographic credentials are used for device provisioning, then the device can access service systems, but the credentials may expire, be hacked, or be lost, leaving the device non-functional

Engineering Contradiction:
Improvedevice access functionalityVSAvoidcredential trustworthiness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system provides beforehand cushioning by issuing a supplemental cryptographic identity that acts as a backup to the manufacturer's credentials. This supplemental identity is obtained in advance and stored in the device, cushioning against the possibility that the manufacturer's credentials may expire, be hacked, or be lost.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Solution Approach 2:

The supplemental cryptographic identity acts as an intermediary between the device and the service systems. Instead of relying directly on the manufacturer's credentials, the device uses the supplemental identity as a mediator that is issued and managed by a supplemental DPS, providing an additional layer of trust.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If an enterprise DPS provides enhanced provisioning features and coordination, then cross-manufacturer provisioning and enhanced security are enabled, but the device must transition from a manufacturer-managed identity system

Engineering Contradiction:
Improvecross-manufacturer provisioningVSAvoididentity management structure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The identity management structure is segmented into two independent parts: the initial cryptographic identity managed by the manufacturer for basic provisioning, and the supplemental cryptographic identity managed by the enterprise DPS for enhanced features. This segmentation allows the device to access both manufacturer and enterprise services without creating a single complex unified system.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP4128687B1Device provisioning using a supplemental cryptographic identity
Publication Date: 2025.08.13 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP4128687B1 patent drawingFigure 1
  • EP4128687B1 patent drawingFigure 2
  • EP4128687B1 patent drawingFigure 3

AI summary

A device provisioning service provisions a network-connected device to access one or more service systems using a supplemental cryptographic identity of the network-connected device. An initial enrollment record (associated with an initial cryptographic identity) and a supplemental enrollment record are stored in a device provisioning service. An identity issuance request is received from the network-connected device at the device provisioning service. The identity issuance request includes the initial cryptographic identity. The supplemental cryptographic identity is requested from a supplemental cryptographic identity issuer identified in the initial enrollment record based on the identity issuance request. The requested supplemental cryptographic identity is received at the device provisioning service from the supplemental cryptographic identity issuer. The network-connected device is provisioned to access the one or more service systems according to the supplemental enrollment record. The supplemental cryptographic identity is communicated to the network-connected device.